期刊文献+

AB-DHD:An Attention Mechanism and Bi-Directional Gated Recurrent Unit Based Model for Dynamic Link Library Hijacking Vulnerability Discovery

原文传递
导出
摘要 With the rapid development of operating systems,attacks on system vulnerabilities are increasing.Dynamic link library(DLL)hijacking is prevalent in installers on freeware platforms and is highly susceptible to exploitation by malware attackers.However,existing studies are based solely on the load paths of DLLs,ignoring the attributes of installers and invocation modes,resulting in low accuracy and weak generality of vulnerability detection.In this paper,we propose a novel model,AB-DHD,which is based on an attention mechanism and a bi-directional gated recurrent unit(BiGRU)neural network for DLL hijacking vulnerability discovery.While BiGRU is an enhancement of GRU and has been widely applied in sequence data processing,a double-layer BiGRU network is introduced to analyze the internal features of installers with DLL hijacking vulnerabilities.Additionally,an attention mechanism is incorporated to dynamically adjust feature weights,significantly enhancing the ability of our model to detect vulnerabilities in new installers.A comprehensive“List of Easily Hijacked DLLs”is developed to serve a reference for future studies.We construct an EXEFul dataset and a DLLVul dataset,using data from two publicly available authoritative vulnerability databases,Common Vulnerabilities&Exposures(CVE)and China National Vulnerability Database(CNVD),and mainstream installer distribution platforms.Experimental results show that our model outperforms popular automated tools like Rattler and DLLHSC,achieving an accuracy of 97.79%and a recall of 94.72%.Moreover,17 previously unknown vulnerabilities have been identified,and corresponding vulnerability certifications have been assigned.
作者 Xiao Chen Le-Tian Sha Fu Xiao Jia-Ye Pan Jian-Kuo Dong 陈霄;沙乐天;肖甫;潘家晔;董建阔
出处 《Journal of Computer Science & Technology》 2025年第3期887-903,共17页 计算机科学技术学报(英文版)
基金 supported by the National Natural Science Foundation of China under Grant Nos.62072253,62172258,62302238,and 62372245 the CCF-Tencent Rhino-Bird Open Research Fund,the Major Science and Technology Demonstration Project of Jiangsu Provincial Key Research and Development Program under Grant No.BE2022798 the Postgraduate Research and Practice Innovation Program of Jiangsu Province of China under Grant No.KYCX20_0829.
  • 相关文献

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部