כתבה
arXiv cs.AI ·
SENTINEL: תכנון רב-נתיבי לזיהוי פגיעות APT של LOTL בפקודות Windows
SENTINEL: A Multi-Pathway Architecture for Detecting Living-Off-the-Land APT Attacks on Windows Command Lines
מערכת SENTINEL זוהתה פגיעות APT של LOTL בפקודות Windows תוך שימוש בתכנון רב-נתיבי.
תקציר מקורי באנגליתarXiv:2609.14593v1 Announce Type: cross Abstract: Living-Off-the-Land (LOTL) is the dominant evasion technique of Advanced Persistent Threat (APT) actors, exploiting legitimate Windows utilities to conduct malicious operations without deploying custom malware and enabling state-sponsored campaigns to maintain persistent access within military and critical defense infrastructure for extended periods. Existing detection methods fail against obfuscated commands and multi-stage attack sequences, as demonstrated by the Volt Typhoon APT campaign, which maintained undetected access to U.S. critical infrastructure for over 18 months using exclusively signed Windows utilities. We present SENTINEL, a multi-pathway architecture integrating BERT-based semantic encoding, character-level CNN for obfusca
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית