0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?

意思決定特化モデルで危険なコマンドを判定してみた。

0
Posted at

はじめに

ローカルで動くOllaya(winnow 12b)の意思決定特化モデルを使って、危険なコマンドを判別してみた

動機

自作AIハーネス作ってるので、危険なコマンドは自動的に「これやべぇっすよ」って人間にレビューを飛ばし、そうでないコマンドは許可されてたら実行するみたいな感じで使えるかなーって思った。

ざっくり検証結果

Base64エンコードされたコマンド(デコードするべき対象になる)

>>> powershell -NoP -Enc VwByAGkAdABlAC0ASABvAHMAdAAgAGgAZQBsAGwAbwA=
is_obfuscated               yes                           ████████████████ 0.99
method_base_encoding        yes                           ████████████████ 0.99
method_string_splitting     no                            ███████████████░ 0.91
method_dynamic_eval         no                            ███████████████░ 0.94
method_char_math            no                            ██████████████░░ 0.86
method_compression          no                            ██████████████░░ 0.87
method_identifier_mangling  no                            █████████░░░░░░░ 0.55
primary_method              base_encoding                 ████████████████ 0.99
maliciousness               1.63 / 3  likely malicious: behavio…  ██████░░░░░░░░░░ 0.38
risk                        0.42 / 3  harmless: no lasting effe…  ███████████░░░░░ 0.66
malicious_behavior          none                          ███████████████░ 0.92

C:\Windows¥System32¥calc.exeの削除(悪性・高リスク挙動)

>>> $c=$b='System32';$a='r'+'m'+' --For'+'ce'; & $a 'C:\\Windows\\'+$b
is_obfuscated               yes                           ███████████████░ 0.94
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     yes                           ███████████████░ 0.95
method_dynamic_eval         no                            ████████████████ 0.97
method_char_math            no                            ████████████████ 0.97
method_compression          no                            ████████████████ 1.00
method_identifier_mangling  no                            ████████████████ 0.97
primary_method              string_splitting              ████████████████ 0.98
maliciousness               1.89 / 3  likely malicious: behavio…  ███████████░░░░░ 0.71
risk                        2.81 / 3  critical: could break pro…  ██████████████░░ 0.85
malicious_behavior          other                         ██████████░░░░░░ 0.61

システム情報収集(用途によっては悪性だが、一般には副作用が無いため悪性度は低いと判定できる)

>>> systeminfo
is_obfuscated               no                            ████████████████ 0.97
method_base_encoding        no                            ████████████████ 0.98
method_string_splitting     no                            ███████████████░ 0.95
method_dynamic_eval         no                            ███████████████░ 0.96
method_char_math            no                            ████████████████ 0.97
method_compression          no                            ███████████████░ 0.93
method_identifier_mangling  no                            ████████████████ 0.98
primary_method              none                          ████████████████ 0.98
maliciousness               0.03 / 3  benign: no hostile intent…  ████████████████ 0.98
risk                        0.08 / 3  harmless: no lasting effe…  ███████████████░ 0.93
malicious_behavior          none                          ████████████████ 0.98

全イベントログ削除(悪性・高リスク挙動)

>>> Get-WinEvent -ListLog * | ForEach-Object { wevtutil cl $_.LogName }
is_obfuscated               no                            ████████████████ 0.99
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     no                            ███████████████░ 0.91
method_dynamic_eval         no                            ████████████████ 0.98
method_char_math            no                            ████████████████ 0.99
method_compression          no                            ████████████████ 0.99
method_identifier_mangling  no                            ████████████████ 0.99
primary_method              none                          ███████████████░ 0.94
maliciousness               2.05 / 3  likely malicious: behavio…  ██████████████░░ 0.86
risk                        1.91 / 3  serious: could lose or ex…  ████░░░░░░░░░░░░ 0.27
malicious_behavior          defense_evasion               ████████████████ 1.00

セキュリティイベントログ削除(悪性・高リスク挙動)

>>> wevtutil cl Security
is_obfuscated               no                            ███████████████░ 0.96
method_base_encoding        no                            ████████████████ 0.98
method_string_splitting     no                            ██████████████░░ 0.90
method_dynamic_eval         no                            ███████████████░ 0.96
method_char_math            no                            ███████████████░ 0.96
method_compression          no                            ███████████████░ 0.96
method_identifier_mangling  no                            ████████████████ 0.98
primary_method              none                          ████████████████ 0.97
maliciousness               1.98 / 3  likely malicious: behavio…  ██████████████░░ 0.89
risk                        1.34 / 3  limited: could lose or ch…  ████████░░░░░░░░ 0.48
malicious_behavior          defense_evasion               ████████████████ 1.00

ファイアウォール無効化(悪性・高リスク挙動)

>>> netsh advfirewall set allprofiles state off
is_obfuscated               no                            ████████████████ 0.99
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     no                            ███████████████░ 0.92
method_dynamic_eval         no                            ███████████████░ 0.97
method_char_math            no                            ████████████████ 0.98
method_compression          no                            ████████████████ 0.98
method_identifier_mangling  no                            ████████████████ 0.99
primary_method              none                          ████████████████ 0.98
maliciousness               2.00 / 3  likely malicious: behavio…  ███████████████░ 0.91
risk                        2.13 / 3  serious: could lose or ex…  █████████████░░░ 0.79
malicious_behavior          defense_evasion               ████████████████ 1.00

mimikatzの実行(悪性・高リスク挙動)

>>> mimikatz.exe "privilege::debug" "sekurlsa::logonpasswords" exit
is_obfuscated               no                            ████████████████ 0.98
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     no                            █████████░░░░░░░ 0.57
method_dynamic_eval         no                            ███████████████░ 0.96
method_char_math            no                            ████████████████ 0.98
method_compression          no                            ███████████████░ 0.92
method_identifier_mangling  no                            ████████████████ 0.98
primary_method              none                          ████████████████ 0.98
maliciousness               2.73 / 3  clearly malicious: unambi…  ██████████░░░░░░ 0.64
risk                        2.14 / 3  serious: could lose or ex…  █████████████░░░ 0.81
malicious_behavior          credential_theft              ████████████████ 0.99

mimi.exeへリネームされたmimikatzの実行(悪性・高リスク挙動)

>>> mimi.exe "privilege::debug" "sekurlsa::logonpasswords" exit
is_obfuscated               no                            ███████████████░ 0.95
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     yes                           ███████████████░ 0.92
method_dynamic_eval         no                            ████████████████ 0.97
method_char_math            no                            ████████████████ 0.98
method_compression          no                            ███████████████░ 0.96
method_identifier_mangling  no                            ███████████████░ 0.95
primary_method              none                          ██████████████░░ 0.86
maliciousness               2.07 / 3  likely malicious: behavio…  ██████████████░░ 0.86
risk                        2.04 / 3  serious: could lose or ex…  ██████████████░░ 0.90
malicious_behavior          credential_theft              ████████████████ 0.98

m.exeへリネームされたmimikatzの実行(悪性・高リスク挙動)

>>> m.exe "privilege::debug" "sekurlsa::logonpasswords" exit
is_obfuscated               no                            ███████████████░ 0.93
method_base_encoding        no                            ████████████████ 0.99
method_string_splitting     yes                           ██████████████░░ 0.87
method_dynamic_eval         no                            ████████████████ 0.98
method_char_math            no                            ████████████████ 0.98
method_compression          no                            ████████████████ 0.98
method_identifier_mangling  no                            ████████████████ 0.97
primary_method              none                          ██████████████░░ 0.86
maliciousness               2.11 / 3  likely malicious: behavio…  █████████████░░░ 0.81
risk                        2.04 / 3  serious: could lose or ex…  ██████████████░░ 0.89
malicious_behavior          credential_theft              ████████████████ 0.97

発展

ソースコードレベルで悪性度合いを検査してみた。
マルウェア検知にも応用できそう。

EternalBlue(CVE-2017-0144を突くExploit)

=== eb.py ===  [!] 悪性の疑い
  preset=script-analysis  model=winnow:e4b  (4 塊を最大集約)
  language : python (0.99)
  難読化   : 不明 (0.47)
  悪性度   : likely malicious (2.31, conf 0.48)
  影響度   : critical (2.56, conf 0.51)
  難読化方式: (なし)  / 代表=identifier_mangling
  悪性挙動 : exploitation 0.90  / 代表=exploitation

感想

なんかめっちゃよさげじゃね?
雑な下書き記事

0
0
0

Register as a new user and use Qiita more conveniently

  1. You get articles that match your needs
  2. You can efficiently read back useful information
  3. You can use dark theme
What you can do with signing up
0
0

Delete article

Deleted articles cannot be recovered.

Draft of this article would be also deleted.

Are you sure you want to delete this article?