中文

扩展Metasploit框架以实现规避性攻击基础设施

密码学与安全 2017-05-16 v1

摘要

鉴于测试主流杀毒软件抵御通过drive-by download投递的规避性恶意有效载荷的能力这一预期目标,本工作旨在以三种方式扩展Metasploit——首选的渗透测试套件——的功能:(1) 允许其动态生成Metasploit打包的恶意二进制文件的规避形式,(2) 提供通过drive-by download衍生的攻击向量投递所述可执行文件的规避手段,(3) 以可在SPICE框架内产生可复现测试的方式协调前两种功能。

关键词

引用

@article{arxiv.1705.04853,
  title  = {Extending the Metasploit Framework to Implement an Evasive Attack Infrastructure},
  author = {Aubrey Alston},
  journal= {arXiv preprint arXiv:1705.04853},
  year   = {2017}
}