🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)
🔧 AI Nachrichten KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten(11.09.2026 um 11:00 Uhr)
🔧 AI Nachrichten Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf(28.08.2026 um 08:46 Uhr)
🐧 Linux TippsPACMAN: KI-Framework steuert Fusionsplasma in Echtzeit(11.09.2026 um 10:46 Uhr)
📰 IT NachrichtenAutismus und ADHS mit früher Weichmacher-Exposition verknüpft(12.09.2026 um 09:04 Uhr)
🪟 Windows TippsMicrosoft bringt Emoji 17.0 auf Windows 11(31.08.2026 um 08:16 Uhr)
⚠️ Malware / Trojaner / VirenNeue Android-Malware schreit Sie an, wenn Sie nicht zahlen(11.09.2026 um 10:33 Uhr)
📰 IT Nachrichten7-max: Tool bringt 10 bis 20 Prozent mehr Tempo für Programme(12.09.2026 um 09:30 Uhr)
⚠️ Malware / Trojaner / VirenHandy: Wer diese App installiert hat, sollte sein Gerät besser zurücksetzen(11.09.2026 um 16:55 Uhr)

🎥 IT Security Video 🕛 vor 1 Jahr 2 Min Lesezeit SECURITY-FEED
0

Youtube virusbtn: SO that looks suspicious: leveraging process memory and kernel/usermode probes to detect Shared...

↗ Quelle (YouTube)
🗣️ Stimme:
📺
YouTube
197 YouTube-Aufrufe

Author: Virus Bulletin - Bewertung: 0x - Views:0

Presented at the VB2024 conference in Dublin, 2 - 4 October 2024.

↓ Slides: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/slides/Slides-SO-that-looks-suspicious-leveraging-process-memory-and-kernel-usermode-probes-to-detect-Shared-Object-injection-at-scale-on-Linux.pdf

↓ Paper: https://www.virusbulletin.com/uploads/pdf/conference/vb2024/papers/Detecting-Shared-Object-injection.pdf

→ Details: https://www.virusbulletin.com/conference/vb2024/abstracts/so-looks-suspicious-leveraging-process-memory-and-kernelusermode-probes-detect-shared-object-injection-scale-linux/



✪ PRESENTED BY ✪



• Daniel Jary



✪ ABSTRACT ✪



Shared Object (SO) injection on Linux is the fundamental equivalent of DLL injection on Windows. It's an effective technique successfully leveraged by attackers and their runtime malware. Under normal circumstances a loaded SO provides additional capability to a process by supplying exported functions. However, attackers can modify, insert, or even execute their own SO(s) in memory to perform malicious activities. What's concerning is the availability of user mode rootkits that implement this functionality but the lack of endpoint monitoring and AV solutions that can detect the many variations of this technique. Even more worryingly, threat groups have leveraged this capability directly from source to great effect in order to remain undetected!



In this talk I will dig into four techniques that can be used to maliciously load SOs and uncover unique ways to detect them. I will explain how to rebuild the ELF structure from process memory, enrich this with forensic metadata and then combine it with u/kprobes to facilitate targeted scanning and perform efficient detections at scale. The four techniques covered here are:



• DT_NEEDED infections.

• LD_PRELOAD injection & API hooking.

• Direct use of __libc_dlopen_mode().

• Reflective SO injection.



In addition, I will be demonstrating part of my own tool that not only identifies SO injection but also shellcode injection, process hollowing & entry point manipulation of running processes. Viewers of this talk, especially those working as sensor developers, incident responders or in a blue team, will come away with knowledge of how to spot such techniques and implement these capabilities into their own toolsets. They will gain an understanding of ELF internals, Linux process memory, uprobes and kprobes, and of how to combine them to detect evil. Coinciding with this talk is the release a two-part white paper on SO injection attack & defence for those who wish to dig a little deeper.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 0%
🟡 In Evaluierung 0%
🟢 Keine Auswirkung 0%
Spannende Innovation 0%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
1 Quelle
KI-Angriffe: Geheimdienste sollen neue Befugnisse erhalten
1 Quelle
Podcast: ChatGPT schwatzt Nutzern in Deutschland jetzt Werbung auf
1 Quelle
PACMAN: KI-Framework steuert Fusionsplasma in Echtzeit
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten SO that looks suspicious: leveraging process memory and kernel/usermode probes to detect Shared...

Thematisch verwandte Begriffe: that, looks, suspicious, leveraging · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...