The rapid growth of web application technologies has ushered in an era in which cyberattacks pose a constant, pervasive threat. This research provides a critical analysis of the systemic vulnerabilities in Web-based application hosting on Windows devices. It also presents an in-depth analysis of advanced antivirus (AV) evasion techniques that can be used to obtain unauthorized remote access. In the aim to purely understand the path to take for applying countermeasures, we address the limitations of conventional signature-based and heuristic security solutions by constructing novel attack methodologies that manipulate the dynamic and often overlooked aspects of web application interactions. Therefore, we propose a novel evasion technique, “Documents inside Documents” (DiD), which consists of parent and child files, to circumvent antivirus products. Additionally, we address some existing bypass techniques in the children’s files in parallel. One primary way to circumvent security measures is to apply custom code during payload creation. On the other hand, a primary way to thwart custom code is to implement a multi-layered defense-in-depth with strict input validation and least-privilege execution. Our findings demonstrate that our proposed behavioral attack can evade both conventional and heuristic security measures, with quantified results. This paper aims to perform attacks from a high level to prove the necessity of significantly enhancing the functionalities of AV software and other security solutions. It can also assist in the future direction of security remediations, performing Offensive Security assessments.
Dora et al. (Wed,) studied this question.
Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context: