Trojan attacks have emerged as a significant threat in the cybersecurity landscape, evolving in complexity and impact over the years. In this article, we provide an up-to-date review of Trojan attacks to contribute to the understanding and mitigation of pervasive threats in cybersecurity, particularly in the context of emerging machine learning-based technologies. First, we delineate several types of Trojan attacks. These include Remote Access Trojans (RATs), Banking Trojans, Backdoor Trojans, Infostealer Trojans, Downloader Trojans, Ransomware Trojans, Distributed Denial of Service (DDoS) Trojans, Fake Antivirus Trojans, SMS Trojans, and Gaming Trojans. The mechanisms of action are explored, detailing the delivery and installation processes, execution, payload delivery, and communication. Typical attack vectors are identified, such as email attachments, phishing links, “malvertising”, drive-by downloads, software bundling, USB and removable media, and fake software updates. We then examine the purpose of Trojan attacks, including data theft, remote control, spyware deployment, ransomware deployment, and botnet inclusion. Detection and prevention techniques are analyzed, first focusing on traditional methods, then turning to recent advancements in such detection methods. Here, we explore the ways that machine learning and AI are used for detection, including behavioral analysis, network traffic analysis, static and dynamic code analysis, adversarial machine learning, feature engineering and data augmentation, ensemble methods, and explainable AI. Finally, we discuss how economic pressures contribute to Trojan attacks through hardware, namely through technology fraud. Technology fraud is when manufacturers intentionally degrade devices and IT systems to promote new product purchases. We discuss the recent class-action lawsuit against one of the “techno king industries” for deliberately slowing down older phone models through software updates and how this relates to security vulnerabilities that Trojan attacks threaten. By providing a detailed analysis of the types, mechanisms, activities, and detection methods of Trojan attacks, we hope to contribute to the understanding and mitigation of these pervasive threats in cybersecurity, particularly in our AI-centric modern world.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

The Sinister Ghost in the Wooden Horse: From Ancient Myths to Industrial Fraud by Trojan Attack

  • Mitchell Eakin,
  • Mahdi Khosravy,
  • Alyssa M. Adams,
  • Olaf Witkowski

摘要

Trojan attacks have emerged as a significant threat in the cybersecurity landscape, evolving in complexity and impact over the years. In this article, we provide an up-to-date review of Trojan attacks to contribute to the understanding and mitigation of pervasive threats in cybersecurity, particularly in the context of emerging machine learning-based technologies. First, we delineate several types of Trojan attacks. These include Remote Access Trojans (RATs), Banking Trojans, Backdoor Trojans, Infostealer Trojans, Downloader Trojans, Ransomware Trojans, Distributed Denial of Service (DDoS) Trojans, Fake Antivirus Trojans, SMS Trojans, and Gaming Trojans. The mechanisms of action are explored, detailing the delivery and installation processes, execution, payload delivery, and communication. Typical attack vectors are identified, such as email attachments, phishing links, “malvertising”, drive-by downloads, software bundling, USB and removable media, and fake software updates. We then examine the purpose of Trojan attacks, including data theft, remote control, spyware deployment, ransomware deployment, and botnet inclusion. Detection and prevention techniques are analyzed, first focusing on traditional methods, then turning to recent advancements in such detection methods. Here, we explore the ways that machine learning and AI are used for detection, including behavioral analysis, network traffic analysis, static and dynamic code analysis, adversarial machine learning, feature engineering and data augmentation, ensemble methods, and explainable AI. Finally, we discuss how economic pressures contribute to Trojan attacks through hardware, namely through technology fraud. Technology fraud is when manufacturers intentionally degrade devices and IT systems to promote new product purchases. We discuss the recent class-action lawsuit against one of the “techno king industries” for deliberately slowing down older phone models through software updates and how this relates to security vulnerabilities that Trojan attacks threaten. By providing a detailed analysis of the types, mechanisms, activities, and detection methods of Trojan attacks, we hope to contribute to the understanding and mitigation of these pervasive threats in cybersecurity, particularly in our AI-centric modern world.