Comparative Analysis of Rule-Based and AI/ML Approaches for Malicious Persistence Techniques

Background

Attackers can abuse Windows persistence mechanisms to maintain access to compromised systems. Traditional security solutions often rely on predefined rules to detect known suspicious behaviors. Machine Learning provides an alternative approach by learning behavioral patterns from system activity.

Research Question

How do rule-based and machine-learning approaches compare in detecting Windows persistence activities, particularly when the observed behavior differs from known patterns?

Keywords

Windows Security, Persistence Detection, Machine Learning, Behavioral Detection, Graph-Based Detection, Rule-Based Detection, WMI, Windows Services.

Goal

The main objective is to evaluate whether ML can provide useful complementary detection capabilities compared with traditional rule-based detection. The project will focus on three persistence mechanisms:

• Windows Services

• Account-based persistence

• Windows Management Instrumentation (WMI)

The student will:

• Review Windows persistence techniques and existing detection methods.

• Collect or prepare a dataset containing benign and persistence-related Windows activities.

• Develop simple rule-based detectors for the selected techniques.

• Extract relevant behavioral features from the same activity data.

• Develop baseline AI/ML models for persistence detection.

• Compare the different approaches using precision, recall, F1-score, and false-positive/false-negative analysis.

• Evaluate the ability of the approaches to detect variations of known persistence behaviors.

Expected Outcome

• Source code of the boxes on our GitLab server

• 1 blog post

• 1 poster

Required skills

To start this project, you should have some knowledge of:

• Programming (any language)

Interested?

Contact us