Content area

Abstract

In recent years, Living off the Land (LotL) attacks have been drawing attention due to their flexibility and difficulty in detection. These attacks exploit legitimate tools already in the system to conduct malicious activities, hiding their malicious intent behind normal benign programs. However, detection methods for such attacks largely rely on expert rules. While rule tags can effectively detect known attacks, this also leads to a high false positive rate, resulting in low detection accuracy for the models. To address these issues, we propose a detection system called LOTLDetector, which combines deep learning methods with expert rules to detect malicious command lines in LotL attacks from both data and knowledge perspectives. LOTLDetector learns the semantics of command line text through neural networks and combines rule tags from expert knowledge, enabling a more comprehensive detection of LotL attacks. We extensively evaluated our method, validated it on a Windows dataset containing 27,448 command lines and a Linux dataset containing 27,093 command lines, and compared it with existing methods. The results show that our method significantly outperforms existing methods in detecting malicious command lines. For the Linux dataset, the detection system achieved a detection performance with an accuracy of 0.9728; for the Windows dataset, the system’s detection accuracy also reached 0.9598, which is about 8% higher than the best existing method. In addition, our project has been open-sourced at https://github.com/csedikaf/LOTLDetector.

Details

1009240
Title
Lotldetector: living off the land attacks detection system based on feature fusion
Author
Zhu, Tiantian 1   VIAFID ORCID Logo  ; Zheng, Jie 1 ; Chen, Tieming 1 ; Lv, Mingqi 1 ; Xiong, Chunlin 2 ; Weng, Zhengqiu 3 ; Zheng, Xiangyang 3 

 Zhejiang University of Technology, College of Computer Science and Technology, Hangzhou, China (GRID:grid.469325.f) (ISNI:0000 0004 1761 325X) 
 China Unicom (Guangdong) Industrial Internet Company Ltd., Guangzhou, China (GRID:grid.469325.f) 
 Wenzhou University of Technology, School of Data Science and Artificial Intelligence, Wenzhou, China (GRID:grid.469325.f) (ISNI:0000 0005 1164 4044) 
Publication title
Cybersecurity; Singapore
Volume
9
Issue
1
Pages
4
Publication year
2026
Publication date
Dec 2026
Publisher
Springer Nature B.V.
Place of publication
Singapore
Country of publication
Netherlands
Publication subject
e-ISSN
25233246
Source type
Scholarly Journal
Language of publication
English
Document type
Journal Article
Publication history
 
 
Online publication date
2026-01-04
Milestone dates
2025-11-27 (Registration); 2024-11-07 (Received); 2025-11-26 (Accepted)
Publication history
 
 
   First posting date
04 Jan 2026
ProQuest document ID
3290061051
Document URL
https://www.proquest.com/scholarly-journals/lotldetector-living-off-land-attacks-detection/docview/3290061051/se-2?accountid=208611
Copyright
© The Author(s) 2026. This work is published under http://creativecommons.org/licenses/by/4.0/ (the “License”). Notwithstanding the ProQuest Terms and Conditions, you may use this content in accordance with the terms of the License.
Last updated
2026-01-05
Database
ProQuest One Academic