Research Article

Efficient Detection and Recovery of Malicious PowerShell Scripts Embedded into Digital Images

Table 3

Detection and performance results for Mavis.

Invoke-PSImage Mode-1

ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated4641/4641 (100%)0/4641 (0%)7.751.6510.03
Obfuscated4018/4018 (100%)0/4018 (0%)19.185.230.12
Overall100%0%13.053.315.43

Invoke-PSImage Mode-2
ScriptsCorrect detec.FN rate (ms) (ms) (%)
Deobfuscated (256 × 256)5000/5000 (100%)0/5000 (0%)1.13.940.0009
Deobfuscated (512 × 512)5000/5000 (100%)0/5000 (0%)4.113.830.0017
Deobfuscated (1024 × 1024)5000/5000 (100%)0/5000 (0%)16.894.030.0022
Obfuscated (256 × 256)5000/5000 (100%)0/5000 (0%)0.999.240.0006
Obfuscated (512 × 512)5000/5000 (100%)0/5000 (0%)4.069.710.0005
Obfuscated (1024 × 1024)5000/5000 (100%)0/5000 (0%)16.299.570.0006
Overall100%0%7.246.720.0011

ScriptsCorrect detec.FP rate (ms) (ms) (%)
Clean (256 × 256)5000/5000 (100%)0/5000 (0%)1.15N/AN/A
Clean (512 × 512)4999/5000 (99.98%)1/5000 (0.02%)4.44N/AN/A
Clean (1024 × 1024)5000/5000 (100%)0/5000 (0%)16.21N/AN/A
Overall99.99%0.01%7.27N/AN/A