Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Security Skills in High Demand | Main | Beating Phishers the Old Fashioned Way »

Malware Poised to Avoid Behavioral Analysis

Since virus writers have used mutating viruses to avoid detection by signature-based methods, anti-virus programs have used behavioral analysis to detect malware. This technique depends on executing the suspected code in a virtual machine, or sandbox. Now The Register is reporting in Destroying sandboxes this AV techniques may be threatened:

Some malware authors have already developed their code to the point where it can identify when it is being operated in a virtual machine, and so neutralise the malicious behaviour. The point of this approach is to make the analysis of their malware more difficult for the anti-malware developers as they can not observe the suspicious code engaging in malicious activity. Other malware can identify when a debugger is attached and respond accordingly (some even with targeted attacks against debuggers such as IDA).

The article concludes it won't be long before we see full blown malware using these techniques:

Based on previous related cases where code has gone from demonstration to application, specialised targeting using similar approaches in the wild are expected within six to eight weeks, with general attack usage viable within 12 to 18 weeks.

This is another example of the tightly coupled evolution of malware and anti-malware. The big question now is how long before AV researchers develop a technique for detecting the kinds of probes used by this technique.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/355

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net