首页 | 本学科首页   官方微博 | 高级检索  
     


A novel malware for subversion of self‐protection in anti‐virus
Authors:Byungho Min  Vijay Varadharajan
Affiliation:Advanced Cyber Security Research Centre, Department of Computing, Macquarie University, Sydney, Australia
Abstract:Major anti‐virus solutions have introduced a feature known as ‘self‐protection’ so that malware (and even users) cannot modify or disable the core functionality of their products. In this paper, we have investigated 12 anti‐virus products from four vendors (AVG, Avira, McAfee and Symantec) and have discovered that they have certain security weaknesses that can be exploited by malware. We have then designed a novel malware, which makes use of the weaknesses in anti‐virus software and embeds itself to become a part of the vulnerable anti‐virus solution. It subverts the self‐protection features of several anti‐virus software solutions. This malware integrated anti‐virus enjoys several advantages such as longevity (anti‐virus is active while the system is running), improved stealthy behaviour, highest privilege and capability to bypass security measures. Then we propose an effective defence against such malware. We have also implemented the defensive measure and evaluated its effectiveness. Finally, we show how the proposed defence can be applied to the current versions of vulnerable anti‐virus solutions without requiring signficant modifications. Copyright © 2015 John Wiley & Sons, Ltd.
Keywords:security  anti‐virus  self‐protection  malware  vulnerability
设为首页 | 免责声明 | 关于勤云 | 加入收藏

Copyright©北京勤云科技发展有限公司  京ICP备09084417号