Go Back   Tech Support Forum > Security Center > Computer Security News

User Tag List

Customised malware attacks grow increasingly widespread

This is a discussion on Customised malware attacks grow increasingly widespread within the Computer Security News forums, part of the Tech Support Forum category. The rising popularity of custom malware and the inability of antivirus software to keep pace poses potent challenges for enterprises


Closed Thread
 
Thread Tools Search this Thread
Old 03-21-2011, 02:35 PM   #1
Security Manager
Analyst
Rangemaster, TSF Academy
 
Glaswegian's Avatar
 
Join Date: Sep 2005
Location: Glasgow
Posts: 39,536
OS: Windows 10 Pro

My System


The rising popularity of custom malware and the inability of antivirus software to keep pace poses potent challenges for enterprises trying to keep their systems secure.

It's no secret that the goal of modern malware writers is to create attack software that is stealthy and flows undetected for as long a period of time as possible. However, what's increasingly startling is how pervasive custom malware has become as part of traditional attacks.

"The advanced attack is getting more pervasive," says Shawn Moyer, managing principal at security services firm Accuvant Labs. "In our engagements and my conversations with peers we are dealing with more organisations that are grappling with international infiltration," he says. "Every network we monitor, every large customer, has some kind of customised malware infiltrating data somewhere. I imagine anybody in the global 2,500 has this problem."

Not all of the code slipping on by security defenses is customised malware. Consider the Prioxer backdoor Trojan discovered by Symantec. The Trojan does many of the things a typical Trojan would do, such as drop a .dll file, operate command and control through IRC channels. However, because of some trickery between the cached version of the infected file on disk, the Trojan that resides in memory is essentially invisible to the system.

All of this supports a report released by NSS Labs last week that found many antivirus applications fail to find malware that attempts to infect systems through multiple entry points, such as email or USB drives. The independent testing company evaluated the effectiveness of 10 popular antivirus applications against multi-vector attacks (malware delivered from the web, email, network file sharing and USB flash drives), memory-only attacks and anti-evasion techniques.

The report, titled Socially-Engineered Malware Via Multiple Attack Vectors, found that antivirus applications that find malware at one point-of-entry may not detect it in another. For example, a web download could be missed if downloaded from a USB drive or network file server.

The report found that antivirus products miss between 10 percent and 60 percent of the evasions most often used by attackers. Furthermore, less than a third of the tested vendors had protection for memory-only malware, leaving a significant evasion gap in their products.

Typically, according to the report, these evasion techniques include placing a wrapper or a disguise that are applied to exploits and malware in an attempt to thwart detection. "An exploit that is detected by a security product can be modified by an evasion technique to still get through to the target - if the intermediary security product does not have the appropriate anti-evasion capability," the report stated.

None of that surprises Moyer. "It's fairly trivial to customise an exploit to bypass 70 percent of the time. I do it all of the time on engagements," Moyer says.

How important is it for antimalware software to be able to stop each and every attack? Stewart has some sobering news about what the attackers do once they gain any kind of foothold. "They'll conduct a lot of network probing. They'll look for vulnerable network servers, web servers, SQL servers and other areas where they can gain another foothold: weak passwords. File shares, and they'll go from there. Moving point to point and extract whatever data they can," he says.


Customised malware attacks grow increasingly widespread - Feature - Techworld.com
__________________
Iain - Defender of the Haggis and all things Scottish.
I don't help by PM - post in the Forums.

PC Safety & Security::PC running a bit slow?::Photographers Corner

Glaswegian is offline  
Sponsored Links
Advertisement
 
Closed Thread

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is on
Smilies are on
[IMG] code is on
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Post a Question


» Site Navigation
 > FAQ
  > 10.0.0.2
Powered by vBadvanced CMPS v3.2.3


All times are GMT -7. The time now is 08:29 PM.


Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2019, vBulletin Solutions, Inc.
vBulletin Security provided by vBSecurity v2.2.2 (Pro) - vBulletin Mods & Addons Copyright © 2019 DragonByte Technologies Ltd.
User Alert System provided by Advanced User Tagging v3.1.0 (Pro) - vBulletin Mods & Addons Copyright © 2019 DragonByte Technologies Ltd.
Copyright 2001 - 2018, Tech Support Forum

Windows 10 - Windows 7 - Windows XP - Windows Vista - Trojan Removal - Spyware Removal - Virus Removal - Networking - Security - Top Web Hosts