You are here: silicon.com > Software > Malware

Malware

Beware 'suicidal' malware, says CyberTrust

Stealth attacks are after your intellectual property...

Tags: suicidal malware, stealth, cybertrust, malware

By Munir Kotadia

Published: 28 July 2006 09:20 BST

The latest threat to intellectual property comes in the shape of malicious software that is capable of infecting a computer, hiding itself until the user accesses specific files or websites - in order to steal files or passwords - and then deleting any trace of itself.

Speaking at the IT Security in Government Conference in Canberra, Australia on Friday, Brian Denehy, security assurance engineer at CyberTrust, told delegates the vast majority of new malware uses "some type of stealth" or anti-forensic technology in an attempt to remain undetected before, during and after an attack.

Techniques used not only include 'the obvious ones' such as encryption and rootkits but also "compression bombs".

According to Denehy, techniques used not only include 'the obvious ones' such as encryption and rootkits but also "compression bombs" - which are compressed files that try to make life difficult for forensic tools by attempting to expand to an infinite size when executed.

He said: "Generally these techniques are seen in about 65 per cent of all forensic investigation these days.

"Some just do a complete wipe on the disk - equivalent to a low level format - to make sure that some of the remnant magnetisation is not left behind. Most of you may well appreciate that just writing on a hard disk still leaves evidence there that can be recovered with the right tools.

"People also use the slack space at the end of files or introduce extras in the bad sectors list to hide their data… it makes life more difficult."

When conducting investigations, it's always Denehy's hope that these techniques haven't been used by hackers. "It is pleasing to find an inexperienced hacker that has not used these things and has made it easy to analyse," he said.

Munir Kotadia writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Web Developer - XSLT,Javascript,HTML,XML - Brighton

On a daily basis you will be developing XSLT code and converting the XML files to HTML format. Computer Futures are seeking a web developer based ...

Performance Engineering Consultant / Manager-00038060

Qualifications You will also have: Proven success in contributing to a team-orientated environment Proven abilities to quickly analyse and ...

C# SOFTWARE DEVELOPER- C#.NET/ ASP.NET/ WINFORMS - NOTTINGHAM- 37,000

Our client list expands from Small to Medium sized businesses to blue chip companies. We are looking for an experienced C#.NET/ ASP.NET Developer to ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: