3 ms·
I work at a threat intelligence firm which provides services for aggregating desktop antivirus engines & specialized malware detection tooling; I've submitted d
by ZephyrP 7y ago
I work at a threat intelligence firm which provides services for aggregating desktop antivirus engines & specialized malware detection tooling; I've submitted dozens of public and manually constructed compression-bombs for analysis (including this one). Many antivirus engines, even very small vendors, handle this case better than you might imagine.
- yarg 7y agoI'm just thinking of strategies for dealing with it. Sandboxed whitebox fuzzing seems like one way of dealing with executables that could take some unknown commands directing the malicious behaviour - but you introduce the possibility of a sandbox breach making the antivirus itself the vector for execution. The other possibility I see harks back to algorithms - build a DAG from the archive's interfile dependencies and run an iterative deepening search through the structure against some heuristic checking for malicious design. I've never gotten into anything security related (other than reading Schneier's blog) but the cat and mouse game is fascinating.