9 ms·
An honest question - to you or anyone who basically feels the same way: What methods do you use to determine if you're running hostile code? How often do you l
by trotsky 16y ago
An honest question - to you or anyone who basically feels the same way:
What methods do you use to determine if you're running hostile code? How often do you look? Do you check from another OS? Keep hashes of system files?
Let me expand on the theory that most malware hosts have absolutely no idea (and not just the dumb ones):
Once installed many threats actively evade AV, personal firewalls, and code signing requirements. Are you booting a livecd and checking hashes of the boot block and boot chain against previously saved values? What about the hash of your EPROMS?
I understand that sounds very paranoid - but advanced toolkits that attack the BIOS or boot loader are widely available. Are they only for juicy targets? TDL4 - an advanced threat that starts in the boot block and has used private 0-days - is engaged in the super spy thriller business of clickfraud. $10k will buy you a kit from Israel that inserts similar code into the system BIOS and is designed for non-techies to deploy.
Expecting to see increased resource usage? CPU, RAM, network speed are all far outstripping most actual application needs and the resources needed for a keylogger, afinity rewriter, ad inserter or similar are vanishingly small.
Expecting a signature hit in some security software? Authors check their own code frequently - when signatures get deployed that catch them they simply recompile and tweak until they're undetected again.
Expecting pop up ads, AV scareware, spamming activity or fraud alerts on your credit card? Some threats are like that, yes, but shrinking. Just as or more likely are threats that manipulate search results, add affiliate tags to big ticket items, slip paid SEO links into blogs, steal your banking credentials but decide you're too poor or in an inconvenient county or steal company IP/plans/etc for chinese, russian, french, korean etc. competitors - the impact of which may take years or never be identified.
Expecting unknown, suspicious or hidden processes? Hiding in plain sight is a common and effective tactic. Can you tell the difference between a game installed codec, a useful codec with legal clickstream collections installed by a torrent downloader and a codec that was installed by exploit and rewrites your network traffic? Looking at a process list how many are you positive were running last month? Can you tell if skype is loading a dll or so that it wasn't before?
Think you're an unlikely target? Odds are that's true. However, automated tools can be deployed against thousands of targets and if only one or two have something really juicy it was a worthwhile effort. Proprietary IP of almost ever type has some value to someone be it term sheets, source code, M&A data, business process, sales leads, P&L data etc. Could your SO think you're cheating? Smartphone malware sold for 3000 yaun (~$450) supposedly marketed to houswives was found running on 150,000 chinese phones - it real time tracks your location, records audio, video and pictures regularly or on demand, steals credentials and all email/im/sms traffic. If you're of no interest it's possible your next door neighbor is, or his girlfriend, or someone who gets coffee where you do.
20 years ago malware was made by hobbyists. 10 years ago malware was made by small independent businessmen and specialty concerns. 5 years ago malware was made by organized crime, corporate espionage and intelligence agencies. Today malware is made by private organizations with hundreds of employees and traditional office space, teams supporting major M&A lawyers, the FBI to execute wiretapping warrants, defense contractors, ad networks, energy companies, virtual currency resellers, intelligence services conducting broad surveillance on foreign populations and security services conducting broad surveillance on their own citizenry.
One reason you don't hear a lot about it is there are very few practical solutions out there to be implemented. Microsoft, Google, Apple, Oracle and Intel are all making inroads to various degrees but practically it is decidely a losing game so far. For the time being their profit margins depend on people not getting scared away. Law enforcement and Intelligence services that might have warned against such threats in another era are by in large too busy exploiting them.
I fully understand that this all sounds very tinfoil hat and extremist. All the examples given are real and happening to very real people every day. The threat model has radically changed - it may just take another 3-5 years for everyone to understand the new rules.