4 ms·
Traditional A/V are broken for the web. With dynamic languages like JS and ActionScript, their approach is to fingerprint 10 different strains of the same thr
by jdangu 14y ago
Traditional A/V are broken for the web.
With dynamic languages like JS and ActionScript, their approach is to fingerprint 10 different strains of the same threat. Then the 11th strain can be generated in a few seconds with new obfuscation.
So the A/V only starts working if/when eventually a native code payload reaches the target.
- throwaway2048 14y agono, it really dosent. native code can do the exact same sort of tricks. a pretty standard tool in detection evasions bag of tricks is to write a custom virtual machine that generates code on the fly, which makes static, signature based analysis of payloads totally useless.
- gizmo686 14y agoWhat keeps you from finger printing the VM just as easily?
- throwaway2048 14y agothe vm is eaiser to modify than the entire codebase, you have to update only one small bit of code, rather than everything. The vm is written with this in mind, and is trival to automaticly obfuscate/transform.
- beagle3 14y agoAnd yet, when I was working on an antivirus, back in 1989 (yes, that's 1989), we already had these viruses, and we were detecting them without problems - it wasn't just a static signature, granted, and back then we wrote a recognizer for each polymorphic virus (a quick first stage would have been served by a regular language back then, but we didn't use them for speed reasons; the whole program was assembly!)