4 ms·
Cleaning up a modern malware infection is quite a big task. You can't immediately wipe it off a single computer because you will be playing whack-a-mole forever
by thornjm 12y ago
Cleaning up a modern malware infection is quite a big task. You can't immediately wipe it off a single computer because you will be playing whack-a-mole forever.
You have to carefully monitor and learn everything you can about the malicious actor, and discover all the infections. Then produce a plan to remove it and prevent further infection. This is all implemented at a single instant.
However, it doesn't end there, you then have to monitor very carefully to see if it comes back. If this can all be done in secret it is much easier, especially if the malicious actor doesn't know you know they are there.
If you immediately reported everything you knew it would greatly assist the malicious actor - keeping it secret is part of trying to stay ahead in the game. Even after the first incident keeping it secret helps with future incidents.
- noinsight 12y ago> Cleaning up a modern malware infection is quite a big task. And the only way to clean up a compromised computer is a full reinstall. You can't possibly know what has happened on the compromised computer during the compromise. This is what the desktop support jockeys and most companies get wrong - obviously it's probably because of the cost associated with a full reinstall, but it doesn't make it any less valid. If it costs too much, companies should then focus on preventing machines getting compromised in the first place. Think about it, if I ask you to hand over your laptop for say, an hour, during which I have completely free reign over it, can you tell me everything I've done during that hour and all the backdoors installed, if any? And to nitpick, obviously these days not even a full reinstall might do it when there's BIOS viruses and even hard drive firmwares can be compromised etc. of course.
- new299 12y agoUnless you reinstall all your systems simultaneously and close whatever vector was used in the attack at the same time, reinstalling might not help. As long as the attacker has at least one route into the organization at anyone time, the possibility of reinfection exists. So I guess it's wise to take a coordinated approach.
- colordrops 12y agoIsn't it possible to clean up a compromised computer if hash of everything installed and an external audit log of installations is maintained? You could scan the drive of the machine externally and know what bits have been compromised.
- danieldk 12y agoHow do you gather the hashes? The machine itself (obviously) couldn't do it, since the malware may have changed the system to always report correct hashes (and/or send the original binaries). So, it means what you mean by 'externally' and how sophisticated you expect the malware to be.
- colordrops 12y agoFor pre-installed files, you have hashes that are publicly known. Afterward, you continue to set the hash with each modification to a file, and report it over the network or to an external device. If you can identify the time of infection, you know which hashes are good. After you get the infected machine, you pull out the drive and scan it externally, looking for bad hashes and files that shouldn't be there.
- likeowned 12y ago"Think about it, if I ask you to hand over your laptop for say, an hour, during which I have completely free reign over it, can you tell me everything I've done during that hour and all the backdoors installed, if any?" Yes, I can. Read up on modern digital forensics. Everything you do on a machine leaves a trace and there are ways to recover those traces and put together exactly what you did. That is exactly what Incident Response/Digital Forensics Firms do. An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine and what other machines were compromised before they even started talking remediation. Wiping the one machine that you got an alert on would do absolutely nothing to solve the problem.
- noinsight 12y agoGranted I'm not an expert, but I'm not confident that you could tell everything, at least not in the default configuration of desktop OSes without special auditing in place. Some stuff, sure. > An IR firm would never tell you to just reimage a machine when you're dealing with an advanced attacker. They'd want to go through, use the tools they have to identify exactly what happened on the machine Yes, I was talking more in the run-of-the-mill case sense, not regarding thorough forensic investigations. If you're actually going to investigate the incident deeper, you should at least get memory dumps, process dumps and an image of the machine and such. In my experience though, at most companies the SOP is just monitoring standard antivirus stuff and then when an infection comes up, it either gets automatically cleaned or someone goes over and fixes it with a manual scan or whatever. Which is completely inadequate.
- scintill76 12y agoI'll admit to a fairly casual acquaintance with digital forensics, but I disagree, if for no other reason than you didn't really address all the possibilities of the scenario given. I'd be happy to hear if I am in turn missing something. Forensic analysts are good at tracing activities done from within a system, and/or by entities that don't know a lot about forensics or don't have system privileges to cover their tracks. I read noinsight's scenario as involving physical access by a skilled attacker. If one shut down the laptop, pulled out the hard drive, mounted it on another system, modified a single sector of a document that doesn't exist anywhere else (and the laptop owner isn't perceptive enough to notice the change), preserved file metadata, and placed the drive back in the laptop, what would digital forensics be able to tell you? Only the details of the system being shut down, I'd guess. Maybe if they paid tens of thousands of dollars to a specialized lab, they could find faint magnetic traces of the former contents of the changed sector, but I'm not sure that's in the scope of what you meant. If all that was done was read the drive, there'd be even less chance of determining what was read. As mentioned, the attacker might compromise the BIOS or firmware, and while that would be detectable, I think only the highest-end IR firms would look for it, let alone have the resources to identify subtle changes. Even working within the system, I'd say many attackers can remove traces such that many investigators won't find them, by doing things like deleting created logs, restoring file metadata to its original state, and writing over the erased evidence multiple times. (This perhaps assumes root access and a consumer-grade OS in default configuration.) It might lead to a suspicious state where the system has been running for hours with no artifacts that would routinely be left, but the investigator might not be able to determine much of what was done. It might be as simple as using a browser the investigators don't check: http://www.cbsnews.com/news/casey-anthony-detectives-overlooked-google-search-for-fool-proof-suffocation-methods-sheriff-says/ http://www.cbsnews.com/news/casey-anthony-detectives-overloo...