metamorphic viruses pat walpole. introduction what are metamorphic viruses why they are dangerous...

12
Metamorphic Viruses Pat Walpole

Post on 21-Dec-2015

213 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Metamorphic Viruses

Pat Walpole

Page 2: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Introduction

• What are metamorphic viruses

• Why they are dangerous

• Defenses against them

Page 3: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Virus Camouflage Types

• None

• Encrypted

• Polymorphic

• Metamorphic

Page 4: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

No Camouflage

Myles Jordan [1]

Page 5: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Encrypted

Myles Jordan [1]

Page 6: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Polymorphic

Myles Jordan [1]

Page 7: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Metamorphic

Myles Jordan [1]

Page 8: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Why Metamorphism is a Problem

• Provides excellent camouflage for the virus code

• Difficult for anti-virus programs to detect

• Difficult for an IDS to detect

Page 9: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

General Virus Defenses

• Do not run or install software from an untrusted source

• Do not open email attachments unless you are 100% sure they are from a trusted source

• Use a good antivirus program and keep it updated

Page 10: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Anti Virus Program Techniques

• Run suspected files in an emulator

• Perform heuristic analysis on the behaviors of the program– False positives– May not find viruses that are event based

Page 11: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

Conclusion

• Virus writers will always find ways to beat anti-virus protection

• Metamorphism is a very effective camouflage technique

• Keep your computer protected and practice safe computing

Page 12: Metamorphic Viruses Pat Walpole. Introduction What are metamorphic viruses Why they are dangerous Defenses against them

References

• [1] Jordan, Myles. Anti-Virus Research Dealing with Metamorphism. http://www3.ca.com/securityadvisor/newsinfo/collateral.aspx?cid=48051