Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Researchers warn that rootkits aren't the only threat

Other stealth techniques are equally effective -- and more imminent

August 3, 2007 12:00 PM ET

Computerworld - Rootkits may be getting most of the attention within the security community. But it's important not to overlook other, equally effective antiforensic techniques that malware writers have at their disposal for hiding their code from detection, according to a security researcher at the Black Hat 2007 conference.

Nick Harbour, a senior consultant at Alexandria, Va.-based security vendor Mandiant, outlined a few of those techniques during a presentation at the show. None of the methods are especially new, but they have been only scarcely documented.

One of the ways in which malware writers can hide their code from forensic discovery is via a method known as process injection. The technique involves the injection of malicious code into another legitimate running process on an end user's system, Harbour said, speaking with Computerworld after his presentation.

There are several methods of process injection available to hackers. The technique allows them to conceal the source of the malicious behavior in a computer. The technique can be used to bypass firewalls on client devices and other security defenses, because the process that has been injected with the malicious code would appear largely normal, he said.

Similarly, "a cleverly named process is often enough to fly beneath the radar and avoid immediate detection," Harbor said in his presentation. The idea is to inject a malicious process in a system and hide its presence by using slight variations on commonly running processes; the Svchost.exe and spoolsv.exe processes make the best targets because there are usually several of them running in memory. "One more will often go unnoticed," he said in his presentation.

Another approach that malware writers can use is to execute malicious code directly from memory on the compromised system. Doing this greatly enhances its stealth because it means the code never has to reside on the hard drive where it might be detected, Harbour said.

The first exploit demonstrating the technique dates back to 2000 and was Windows-specific, Harbour said in a white paper accompanying the presentation. The technique involved launching a process in a suspended state and then overwriting it with malicious code.

For instance, an attacker could launch notepad.exe in a suspended state and then overwrite it with sol.exe, causing a game of Solitaire to be presented to the user even though views in the task bar would make it appear that notepad was running, he said.

Such techniques are simpler to use and more commonly available than rootkits and therefore present a more imminent threat to companies, Harbour said.

Read more about security in Computerworld's Security Knowledge Center.



Jump to comments

rootkits

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs