Security hack
Dynamic code obfuscation techniques are the latest salvo from hackers
R E L A T E D   C O N T E N T
ADVERTISEMENT

Cyber-crooks switch to code obfuscation

Technique being used to bypass signature-based systems

Clement James, vnunet.com 12 Jan 2007
ADVERTISEMENT

Security firm Finjan has reported that dynamic code obfuscation was increasingly used as a method to bypass traditional signature-based security systems and propagate malware during the fourth quarter of 2006. 

The technique works by providing each visitor to a malicious site with a different instance of obfuscated malicious code, based on random functions and parameter name changes.

A conventional signature-based security solution would theoretically need millions of signatures to detect and block this particular piece of malicious code.

"Dynamic code obfuscation techniques are the latest salvo from hackers in the ongoing battle of wits between security vendors and their hacker opponents," said Yuval Ben-Itzhak, chief technology officer at Finjan.

"Over the years, each time a new type of attack appears in the wild, security companies scramble to create a solution. Then, as soon as the hackers become familiar with the newest defence, they devise a method to circumvent it."

Ben-Itzhak explained that this endless game of "cat and mouse" dates back to the early 1990s when virus writers created 'stealth' and polymorphic viruses to elude antivirus programs.

"Hackers have begun to take advantage of new web technologies to create complex and blended attacks," he added.

"With the creation of dynamic obfuscation utilities, which enable virtually anyone to obfuscate code in an automated manner, they have dramatically escalated the threat to web security."

The Finjan report also details two recently publicised incidents in which hackers used the Wikipedia encyclopaedia and MySpace social networking sites to infect users.

These incidents provided real-world examples of the use of Web 2.0 technologies to propagate malicious attacks.

Finjan said that 2006 saw the arrival of a diverse range of web-based infection techniques, including rogue anti-spyware, ransomware and rootkits, that elude traditional security solutions geared to protect against email viruses and spam.

Another development was the commercialisation of malicious code, as financial motivations played an increasing role in the evolution of malware.

Motivated by financial gain, hackers are trading vulnerabilities in online auctions, commercialising products such as malicious website creation toolkits, and developing new distribution techniques, including spam, for the propagation of malicious code.

Finjan predicts that as Windows Vista and Internet Explorer 7.0 begin to achieve critical mass during 2007, this development will trigger a new wave of exploits from professional hackers who have had time to prepare in advance.


All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
London, United Kingdom | MI6
Business Change Managers, £39,753 - £46,355 We're the Secret Intelligence Service. You may know us as MI6. Information is at the heart of everything we do. We operate around the world to gather intelligence which ... more >
London, United Kingdom | MI6
Junior SLA Manager, £32,443 - £37,925 We're the Secret Intelligence Service. You may know us as MI6. Information is at the heart of everything we do. We operate around the world to gather intelligence which ... more >
London, SW1H, United Kingdom | Metropolitan Police Service
Leading Service Technician, London, SW1H, £32, 625 - £37,130 Ensuring service delivery for business critical systems, you'll have a direct impact on the provision of IT support to operational policing at the Metropolitan Police Service. ... more >
Warrington, United Kingdom | Environment Agency
Enterprise Architect, Warrington, Salary and package to attract the best A highly demanding and challenging role requiring an individual who is capable of leading and advising IT professionals within IS and business colleagues. To be ... more >
More job opportunities