left edge shadow
Allen Corporation of America
WetStone Technologies, Inc.
top menu - tab edge Home      members Customer Portal     shopping cart Shopping Cart     corporate Corporate     contact us Contact Us
main menu - top edge
content area - top edge
The Science of Digital Investigation - by Chet Hosmer
« Steganography vs. Digital WatermarkingForensic Network Mapping »

Will metamorphic malware hinder investigations?

06/30/08

Permalink 05:42:48 pm, by Chet Hosmer Email , 233 words   English (US)
Categories: Uncategorized

Will metamorphic malware hinder investigations?

As new more sophisticated and stealthy forms of malicious code arrive on the scene how will they affect digital investigations?

From the bottom up, the purpose of metamorphic code is to evade discovery and a variety of techniques are employed to help disguise the static forms (i.e. files stored on the hard-drive) while more sophisticated forms morph the running version of each propagated malicious code.

Traditional investigation techniques that use hash sets to identify either “known good” or “known bad” software components are of little value in identifying this type of contraband. Block hashing techniques offer little assistance except against the most primitive form (mainly polymorphic Malware) and is then only effective when used to identify code running in memory when the polymorphic code is most vulnerable to identification. Note, only limited hash sets are available for memory or running process based identification, clearly a broadening of efforts in this area is required.

In addition to methods that identify metamorphic code (statically or dynamically) other approaches include behavior identification (both host and/or network) that can model the activities of specific types of malicious code that exhibit metamorphic or polymorphic processes.

At the end-of-the-day our investigative methodologies need to also morph, as the move from post-mortem to live investigation becomes the rule.

Chet Hosmer is the Chief Scientist at WetStone and would like to hear your comments and feedback to his opinions.

March 2010
Sun Mon Tue Wed Thu Fri Sat
 << <   > >>
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      

Search

XML Feeds

blogging software
content area - bottom edge
right edge shadow