Microsoft Windows Vista Community Forums - Vistaheads
Driver Scanner 2009 - Free Scan Now



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Loveheart Dating - Find your Perfect Partner

Kernel Malware

Security News



Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Reply
  #1 (permalink)  
Old 02-28-2007
Paul's Avatar
Paul Paul is offline
Moderator
 

Join Date: Feb 2007
Location: wicklow mts
Posts: 9,495
Paul is on a distinguished road
Thanks: 0
Thanked 0 Times in 0 Posts
Kernel Malware
Last December, I blogged about the AVAR 2006 conference where I presented my paper on kernel malware. Finally, we are able to provide the material for our readers. Both the paper and slides are available in PDF format.

The paper – "Kernel Malware: The Attack from Within" – is about kernel malware, explaining what they are, how they work, and what makes their detection and removal challenging. It also looks at two interesting malware cases utilizing kernel-mode techniques to avoid detection and to bypass personal firewalls.
An important part of the paper was a statistical analysis run over a large sample set to investigate how the kernel malware trend has changed over the years. Details for the analysis can be found from the paper but I thought it would be nice also to post the results here. Below, we have two graphs demonstrating the change in kernel malware trends since year 2003 onwards.

The first graph shows how the number of kernel-mode driver samples has changed over the years. This data includes different variants of the same family. A more interesting graph is shown below, which illustrates the cumulative number of malware families utilizing kernel-mode components.

From these two graphs we can easily see how the trend has changed dramatically at the end of the year 2004. This is mostly explained by the increased number of malware starting to use kernel-mode rootkits to hide their presence on the compromised system.
Today, kernel-mode rootkits are much more common than their user-mode counterparts. There are many reasons for this. Kernel-mode rootkits are more powerful thus they are able to hide better. Documentation with examples and fully working source code is easily available – there are even books available that explain in detail how to write your own kernel-mode rootkit. Implementing a full-flexed user-mode rootkit is a complex task. It seems that for malware authors, it is much easier just to upgrade their user-mode malware with a cut-and-paste kernel-mode rootkit.

Signing Off,
Kimmo On 22/02/07 At 08:34 AM


More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Half of pirated Vista is malware Steve News & Announcements 0 02-19-2007 12:39


All times are GMT +1. The time now is 05:44.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.0.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119