Attackers Evade Detection Using New Method

March 2nd, 2007

Further exposing the weaknesses of signature-based detection, cybercriminals have developed a new method to hide malicious code to evade detection.

Called dynamic code obfuscation, the method alters virus code using a different set of functions, parameter names and encryption keys for each user! For example, if two people visit a malicious Web site at the same time, each person will get a different encrypted or obfuscated code, generated on the fly.

“Security vendors that post security updates to their customers will need to theoretically create millions of signatures for their customers.”
– Yuval Ben-Itzhak,
Chief Technology Officer, Finjan Inc.

Article: “Attackers hide malicious code using new method

3 Responses to “Attackers Evade Detection Using New Method”

  1. The Command Line 2007-03-04 (Comment Line 360-252-7284) « The Command Line Says:

    [...] This week’s security alerts include malware targeting security software and malware authors using encryption and code obfuscation to defeat signature based defenses. [...]

  2. Rob Lewis Says:

    All the more reason to use use deny-by default, trusted systems that prevent unauthorized actions by any malware.

    External threats are increasing exponentially.

  3. Nick Says:

    Speaking of security absurdities:

    “Total malware volumes grew “dramatically” during the first three months of 2007 as the majority of malicious code writers began targeting the web, new research warned today”

    http://www.vnunet.com/vnunet/news/2188497/total-malware-volumes-grow

Leave a Reply