- Title
- A novel malware for subversion of self-protection in anti-virus
- Creator
- Min, Byungho; Varadharajan, Vijay
- Relation
- Software: Practice and Experience Vol. 46, Issue 3, p. 361-379
- Publisher Link
- http://dx.doi.org/10.1002/spe.2317
- Publisher
- John Wiley & Sons
- Resource Type
- journal article
- Date
- 2016
- Description
- Major anti-virus solutions have introduced a feature known as ‘self-protection’ so that malware (and even users) cannot modify or disable the core functionality of their products. In this paper, we have investigated 12 anti-virus products from four vendors (AVG, Avira, McAfee and Symantec) and have discovered that they have certain security weaknesses that can be exploited by malware.We have then designed a novel malware, which makes use of the weaknesses in anti-virus software and embeds itself to become a part of the vulnerable anti-virus solution. It subverts the self-protection features of several anti-virus software solutions. This malware integrated anti-virus enjoys several advantages such as longevity (anti-virus is active while the system is running), improved stealthy behaviour, highest privilege and capability to bypass security measures. Then we propose an effective defence against such malware.We have also implemented the defensive measure and evaluated its effectiveness. Finally, we show how the proposed defence can be applied to the current versions of vulnerable anti-virus solutions without requiring signficant modifications.
- Subject
- security; anti-virus; self-protection; malware; vulnerability
- Identifier
- http://hdl.handle.net/1959.13/1356174
- Identifier
- uon:31627
- Identifier
- ISSN:0038-0644
- Language
- eng
- Reviewed
- Hits: 1614
- Visitors: 1783
- Downloads: 0
Thumbnail | File | Description | Size | Format |
---|