funsec mailing list archives

Re: write viruses? it's controversy time of the month


From: Drsolly <drsollyp () drsolly com>
Date: Wed, 30 Aug 2006 19:37:46 +0100 (BST)

On Wed, 30 Aug 2006, Dude VanWinkle wrote:

On 8/30/06, Drsolly <drsollyp () drsolly com> wrote:
On Wed, 30 Aug 2006, Dude VanWinkle wrote:

On 8/30/06, Blue Boar <BlueBoar () thievco com> wrote:
Drsolly wrote:
Uh - no. That's not being a good guy. Being a good guy, means you deleted
all copies of the virus.

Speaking of which, do you want Consumer Reports to delete their 5500
"viruses", or do you want them to submit them to AV to see if they are
really viral?


rhetorical question alert!!

since most viruses are met with applications that analyze them (99%)
the addition of 5.5k would only help the analysis or prove 99% of the
company is useless ;-)

Sorry, I don't think I speak the same language you do - could you reword
that for me, please?


I did an eval of most AV companies for the Campus AntiVirus review. A
lot of them were bragging about their auto analysis software. If a
client picks up a possible "unknown" virus, it is sent to the AV
companies servers for analysis. I was told by Kaspersky that 90 some
odd percent of the files sent are analyzed by a fully automated
process, and the "tricky ones" that the automated process couldnt
handle were analyzed by humans. I just assumed this was industry
standard.

Did I assume wrong?

A very large percentage of files sent for analysis, can be run against two 
programs. The first program you use is "trashcan", which has a database of 
MD5s for known files that aren't malware. For example, FORMAT.COM from 
various versions of Dos was often sent in as a suspect file. Once you've 
checked that the file really is bit-identical to one of the FORMAT.COM's 
that you know, then no further analysis need be done. And you can extend 
that to trojans; if it's bit-identical to a known trojan, no further 
analysis is needed.

You might think that this is an obvious thing to do, but before I did it, 
I don't think anyone else had thought of the idea.

The second program is one that does *exact* identification of viruses, by 
checksumming all the static code of the virus. I used Findvirus for this 
(I don't know if there's other scanners that can do exact id).

So, that might eliminate 90% of files sent in, right there.

Then there's the files that aren't eliminated by Trashcan.
 
I had an automated analysis program round about 1991, but there was still 
some that needed to so by hand - it wasn't entirely automatic. I imagine 
that things have improved a bit since then, but you can never entirely 
automate the process, all you can do is get as much help as possible from 
these helper systems.


_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: