A novel malware for subversion of self‐protection in anti‐virus. (3rd February 2015)
- Record Type:
- Journal Article
- Title:
- A novel malware for subversion of self‐protection in anti‐virus. (3rd February 2015)
- Main Title:
- A novel malware for subversion of self‐protection in anti‐virus
- Authors:
- Min, Byungho
Varadharajan, Vijay - Abstract:
- Summary: Major anti‐virus solutions have introduced a feature known as 'self‐protection' so that malware (and even users) cannot modify or disable the core functionality of their products. In this paper, we have investigated 12 anti‐virus products from four vendors (AVG, Avira, McAfee and Symantec) and have discovered that they have certain security weaknesses that can be exploited by malware. We have then designed a novel malware, which makes use of the weaknesses in anti‐virus software and embeds itself to become a part of the vulnerable anti‐virus solution. It subverts the self‐protection features of several anti‐virus software solutions. This malware integrated anti‐virus enjoys several advantages such as longevity (anti‐virus is active while the system is running), improved stealthy behaviour, highest privilege and capability to bypass security measures. Then we propose an effective defence against such malware. We have also implemented the defensive measure and evaluated its effectiveness. Finally, we show how the proposed defence can be applied to the current versions of vulnerable anti‐virus solutions without requiring signficant modifications. Copyright © 2015 John Wiley & Sons, Ltd.
- Is Part Of:
- Software, practice & experience. Volume 46:Number 3(2016)
- Journal:
- Software, practice & experience
- Issue:
- Volume 46:Number 3(2016)
- Issue Display:
- Volume 46, Issue 3 (2016)
- Year:
- 2016
- Volume:
- 46
- Issue:
- 3
- Issue Sort Value:
- 2016-0046-0003-0000
- Page Start:
- 361
- Page End:
- 379
- Publication Date:
- 2015-02-03
- Subjects:
- security -- anti‐virus -- self‐protection -- malware -- vulnerability
Computer software -- Periodicals
Computer programming -- Periodicals
Computer programs -- Periodicals
005.3 - Journal URLs:
- http://onlinelibrary.wiley.com/ ↗
- DOI:
- 10.1002/spe.2317 ↗
- Languages:
- English
- ISSNs:
- 0038-0644
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 8321.453000
British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 154.xml