munotes®

Virus Countermeasures

Get access to whole semester resourcesSemester Pass

Chapter Ninety

Syllabus topic Module 2, "Malicious Software: Virus Countermeasures"

Pages 603 to 608 of 678

In one line

No single defence finds everything, so the answer is layers: keep the malware out (patching, least privilege, filtering), find what gets in (scanning, emulation, integrity checks), and stop what is found from doing harm (behaviour blocking, quarantine, backups).

In the words an answer should use: the ideal solution to the threat of viruses is prevention, but prevention is rarely achieved, so the realistic approach is detection, identification and removal. Antivirus software has developed through four generations: first generation, simple scanners that need a virus signature and can also check a program's length; second generation, heuristic scanners, which look for fragments of code often associated with viruses or use integrity checking with checksums; third generation, activity traps, memory-resident programs that identify a virus by the actions it takes rather than its structure; and fourth generation, full-featured protection, packages that combine scanning and activity traps with access controls that limit the ability of viruses to reach files at all.

Prevention, and why it is first

NIST's guide organises prevention into five kinds of measure, and every one of them removes work from the scanner.

MeasureExamples from SP 800-83
Policywhat may be installed, what may be attached to email, who may use removable media
Awarenessteaching people to recognise phishing and social engineering, which is how most malware arrives
Vulnerability mitigationpatching, and least privilege, because "malware often requires administrator-level privileges to exploit vulnerabilities successfully"
Threat mitigationantivirus, intrusion prevention, firewalls, content filtering, application whitelisting
Defensive architecturesandboxing, keeping browsers separate, protecting the firmware

Least privilege is the cheapest of these. A student account that cannot write to program directories cannot have its programs infected by anything it runs, whatever the antivirus misses.

The four generations of antivirus

This is the textbook's classification of how antivirus software developed.

GenerationCalledWorks byBeaten by
Firstsimple scannermatching a known signature; checking a program's lengthany variant; the compression trick
Secondheuristic scannerlooking for fragments and structures typical of viruses; integrity checking, storing a checksum of each file and recomparingan attacker who can also update the stored checksums; encrypted checksums answer that
Thirdactivity trapstaying in memory and watching for actions typical of a virus, rather than structurenothing structural; but legitimate programs take those actions too
Fourthfull-featured protectioncombining scanning and activity traps with access control, so that malware cannot reach what it wantspoor configuration, and users who approve whatever they are asked

Generic decryption is the answer to the encrypted and polymorphic viruses of the previous chapters. The scanner runs the suspect file inside an emulator, a sealed interpreter where nothing it does touches the real machine, and waits: a masked virus must unmask itself before it can run, and the moment it does, the scanner recognises the body. The difficulty is knowing how long to wait, because the scanner must not spend too long on a file that is simply slow to start.

munotes.in603

Virus Countermeasures

The digital immune system is the textbook's account of a proposal from IBM: when a machine finds something suspicious, it sends the sample to a central analysis machine, which runs it in an emulated environment, works out how to recognise and remove it, and sends the answer back to every machine on the network, so that one victim protects the rest. The idea survives today in the way antivirus products send suspicious files to their makers' analysis systems and receive new definitions within hours.

Behaviour-blocking software is the fourth generation's core: it runs alongside the operating system and watches what a program does, an attempt to open a file for writing, to change system settings, to open a network connection, and blocks or asks before the action completes. Its advantage over a scanner is that it does not need to have seen the malware before. Its cost is that legitimate software does many of those things too, which is the false-alarm problem the run measures.

The run: four defences on the same files

The listing takes eight files, five of them harmful, and applies four defences: a scanner looking for known bytes, an emulating scanner, an integrity check against the hash each file had when it was installed, and a behaviour blocker that flags any program that writes to other programs. Nothing runs: the samples are byte strings, and every figure in the summary is counted by the program.

# Four defences measured against the same set of files, and then used together.
# Everything here is a detector: the "samples" are ordinary byte strings that never run.
import hashlib

SIGNATURE = b'\x8b\x45\xfc\x83\xc0\x01\x89\x45\xfc\xeb\xe2'   # the bytes a scanner was given
STUB = b'\x31\xc9\xb1\x0b\x80\x34\x0e'                         # a fixed unmasking loop

def masked(data, key):
    return bytes(b ^ key for b in data)

PROGRAM = b'GRADES REPORT v2\x00' + bytes(range(64)) * 3
UPDATER = b'COLLEGE UPDATER v4\x00' + bytes(range(48)) * 2
# name -> (as installed, as it is now, is it harmful, does it write to other programs)
SAMPLES = {
    'notes.exe':     (PROGRAM, PROGRAM, False, False),
    'report.exe':    (PROGRAM + b'\x00' * 32, PROGRAM + b'\x00' * 32, False, False),
    'setup.exe':     (PROGRAM, PROGRAM + SIGNATURE, True, True),
    'game.exe':      (PROGRAM, PROGRAM + STUB + masked(SIGNATURE, 0x11), True, True),
    'demo.exe':      (PROGRAM, PROGRAM + STUB + masked(SIGNATURE, 0x7d), True, True),
    'tool.exe':      (PROGRAM, PROGRAM + b'\x33\xc9\xb9\x0b' + masked(SIGNATURE, 0x42), True, True),
    'macro.doc':     (PROGRAM, PROGRAM + b'\x90' * 40, True, True),
    'patcher.exe':   (UPDATER, UPDATER, False, True),          # writes to programs for a living
}
NOTE = {'setup.exe': 'carries known bytes', 'game.exe': 'the same, masked',
        'demo.exe': 'masked, another key', 'tool.exe': 'masked, stub rewritten',
        'macro.doc': 'never seen before', 'patcher.exe': 'a real updater',
        'notes.exe': 'untouched', 'report.exe': 'untouched'}

# ---- the four defences ------------------------------------------------------------------------
def simple_scanner(blob):
    """First generation: does the file contain a sequence of bytes on the list?"""
    return SIGNATURE in blob

def emulating_scanner(blob):
    """Generic decryption: let the suspect run in a sealed interpreter until it reveals its
    own body, then scan what was revealed. Here: undo what the fixed stub would undo."""
    if simple_scanner(blob):
        return True
    if STUB not in blob:
        return False
    body = blob[blob.index(STUB) + len(STUB):]
    return any(SIGNATURE in masked(body, key) for key in range(256))

def integrity_check(installed, now):
    """Has this file changed since it was installed and its hash written down?"""
    return hashlib.sha256(now).hexdigest() != hashlib.sha256(installed).hexdigest()

def behaviour_blocker(writes_to_programs):
    """Fourth generation: watch what a program DOES, and stop it before harm is done."""
    return writes_to_programs

DEFENCES = ('scanner', 'emulating', 'integrity', 'behaviour')
print('WHAT EACH DEFENCE SEES')
print('   %-13s %-22s %-5s %-8s %-9s %-9s %s'
      % ('file', 'what it is', 'bad?', *DEFENCES))
score = {d: [0, 0] for d in DEFENCES}
for name, (installed, now, harmful, writes) in SAMPLES.items():
    verdict = {'scanner': simple_scanner(now), 'emulating': emulating_scanner(now),
               'integrity': integrity_check(installed, now), 'behaviour': behaviour_blocker(writes)}
    for d in DEFENCES:
        score[d][0 if harmful else 1] += verdict[d]
    print('   %-13s %-22s %-5s %-8s %-9s %-9s %s'
          % (name, NOTE[name], 'yes' if harmful else 'no',
             *['FLAG' if verdict[d] else '-' for d in DEFENCES]))

harmful_total = sum(1 for v in SAMPLES.values() if v[2])
clean_total = len(SAMPLES) - harmful_total
print()
print('   %-11s %-22s %s' % ('defence', 'harmful caught', 'clean wrongly flagged'))
for d in DEFENCES:
    print('   %-11s %-22s %s' % (d, '%d of %d' % (score[d][0], harmful_total),
                                 '%d of %d' % (score[d][1], clean_total)))

together = [0, 0]
for name, (installed, now, harmful, writes) in SAMPLES.items():
    flagged = (emulating_scanner(now) or integrity_check(installed, now)
               or behaviour_blocker(writes))
    together[0 if harmful else 1] += flagged
print('   %-11s %-22s %s' % ('all four', '%d of %d' % (together[0], harmful_total),
                             '%d of %d' % (together[1], clean_total)))
print()
print('   the one clean file still flagged is the updater, which writes to other programs')
print('   because that is its job: somebody has to decide that, once, and record the decision')
munotes.in604

Virus Countermeasures

WHAT EACH DEFENCE SEES
   file          what it is             bad?  scanner  emulating integrity behaviour
   notes.exe     untouched              no    -        -         -         -
   report.exe    untouched              no    -        -         -         -
   setup.exe     carries known bytes    yes   FLAG     FLAG      FLAG      FLAG
   game.exe      the same, masked       yes   -        FLAG      FLAG      FLAG
   demo.exe      masked, another key    yes   -        FLAG      FLAG      FLAG
   tool.exe      masked, stub rewritten yes   -        -         FLAG      FLAG
   macro.doc     never seen before      yes   -        -         FLAG      FLAG
   patcher.exe   a real updater         no    -        -         -         FLAG

   defence     harmful caught         clean wrongly flagged
   scanner     1 of 5                 0 of 3
   emulating   3 of 5                 0 of 3
   integrity   5 of 5                 0 of 3
   behaviour   5 of 5                 1 of 3
   all four    5 of 5                 1 of 3

   the one clean file still flagged is the updater, which writes to other programs
   because that is its job: somebody has to decide that, once, and record the decision
munotes.in605

Virus Countermeasures

What the run establishes, in order.

A plain scanner finds only what it has been given. One of five, the file carrying the exact bytes on its list. It raises no false alarms at all, which is why scanning remains the first line: it is cheap and quiet.

Emulation recovers the masked ones. Three of five, because unmasking is something the file must do to itself. The one that rewrote its unmasking routine defeats it here, and so does the one nobody has seen before.

Integrity checking finds every changed file and accuses nobody. Five of five with no false alarms, because it compares each file against its own hash from installation and asks nothing about what malware looks like. Its two costs are that the baseline must be recorded before the trouble starts, and that it must be stored where an attacker cannot rewrite it.

Behaviour blocking finds everything and argues about the updater. Five of five, and one false alarm: a legitimate updater writes to other programs, which is its job. That is the permanent trade of behaviour-based defence, and it is the base-rate problem of the intrusion-detection chapters in a new place: the answer is not a cleverer rule but a decision recorded once, that this updater is allowed to do this.

Layers work because their blind spots differ. All four together catch all five, and the only disagreement left is a question for a person, not for a program.

What a college laboratory should actually do

For a laboratory of ordinary Windows or Linux machines, in the order that gives the most safety for the least effort:

  1. Patch automatically. Both worms in the previous chapter had patches out for months or weeks.
  2. Take away administrator rights from the accounts students use.
  3. Keep antivirus on and updated, configured as NIST describes: on-access scanning of files as they are opened, regular full scans, and scanning of removable media before use.
  4. Filter at the gateway so that executable attachments and known bad sites do not reach the machines.
  5. Restore, do not clean. A laboratory machine should be rebuilt from a known good image rather than disinfected; the image is the integrity baseline.
  6. Back up what cannot be rebuilt, offline, and test a restore. Against ransomware this is the only defence that always works.
  7. Report. In India CERT-In's directions require reporting the listed incidents within six hours, and keeping 180 days of logs.
munotes.in606

Virus Countermeasures

Distinctions that carry marks

Signature scanningIntegrity checkingBehaviour blocking
Asksdoes this look like known malware?has this file changed?what is this program doing?
Finds new malwarenoyes, once it changes somethingyes
False alarmsvery fewfew, if the baseline is rightmany, from legitimate software
Needsa signature list, updateda trusted baseline, protectedrules about what is allowed
When it actsbefore the file runsafter the change, before it runsas the harm is attempted
DetectionIdentificationRemoval
Questionis something wrong?which malware is it?put the system back as it was
If it failsthe infection continuesthe right removal is unknownthe file must be replaced from backup

What beginners get wrong here

Treating antivirus as the whole defence. It is one of five kinds of measure in NIST's list, and the cheapest wins, patching and least privilege, come before it.

Thinking a checksum must be secret. It must be correct and protected from being rewritten; encrypted or signed checksums exist so that an attacker who changes a file cannot also change its recorded hash.

Expecting behaviour blocking to be quiet. It flags legitimate updaters and installers; a defence that watches actions must be tuned, and the tuning is a decision somebody records.

Believing disinfection always works. NIST notes that "many infected files cannot be disinfected", and says software should quarantine or delete what it cannot clean; for a laboratory, rebuilding from an image is better still.

Quick revision

  • Ideal is prevention; in practice detection, identification, removal.
  • NIST's prevention: policy, awareness, vulnerability mitigation (patching, least privilege), threat mitigation (antivirus, IPS, firewalls, filtering, whitelisting), defensive architecture (sandboxing, browser separation).
  • Four generations: simple scanner (signature, length), heuristic scanner (fragments, integrity checking), activity trap (actions, memory-resident), full-featured (scanning plus traps plus access control).
  • Generic decryption: run the suspect in an emulator until it unmasks itself, then scan.
  • Digital immune system: sample sent to a central analyser, a cure derived and distributed to everyone.
  • Behaviour blocking: watches actions, catches the unknown, argues with legitimate updaters.
  • Run: scanner 1 of 5, emulation 3 of 5, integrity 5 of 5 with no false alarms, behaviour 5 of 5 with one.
  • A laboratory: patch, no administrator rights, antivirus on-access, gateway filtering, rebuild from images, offline backups, report to CERT-In in six hours.

Test yourself

1. Describe the four generations of antivirus software. The first generation is the simple scanner, which requires a virus signature to identify it and may also record and check program lengths; it can only find viruses that are already known. The second generation is the heuristic scanner, which does not rely on a specific signature but looks for fragments of code and structures typical of viruses, or uses integrity checking, storing a checksum for each file and recomputing it to detect change. The third generation is the activity trap, a memory-resident program that identifies a virus by the actions it takes rather than by its structure. The fourth generation is full-featured protection, packages that combine scanning and activity traps with access control so that malware cannot reach the files it wants.

munotes.in607

Virus Countermeasures

2. What is generic decryption, and what problem does it solve? It answers encrypted and polymorphic viruses, whose body is masked differently in every copy so that no fixed signature matches. The file is run inside an emulator, a controlled interpreter in which nothing it does affects the real machine. Because the virus must unmask its own body before it can run, it reveals itself, and the scanner then matches the revealed body against its signatures. The practical difficulty is deciding how long to let a file run before concluding it is clean.

3. Explain behaviour-blocking software, with its advantage and its weakness. Behaviour-blocking software is integrated with the operating system and monitors the actions programs take, such as opening files for writing, altering system settings, formatting disks or opening network connections, and blocks or queries actions that violate policy before they complete. Its advantage is that it can stop malware nobody has seen before, because it judges behaviour rather than appearance. Its weakness is that legitimate programs, updaters and installers in particular, take the same actions, so it raises false alarms and requires decisions about what is permitted.

4. What is a digital immune system? It is the approach in which a machine that detects suspicious behaviour sends the sample to a central administrative machine, which runs it in an emulated environment to analyse its behaviour, derives a way to recognise and remove it, and distributes that to every machine on the network, so that the experience of one victim immunises the rest. Antivirus products today work in much the same way, sending suspicious files to their makers and receiving updated definitions.

5. What would you do to protect a college computer laboratory from malware? Apply operating system and application patches automatically, since recent worms exploited flaws whose patches were already published; remove administrator rights from the accounts students use, since much malware needs them; run antivirus software configured for on-access scanning, regular full scans and scanning of removable media; filter executable attachments and known bad sites at the gateway; rebuild machines from a known good image rather than trying to disinfect them; keep offline backups of anything that cannot be rebuilt and test restoring them, which is the only reliable answer to ransomware; and report incidents to CERT-In within six hours, keeping 180 days of logs as its directions require.

munotes.in608

The rest of this subject

These notes are cut from the University's printed syllabus. Open the syllabus itself for the same subject.

Issue
Done!