<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>ab origine ... : security</title><link>http://msmvps.com/blogs/v_scherbina/archive/tags/security/default.aspx</link><description>Tags: security</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>Seems like "malware" may have a chance to exist under Windows Vista</title><link>http://msmvps.com/blogs/v_scherbina/archive/2006/11/23/seems-like-malware-programs-may-have-a-chance-to-exist-under-windows-vista.aspx</link><pubDate>Thu, 23 Nov 2006 17:07:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:323056</guid><dc:creator>V. S.</dc:creator><slash:comments>0</slash:comments><description>&lt;p&gt;&lt;a href="http://arstechnica.com/news.ars/post/20061016-7998.html" style="font-weight:normal;" target="_blank"&gt;Microsoft to give Vista kernel access to security firms&lt;/a&gt;&lt;span style="text-decoration:underline;"&gt; &lt;/span&gt;- an interesting article that explains why Microsoft is going to publish new API to allow 3rd party security software to access the Vista kernel. This is a really amazing news, because once
these gates will be opened to 3rd party security software they can be (theoretically)
used by malware to gain the access to kernel.
&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=323056" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/v_scherbina/archive/tags/events/default.aspx">events</category><category domain="http://msmvps.com/blogs/v_scherbina/archive/tags/security/default.aspx">security</category></item><item><title>Choosing the undocumented ways when dealing with security. General thoughts.</title><link>http://msmvps.com/blogs/v_scherbina/archive/2006/11/08/Choosing-the-undocumented-ways-when-dealing-with-security.-General-thoughts_2E00_.aspx</link><pubDate>Tue, 07 Nov 2006 23:16:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:263497</guid><dc:creator>V. S.</dc:creator><slash:comments>0</slash:comments><description>&lt;p class="MsoNormal"&gt;&lt;span&gt;There is
some kind of a struggle in the newsgroups between those who accepts the
&amp;lsquo;undocumented&amp;rsquo; programming and those who does not. I will try to express my
thoughts concerning this issue here. &lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;Nowadays,
all popular AntiVirus (AV) software products can be divided into two main
groups: &lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;those
who has protection (and use undocumented staff)&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;and
those who does not (and use only documented approaches)&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;The
&amp;lsquo;protection&amp;rsquo; in this context is just some logical part of the product which ensures
that AV cannot be terminated by malware modules. The protection logics can be
implemented only using undocumented approaches, because Windows does not
provide interfaces to ensure that some code should always keep running.
Instead, Windows API provides flexible way to manage system resources. This of
course, means that any entity can obtain access to resources if it has
appropriate rights.&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;Such
situation leads to the following scenario.&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;The
malware module is able to terminate (any) process if it has appropriate rights.
&lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;The
malwares also can modify the memory, context, PEB, and other properties of a
process and make everything it wants in order to &amp;hellip; hide its activity. &lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;Malware
also can be represented as a rootkit &amp;ndash; this is even worse, because rootkits
have extremely big power, since they operate in kernel mode. &lt;/span&gt;&lt;/p&gt;

&lt;p class="MsoNormal" style="margin-left:36pt;text-indent:-18pt;"&gt;&lt;span&gt;&lt;span&gt;-&lt;span style="font-family:'Times New Roman';font-style:normal;font-variant:normal;font-weight:normal;font-size:7pt;line-height:normal;font-size-adjust:none;font-stretch:normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span&gt;&amp;hellip;&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;AntiVirus
software also tries to do its best. Those who does not have protection scheme
or those who does not use undocumented techniques fall into the limited ability
to control the system. In this situation the AntiVirus software tries to fully
control and filter all threats that are coming through acceptable for
controlling channels. &lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;A typical
example of the written above is the powerful heuristics that is used in
combination with file system filter driver (fully documented approach), which
does not allow malware even to be copied on the target PC. And thus, there is
no need to protect AV module &amp;ndash; because heuristics will do the job. The
disadvantage of this way is that if the system makes error &amp;ndash; i.e. it treats
malware as a normal executable, it (possibly) has no chances to control the
system after the one mistake &amp;hellip;&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;However,
there is another approach. Combining documented ways with the undocumented. This
involves new challenges and brings new problems. Undocumented is prone to
changes. It means that once next build of OS or SP will be shipped AV makers
probably will need to rewrite their code. In this case they may even globally
change the architecture of the product because some major features can be cut
from OS. &lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;The
positive side of this approach is that it provides extended challenges to
control the OS. Thus, properly written AV that uses protection schemes is
almost impossible to bypass by malware. Why I say &amp;lsquo;impossible&amp;rsquo;? Because
software programs are written by the people. People do mistakes. If there is a
need to bypass AV the malware writer can use exotic ways to accomplish that. I
will discuss these ways later in my next posts. &lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;Summarizing.
&lt;/span&gt;&lt;/p&gt;



&lt;p class="MsoNormal"&gt;&lt;span&gt;&amp;lsquo;Protection&amp;rsquo;
is a set of complex methods that allows controlling different facilities of
operating system. These facilities cannot be controlled without interaction
with undocumented techniques, because public API gives you a limited ability to
control OS. The more directions are controlled the higher possibility that you
may catch the bad thing &amp;lsquo;on a fly&amp;rsquo; and do not allow it to harm your OS. &lt;/span&gt;&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=263497" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/v_scherbina/archive/tags/security/default.aspx">security</category></item></channel></rss>