How to block stealthy malware attacks
November 4th, 2009 - 2:00 pm ICT by ANI ( Leave a comment )Washington, Nov 4 (ANI): Researchers from North Carolina State University have devised a novel way to block rootkits, one of the most insidious types of malware, preventing them from taking over computer systems.
Malware or computer viruses is a growing problem that can lead to crashed computer systems and stolen personal information.
A recent Internet security threat report showed a 1,000 percent increase in the number of new malware signatures extracted from the in-the-wild malware programs found from 2006 to 2008.
Rootkits typically work by hijacking a number of “hooks,” or control data, in a computer’s operating system.
“Hackers can use rootkits to install and hide spyware or other programs. When you start your machine, everything seems normal but, unfortunately, you’ve been compromised,” said Dr. Xuxian Jiang, assistant professor of computer science at NC State and a co-author of the research.
“By taking control of these hooks, the rootkit can intercept and manipulate the computer system’s data at will essentially letting the user see only what it wants the user to see,” Jiang added.
As a result, the rootkit can make itself invisible to the computer user and any antivirus software. Furthermore, the rootkit can install additional malware, such as programs designed to steal personal information, and make them invisible as well.
In order to prevent a rootkit from insinuating itself into an operating system, Jiang said that all of an operating system’s hooks need to be protected.
“Our research leads to a new way that can protect all the hooks in an efficient way, by moving them to a centralized place and thus making them easier to manage and harder to subvert,” said Jiang.
Jiang revealed that by placing all of the hooks in one place, researchers were able to simply leverage hardware-based memory protection, which is now commonplace, to prevent hooks from being hijacked.
They were able to put hardware in place to ensure that a rootkit cannot modify any hooks without approval from the user. (ANI)
- BLADE software eliminates threats of 'drive-by downloads' from Internet - Oct 07, 2010
- Malicious software can invade smart phones, warns Indian American - Feb 23, 2010
- MP3 can cost you your car - Mar 17, 2011
- Arrests made in malware fraud case which infected millions of computers worldwide - Nov 10, 2011
- AV Security Suite: Wolf In The Clothing Of Lamb - Jun 08, 2010
- New security threat against 'smart phone' users identified - Feb 23, 2010
- Users at risk of IE bug, warns Microsoft - Dec 24, 2010
- New malware could knock out antivirus systems - Dec 12, 2011
- Best Sites To Watch Tv On Computer - Oct 02, 2010
- Soon, software systems that can sense user's activity - Jun 23, 2010
- 20pc of Facebook users exposed to malware - Nov 25, 2010
- Government May License Internet In Near Future? - Oct 08, 2010
- Buy original software, Microsoft tells people in Lucknow - Apr 06, 2011
- Microsoft warns about flaw that makes hacking easier - Dec 26, 2010
- Top US officials' gmail hit by Chinese phishing - Jun 02, 2011
Tags: antivirus software, assistant professor, centralized place, co author, computer science, computer system, computer systems, computer user, computer viruses, internet security, malware, memory protection, nc state, north carolina state university, operating system, rootkit, s hooks, security threat, signatures, system hackers