Search 
You are here: ArticlesNews from the Web   
ArticlesMinimize
IN FOCUS: Malware Evolves to Bypass Common Controls
Posted by SteveT on Thursday, December 20, 2007 :: Last Updated on Sunday, January 20, 2008:: Views 1974

   

by Mark Joseph Edwards, News Editor, mark at ntsecurity / net

Botnets and Trojans are huge headaches. They're everywhere, and their numbers are growing exponentially. Sometimes that kind of malware is discovered by security scanning software. Other times it's discovered by unusual traffic patterns sent to specific IP addresses, sometimes on atypical ports.

When you discover such malware, you can typically, monitor it to learn which IP addresses it's communicating with and then block access to those addresses. The blocking technique is particularly effective in stopping bots and Trojans. Therefore one key to survival for many types of malware is decentralization of malware command and control centers. The next wave of malware promises to make the task of blocking far more difficult.

In a new report, security solution maker Finjan describes upcoming trends in malware behavior. Finjan points out that instead of using typical point-to-point communication, new forms of malware will use seemingly harmless technologies and existing Web sites to mask their traffic.

Many Web sites, such as Google, Yahoo!, and Feedburner (to name just a few) are available for access from within enterprise networks and certainly from within most every home user's network. Traffic to and from such sites wouldn't seem unusual in most cases. Several companies (including the companies I just named) provide incredibly useful technologies such as RSS feed aggregation and data aggregation from disparate sources. Malware developers realize that and aim to take advantage of it by using these publicly available resources as a go-between.

In one type of scenario, a botnet operator could post a message to a site, such as a blog on a free blog hosting site (MySpace, for example).  Bots in the botnet could then download the blog's RSS feed, parse the content, extract commands, and act on them. In another scenario, spyware could do the same thing the bots do, but it could also post information back to the blog as comments if the blog is configured so that all comments must be approved before being published (thereby keeping any data out of sight). Or the spyware could post the data back to the blog as an unpublished post by using such technologies as XML-RPC.

The problem here is obvious. It's not reasonable to think you can protect your network by blocking access to sites in hopes of stopping botnets and spyware because any number of different sites could be used and blocking sites reduces overall Internet value. One solution that might help is packet content inspection, although that's not foolproof either. Any number of innocuous word combinations could be used as commands for bots and spyware. So we're facing a much more difficult problem to solve. Of course when it comes to security, an ounce of prevention is worth a megaton of cure, which means that you should use the best security products you can get.

Next week, I'll tell you about a particular set of preventive solutions and how they stack up against their peers. Until then, if you're interested, head over to Finjan's site and get a copy of its report. It's available in PDF format at

finjan.com/GetObject.aspx?ObjId=545
(http://ct.email.windowsitpro.com/rd/cts?d=33-876-803-202-5219-48838-0-0-0-1-2-207)

Previous Page | Next Page

COMMENTS


DonationsMinimize

Find our site useful? Make a donation to show your support

Donate

logo_ccMC.giflogo_ccVisa.giflogo_ccDiscover.giflogo_ccAmex.gif

ArGoStuff Supporters

 


News from ArGoSoftMinimize
1 2 3 4 5 6


Mail Server v1.0.8.3
  • Added support of STARTTLS (STLS) command for SMTP, POP3, IMAP, and SMTP relay and delivery, which will allow secure, fully encrypted connections, when possible;
11/6/2011 1:10:34 PM
Mail Server v1.0.8.2
  • Optimized delivery speed. In earlier versions each "tick" which was checking whether messages were in the outbox queue, was picking up only one message at a time. Now it will attempt to pick MaximumAllowedThreads-ActiveDelivery threads messages, which should considerably increase deliver speed;
  • Optimized SEARCH and STATUS IMAP commands. They appear to be used very extensively by Android, and (not that extensively, but still) by iPhone. Now users who use mobile phones to access their IMAP accounts will see considerable improvement;
  • Optimized STORE IMAP command. Before storing of IMAP flags was occuring one message at a time, which seemed to be fine with SQL server, but proved to be slow for SQLite... Now it happens with single SQL call.
10/8/2011 7:59:35 PM
ArGoSoft Mail Server v1.0.8.1
  • Fixed a bug: when using IMAP via Firefox with "When I delete a message, move it to Trash folder" option, marking messages in the trash folder was causing high CPU usage, and was taking some time, making the server pretty much non-responsive. The problem was happening only when using SQLite.
6/6/2011 9:33:36 PM
ArGoSoft Mail Server v1.0.8.0
  • Fixed a problem with web interface - was showing only first page of messages, and would not switch to other pages; In order to fix the web interface, mail server itself has to be updated;
  • When installint initially, was still using SQLite, even when SQL was requested;
  • There was a problem with switching from SQLite database engine to SQL server database engine: the SQL database was not being created;
5/23/2011 5:53:55 PM
ArGoSoft Mail Server .NET v1.0.7.9
  • The server no longer requires Microsoft SQL Server. If SQL server is not found, it will use SQLite engine, which does not require separate installation. If SQL server is found, then user will be prompted whether he wants to use it;
  • Made other improvements, such as, now mailbox rebuild indexes orphaned records, rather then deleting them, also added an opotion to increment UIDL validity of folder (both on the Mailbox viewer box);
  • Made minor improvements on web interface;
4/26/2011 9:47:25 PM


1 2 3 4 5 6

Protect Your Computer today withGet AVG Today


Home:ArGoStuff:Forums:Articles:Cyber Security Tips:FAQ:Downloads:Links
Copyright 2006-2011 by ArGoStuff Terms Of UsePrivacy Statement