I've read anecdotal evidence that malware authors are purposefully inflating the size of their exploit kits to...
By submitting your email address, you agree to receive emails regarding relevant topic offers from TechTarget and its partners. You can withdraw your consent at any time. Contact TechTarget at 275 Grove Street, Newton, MA.
avoid detection by antivirus software. Does this method actually help avoid antivirus detection, and how can we detect this malware?
Ask the Expert!
SearchSecurity expert Nick Lewis is standing by to answer your questions about enterprise security threats. Submit your question via email. (All questions are anonymous.)
Malware authors are in a constant cat-and-mouse game with antimalware researchers. As soon as either makes an advance, the other counters it. In the recent attack on the New York Times, malware authors were reported to use exploit kits that changed the sizes and contents of malware files to avoid detection by signature-based antivirus.
However, changing only the size of the files will not prevent detection. The way signatures are generated for malware detection requires more sophisticated methods -- depending on the antivirus engine and the research teams -- but usually signatures are slightly more advanced than just comparing MD5 sums. Antimalware systems are designed to look for certain patterns or hashes within a file to identify malware and potential variants, regardless of size. Defensive systems have had to adapt to these types of techniques amid the rise in polymorphic or constantly changing malware, and often use heuristics (clues based on past malware detection) to improve detection rates. The use of heuristic techniques is one way false positives are introduced, but the overall improvements in detections outweigh the potential for false positives. If there are sufficient differences generated between malware produced, it might help the malware avoid detection.
These same techniques are used elsewhere to avoid signature-based detection. Avoiding signature-based intrusion detection has been accomplished by using no-op sleds (a programming technique) in shell code or exploit code, but no-op sleds can be detected. These techniques may not be effective against behavioral-based detection or whitelisting.
Dig Deeper on Malware, Viruses, Trojans and Spyware
Related Q&A from Nick Lewis
A malware tool that helped to compile the Zeus Trojan has been leaked on the Web. Expert Nick Lewis explains what this means for enterprise security ...continue reading
When it comes to state-sponsored attacks infecting mobile devices, do users have any chance of tracing the attack? Expert Nick Lewis offers some ...continue reading
Microsoft won't patch certain ASLR bypass flaws, but enterprises still need to protect against them. Expert Nick Lewis explains the threat and how to...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.