sproutedlist.com
Search:    Main >> About Us >> Privacy >> ToS >> Place Your Link >> Add Article   
Add Url
 

Healthcare & Medicine

Tour & Travel

Business & Companies

Adventure & Sports

Software & Networking

Lifestyle & Fashion

Shopping & Auction

Indoor Games

Policies & Law

Jobs & Careers

Issues & News

Academics & Learning

Self Management

Society & Communities

Creative Arts

Teens & Children

Automobiles

Recreation

Estate & Realty

Garden & Home

Fitness & Health

Banking & Finance

Eating & Drinking

Science & Space


 

Main » Software & Networking » Internet Firewalls & Security
 

SubVirt - the prototype of the next generation malware

 
Author: Matija Vidmar
 

In the last few years the most dangerous computer viruses are disappearing. Macro viruses and script viruses are almost extinct.

But in the meantime there was an increase of trojan, backdoor, rootkit and spyware which can be used to remotely control a pc. There was an increment of malware that includes spyware programs from 54.2% to 66.4%.

Rootkits are becoming famous. They are used by virus writers to remotely control infected computers and use them for stealing money and perform DDOS attacks.

In the Windows world the rootkit term is usually used to describe viruses and malware programs that use a special technique to hide into the system environment. In Unix environment, rootkits are usually rewritten tools of the operating system that are used to hide data from the users. For example the ls command can be rewritten so that it doesn't show certain files.

There exist user-mode rootkits and kernel-mode rootkits. User-mode rootkits are basically normal processes that can be easily detected and eliminated. Kernel-mode rootkits are hidden inside of the operating system itself and caan be very hard to detect and eliminate.

SubVirt is the name of a research project directed by Microsoft with the help of the University of Michigan. Currently malware software and detection software have both control of the system at kernel-mode level. Virus writers are trying to find the best way to hide their malware in front of detection software and maintain at the same time the have maximum control over the machine.

The result of this research is the VMBR, Virtual Machine Based Rootkit. A Virtual Machine is a special software layer that works between the hardware and the operating system. On a Virtual Machine also the operating system runs in user mode. The rootkit would install itself between the operating system and the hardware and would have a total control of the system.

In order to work, the VMBR needs to start up before the operating system, so it's necessary to modify the Master Boot Record in order to make it work. At computer startup the Virtual Machine would start and then it would run the operating system in a virtual environment. Potentially it can run two operating systems at the same time, the user's Windows and a specially crafted malware operating system that would be invisible to the Windows system and to the user.

The problem with this type of malware software is that it would slow down the system. During their tests Microsoft noticed that the system sturtup takes about 30 seconds more with the Virtual Machine and it eats about 3% of system resources.

It's also important to point out that the virtual machines that Microsoft used had the size of about 100 megabytes, which is too much to fit in a common MBR.

The entire dossier can be downloaded at http://www.eecs.umich.edu/~pmchen/papers/king06.pdf

 
 
 

Related Articles

 
Indexing and the Registry
 
Mobile Phone Insurance ?C Secured Communication
 
An Introduction to HD-DVD
 
Top 5 Tips For Effective Email Marketing
 
How to Create a Powerful Online Presence
 
How To Earn Extra Income Online - Lesson 1
 
How To Make Your Customers Leave Forever - Or Not
 
eMarketing Basics
 
Is Email Marketing Still Effective?
 
What Newbies Need To Know About Using Pay Per Click Ads To Generate Traffic
 
 
 
 
 

Types Of Telephone Answering Systems You Should Look For

One of the great inventions of our time is certainly the telephone. We use these devices on a daily ... - Dan Sherman
 

Boost Ebook Sales with eBook Directories!

Many webmasters search ebook directories to find ebooks they want to offer to their web visitors. It ... - Leva Duell
 

Dell Computer Dominates the Marketplace

About three out of five households in America have computers today, compared with almost no one havi ... - Christopher Luck
 
 

How To Protect Your Site From A Google PageRank Drop

Let's face it, Google is still the major deliver of the web's traffic. That's why losing your high G ... - Titus Hoskins
 

How to Protect Your Files From a Computer Virus

New viruses creep up every day. A computer virus can completly wipe out your hard drive. Some viruse ... - Doran Roggio
 
 
Main >> Privacy >> ToS
Copyright © 2006-2008 www.sproutedlist.com - All Rights Reserved.