论文标题
回避Windows恶意软件:对抗病毒和可能对策的影响
Evasive Windows Malware: Impact on Antiviruses and Possible Countermeasures
论文作者
论文摘要
防病毒和恶意软件之间的永久对立导致双方不断发展。一方面,防病毒构成了越来越复杂的解决方案,除了经典的签名分析外,还提出了更复杂的检测技术。这种复杂性导致防病毒在保护机器上留下更多的痕迹。为了尽可能长的时间,恶意软件可以通过追捕防病毒所留下的修改来避免在此类环境中执行。本文旨在确定恶意软件检测防病毒,然后评估这些技术在当今最常用的抗病毒板上的效率。然后,我们收集显示这种行为的样本,并建议评估产生虚假伪像的对策,从而迫使恶意软件逃避。
The perpetual opposition between antiviruses and malware leads both parties to evolve continuously. On the one hand, antiviruses put in place solutions that are more and more sophisticated and propose more complex detection techniques in addition to the classic signature analysis. This sophistication leads antiviruses to leave more traces of their presence on the machine they protect. To remain undetected as long as possible, malware can avoid executing within such environments by hunting down the modifications left by the antiviruses. This paper aims at determining the possibilities for malware to detect the antiviruses and then evaluating the efficiency of these techniques on a panel of antiviruses that are the most used nowadays. We then collect samples showing this kind of behavior and propose to evaluate a countermeasure that creates false artifacts, thus forcing malware to evade.