Showing posts with label trojan. Show all posts
Showing posts with label trojan. Show all posts

Sunday, February 12, 2012

is the iphone really malware free?

friday morning mikko hypponen posted a tweet about the folks behind flexispy changing the look of their site, and i took the opportunity to pose a question to him about iphone malware. you see, flexispy is (or was) a piece of mobile malware that f-secure posted about about 6 years ago. not only that, but there's a version of the software for the iphone, so i found mikko's repeated statement that there was no malware for the iphone to be a little strange in light of the fact that both he and his company have been aware of software that seems to contradict that claim for quite some time.

the resulting discussion with both mikko and his colleague sean sullivan lead in 2 separate directions, so let's look at them in turn. first mikko responded with the following:
@imaguid No malware for iPhones. If you jailbreak your phone: all bets are off. Flexispy runs on jailbroken only.
now to me, this gets to one of the hearts of the matter. when people say there's no malware for the iphone, they're only talking about non-jailbroken phones. the pertinent difference between a normal iphone and a jailbroken iphone is that normal iphones can only install apps from the app store. the app store is a so-called walled garden where all the apps go through a screening process to keep out undesirable programs.

so what people really mean when they say no malware for the iphone is that there's no malware in the app store. this is an important distinction, because the iphone ecosystem (and by extension, the threat landscape) extends beyond the app store. when chris di bona attempted to downplay the threat malware played to android devices by pointing to google's efforts to keep their android marketplace clean, a number of folks were quick to point out that the android ecosystem extended beyond google's android marketplace, so it seems strange that people would forget the same line of reasoning applies to the iphone as well.

one other thing (well, the only other thing, really) that mikko said was:
@imaguid ...and to top it all: we couldn't do anything about iPhone malware anyway, as Apple won't allow Antivirus products to iPhone.
and you know what? why should they allow them when there's apparently "No malware for iPhones"? whether or not there is malware for the iphone, apple doesn't want people to think there is. there is this (rather old) idea that computers can be as easy to use as an appliance (like a toaster). this idea is actually very appealing. it promises computers that just work, computers that don't get malware, computers that are easy and safe and worry free. that promise is part of the secret sauce behind apple's marketing, but if they allowed AV products in then it would dispel the illusion of the appliance computer and apple's products would lose their lustre. it's very convenient, then, that AV vendors are willing to be complicit in apple's marketing by repeating the claim that there's "No malware for iPhones".

but such unqualified claims are, as mikko has revealed, not technically true. it's not that there's no malware for iphones, it's that there's no malware in the iphone app store.

but wait, is that really true? is there no malware in the app store at all? i'm not sure that's true when we've recently been made aware of apps in the app store that collect and send personal information to a remote server without the user's knowledge or consent. but it's about time i turned my attention towards the much more verbose and nuanced discussion that sean sullivan and i had on the subject. perhaps he can shed light on why these personal info stealing apps shouldn't be considered malware. while mikko didn't question the classification of flexispy as malware, sean informed me that f-secure no longer calls it malware.
@imaguid @mikko But they then added an installation interface, and we have since categorized it as riskware.
that's right - in spite of the fact that it is designed and marketed as a tool for spying on other people, it is not classified as spyware or malware because it was given an installation interface - meaning that the attacker has to have physical control of the phone for at least as long as it takes to install an app. now, on the desktop this might be a meaningful mitigating factor, but on mobile devices where physical access is so much easier to achieve? come on...

why exactly that stops it from being malware in general or spyware in particular in the context of mobile device security i still can't fathom, but sean offered up two things by way of explanation. one being a concern over being sued... by malware vendors. this rationale is something i heard from dr. solomon years and years ago, but i have to admit i had hoped that the industry had become less spineless in the interim. i guess that was too much to hope for. google may stand up to the government on behalf of it's users (perhaps not always, and perhaps it doesn't always succeed, but it has tried), but apparently anti-malware vendors only stand up for their users when there's zero risk they'll be challenged.

the other thing he offered was the following definition of spyware from google:
Software that self-installs on a computer, enabling information to be gathered covertly about a person's Internet use, passwords, etc.
apparently it's not enough that the software spies on you in order for it to be called spyware, it has to "self-install" as well. now i'm sure i must be missing something, because this definition seems to exclude anything where the victim is socially engineered into installing the software (it's hard to call it self-installing if the victim is the one installing it). it also seems to exclude anything that utilizes the particular trojan horse case where the software actually does perform the function it claims to, so the payload is additional functionality instead of strictly misrepresented functionality. a game that also steals passwords, a text editor that also sniffs network traffic, webcam software that just happens to send the video stream to a second undisclosed location in addition to the intended recipient - all of these are examples of software that ought to be called spyware but which the victim actually knowingly installs (because the undesirable functionality is unreported) and thus fails to meet the "self-install" criteria. this is precisely the type of situation users of the photo sharing iphone app called path faced.

now, sean also pointed me towards the anti-spyware coalition's risk model description document. i had hoped it would help me to learn more about this "self-install" concept that sean assured me was part of an industry agreed upon standard definition. things didn't turn out that way, since the term "self-install" doesn't appear in that document, but the topic of installation and distribution do figure prominently in the contexts of both risk factors and consent factors. unfortunately this document from 2007 appears once again to be geared to desktop computing rather than mobile computing. that's probably not too surprising considering it's 5 years old now, but it does highlight the age old problem of letting context into the classification process. mobile devices are easier to gain illicit physical access to, as well as being shared more freely (and more frequently) in social circumstances by their owners. the issue of consent at the point of install has far less significance as a risk mitigation for mobile devices. furthermore, the issue of consent at the point of install pretty clearly drops the ball in the case of trojans because it's not necessarily fully informed consent.

as the risk model description document demonstrates, somewhere along the line the industry gave up on basing it's classification system on functional definitions. sean insists that this is a "stricter process" but i think it's more correct to say that it utilizes more criteria than a functional definition system would. utilizing more criteria doesn't always lead to a stricter process because not all criteria are created equal and, at least in the case of the risk model description document, some of those criteria are used to create exceptions (which are generally not the hallmark of a strict process).

one of the last things sean wondered is how could the AV industry possibly use my (supposedly) broader definition(s) and not be accused of FUD. now, aside from the fact that the industry is already accused of FUD (and worse) pretty much regardless of what they do, i think it's important to spell out one of the key differences between a functional definition and the kind of definitions that sean sees in use. definitions that include contextual evaluation are judgements, they engender choice and leave room for agendas. a functional definition has no judgement, it is purely descriptive of the functional capabilities of what is being classified. you can no more be blamed for saying software that spies is spyware than you can for saying water is wet or the sky is blue. there's no silver bullet to make accusations go away, but if you take judgement out of the equation it should render those accusations baseless.

so why is all of this important? because it appears that we've somehow stumbled upon a way in which malware can be classified as "riskware" instead of malware. nobody hears about the riskware classification, nobody cares. they hear "No malware for iPhones" and they shut the rest out because that's all they needed to know (or at least according to traditional notions of malware that should have been all they needed to know). classifying malware as something other than malware seems to be what's enabling people to make the "No malware for iPhones" claim, like some kind of terminological shell game. "No malware for iPhones" makes people think the devices are safe and worry free, but there are risks, and not just for those who jailbreak."No malware for iPhones" is creating a false sense of security and with the revelations that have been made about apple's abject failure to lock down a particular type of personal information and the near ubiquitous exploitation of that failure by app developers, it seems like the stuff of snake-oil.

i tend to think that when people face risks they want to know about them rather than be told there's nothing to worry about, and i tend to think that when those risks come in the form of software that acts against the user's interests, informing the user is the AV industry's job. some people don't want that to happen, they want their own interests to take precedent. if the AV industry allows that to happen through inaction (or worse, facilitates it) then they don't deserve the reputation they have for protecting the user. the industry may not be able to put AV software on iphones yet, but they can certainly do a better job of raising awareness of the risks than going around telling people there's "No malware for iPhones". maybe when public awareness is raised apple will change their ways.
image from secmeme.com

Wednesday, April 07, 2010

poking holes in trojans

it seems like only days ago when this blog's longest comment thread in recent memory drew to a close after a heated discussion on the definition of trojan and now it seems that not long after both chet wisniewski and david harley posted blog entries featuring that very classification.

not only that but chet's usage of the word as an umbrella term for all non-replicative malware doesn't seem to match david's usage - nor does it agree with my definition (which i imagine probably doesn't exactly match david's either). all of which just goes to show that there really isn't a universally agreed upon definition of trojan. no matter which definition you use there are always some problems with it.

that being said, there are some ideas in chet's post that mirror topics brought up in the aforementioned comment thread and that i think should be brought out front and center.

starting with the low-hanging fruit, let's look chet's example of a trojan that you don't have to execute in order to become a victim of - that being the drive-by download. now i realize that my computer science background has allowed me to develop some rather transcendent notions of what execution means (even going beyond this), but i really don't think one needs to go that far to get the concept that when you open a web page you're executing it's contents. a web page is a container for data and a wide variety of executable content (from javascript to flash to activex to silverlight, etc) and, rather than bog down the user experience with endless prompts to execute this, that, and the other thing, browser developers decided that opening a webpage should result in the execution of whatever executable content it contains. this is something that doesn't get nearly as much attention as it probably should and as a result most people aren't aware of this rather significant detail (otherwise more people would be using noscript) and consequently make bad decisions about how to use the web. i expect that chet himself is all too aware of the executable potential of web content but he's not passing that knowledge on to the reader when he tells them that drive-by downloads don't require any user interaction. the user opened the page in the first place (or opened another page that lead to the drive-by download page being opened) so they did interact in the sense of executing something. clicking a link in your web browser isn't that much different than clicking an *.exe in your file browser, and if more people understood that they might be more careful online.

more generally, the notion that something can be a trojan without requiring the user to execute something seems very odd to me. it seems to me that a piece of malware that doesn't need the user to execute it, that doesn't need the victim to let it in past the defenses, simply doesn't bare much similarity to the legendary strategem from which the name trojan horse program is derived.

i realize that analogies shouldn't be carried too far but to say that all malware that doesn't self-replicate (basically everything that's left over once you remove viruses and worms) is a trojan horse makes me wonder why on earth they chose the term trojan horse in the first place. the definition and the name seem to have no obvious connection. perhaps at the time they simply hadn't conceived of any malware that didn't conform to the paradigm used by the ancient greeks, but is that still true today or could i conjure up some malware examples that just don't seem like they should be called trojans at all? for example, when we think about malicious software we often think about that which runs on the victim's computer, but what about malicious software that runs on the attacker's computer? a participatory DoS tool, for example, would certainly seem to belong to the malware set since it's malicious software, and it certainly doesn't belong to the self-replicating set, but can you imagine something whose malicious functions are both known and advertised being called a trojan horse? should we call every implement of war a trojan horse instead of just the actual hollow wooden horses? catapults will henceforth be known as trojan horses, trenches also, swords and guns and chemical weapons, all of it. while we're being absurd let's call everyone bruce in order to avoid confusion. g'day bruce.

how about an example that does execute on the victim's machine? now remember i'm trying to steer clear of anything the victim user would let in past his/her defenses so the question you might be asking yourself (after taking into account just how liberal my concept of execution really is) how on earth such malware would get onto the victim's system? the answer, of course, is that it's planted there by an attacker who has already gained access to the system. back in the early 90's (perhaps even earlier) there was this attack technique whereby an unsecured system would be used to sniff out enough information (generally login credentials) to compromise a more secure system (because users of the unsecured system might on occasion access resources on another system), which in turn would then be used to sniff out information to compromise an even more secure system and so on and so forth until the attacker reached his/her goal. the attacker would use a collection of tools, often including some sort of back door in the form of a modified system binary as well as a password sniffing program, that were at least in the beginning known as toolkits (eventually one of these toolkits got named "rootkit" and the rest, as they say, is history). now i'll admit that the modified system binary that provides a back door does seem to bare at least a passing similarity to what we'd think of as a trojan horse program even if the victim didn't let it in him/herself (it's something that the victim could have easily let through the gates if given the chance), but in this context, rather than baring a similarity to the trojan horse of old, this bares more similarity to converting an existing agent into a double-agent. additionally a password sniffer in and of itself doesn't necessarily strike me as being particularly trojan-like. it's a packet sniffer that filters what it captures. it's not even clear that it's malicious until you take the context of it's use into account.

that sort of context sensitivity is often cited as a property of the trojan set but i believe it is a property of the malware set (of which the trojan set is a proper subset). in fact i think the trojan set inherits that property from the malware set. i also think that at the end of the day it's that property which makes the question of how to define such a set pointless. the term "trojan horse program" should probably go down in infamy as one of the anti-malware community's great failures because in it's unqualified form it has been one of the most singularly unhelpful classifications. back when there were only 3 major subclassifications for malware (virus, worm, and trojan, as chet mentioned in his post) we had quite a successful anti-virus industry that handily took care of viruses and worms, but not really trojans. both viruses and worms have functional definitions and trojans (whether you consider them the complement of the self-replicative set within the malware set or something more specific) do not. it wasn't until we started carving out functionally defined subsets of the trojan set (such as spyware and adware) that we started to actually get a handle on trojans. problems need to be well-defined before we can hope to address them.

so maybe we should all just forget about trojan as an unqualified term and only use it when we're talking about things like remote access trojans or downloader trojans. while we're at it, let's make sure we continue to carve out new functionally defined subsets of the malware set when fundamentally new behaviour comes along so that we don't sit around gazing at our navels and lamenting how difficult it is to classify things as belonging to an ill-defined set. we've already had an anti-spyware industry, an anti-trojan industry, an anti-rootkit industry, etc. due to slow response by anti-malware incumbents - we don't need to keep doing that.

Sunday, December 06, 2009

malware classification fail

here's one from the drafts pile, hopefully it's not too stale


i'm wondering what the anti-malware world is coming to when the leading vendor classifies something as a trojan even though it clearly discloses what damage it does.

by this logic, every copy of every operating system also ships with a trojan horse program, either in the form of the delete command or the format command.

one of the basic requirements of a trojan is that it tricks the user into executing it - the original trojan horse wouldn't have gotten very far if there was a warning sign on the outside that said it contained enemy soldiers that would sack the city when night fell. so too would suspected malware not get very far if it plainly disclosed what it does.

this game is at worst a potentially unwanted program - in other words, grayware. we can't just go around calling every bad program (or even just every bad non-viral program) a trojan anymore than we can go around calling all malware viruses. not using the proper terminology is a great way to confuse everyone and confusion is something we don't want to sow, right?!?

Wednesday, December 13, 2006

what is greyware?

greyware is the class of programs that are neither clearly good nor clearly bad... the world, unfortunately, is not just black and white, there are shades of gray and that is where grayware gets it's name... it's also called things like potentially unwanted programs, potentially unwanted applications, and other variations on that theme...

greyware represents the cases where the context sensitivity problem of the trojan definition is particularly acute... for example, commercial keystroke logging software can fall under a number of malware categories like keylogger, trojan horse program, and even spyware, but if it's used by upper management to keep an eye on what employees are doing with corporate assets or if it's used by correctional agencies to keep track of what convicted felons do online then there's an argument for not calling it malware at all...

another example is adware that gets bundled with conventional software to help offset the cost of that software... if the user knowingly and intentionally accepted the trade-off of viewing ads in order to use the software for free then there's nothing wrong, but if not (and this is often the case) then it's malware...

as should be clear, greyware does not have a functional definition... it would be nice if we didn't see that sort of thing, if we could call something bad or good solely by virtue of what it does, but unfortunately only a black and white world has that property...

back to index

Wednesday, September 20, 2006

symantec and the poor man's 'rootkit'

can't we stop calling everything a rootkit? please?

i grow weary of pointing out terminology misuse over and over again - from stealth digital rights malware, to protected recycle bins, to anti-virus products, to alternate data streams (yes, ADS all by itself has been likened to a 'rootkit') - but if someone sinks to a new low, well the full range of this terminology abuse needs to be documented in order to underscore how idiotic it is...

the latest 'new low' comes from symantec where the 'rootkit' label is being (loosely) applied to a trojan that scans through the registry for programs that get run and then replaces one (or more?) of them with a copy of itself while saving a backup of the original to execute after the trojan gets executed...

so apparently now trojans that employ the non-viral equivalent of companion file infection are 'rootkits'... well gee, at that rate just about any kind of program paracitism (i hesitate to call it file infection as i reserve infection for self-replicators) is a 'rootkit' technique since just about all of them hide changes as well as or even better than companion infectors (overwriting infectors are about the only kind that does a worse job)... so nearly all file infecting viruses and other forms of paracitic malware are 'rootkits' - yeah, that's a wonderful message to be sending people who look to you for expert analysis, symantec... thanks a lot...

things weren't bad enough when virus was treated as an umbrella term, or when spyware became the new umbrella term, now it's going to be 'rootkit'... let's take this absurd "if it hides things it's a rootkit" business to it's logical conclusion, shall we? file permissions are a 'rootkit' technique, attrib is a 'rootkit', popups are 'rootkits', the cursor is a micro-'rootkit' - my trousers are a 'rootkit'...

Friday, April 21, 2006

what is a password stealer?

a password stealer is a program that collects chunks of data that are likely to be account names and their associated passwords so that an attacker can use those credentials to pose as the person they were stolen from...

password stealers can be implemented in a number of different ways, most of them involve running on a machine where the owner/user of the machine is unaware of the password stealer's presence/nature (thus making it a trojan horse program)...

some password stealing trojans can monitor keystrokes, like a specialized form of keylogger... others might collect data from files or registry keys that are known to contain passwords... another type can pose as a window where the user would normally enter his/her password and record what the user enters... and yet another type can monitor network traffic (a network sniffer) looking for passwords...

back to index

Wednesday, April 19, 2006

what is a keylogger?

a keylogger is a program or piece of hardware that records keystrokes, often so that they can be sent out to or collected by a 3rd party but sometimes for use by the computer's owner for system monitoring... the fundamental functionality of keylogging is also present in keyboard/mouse playback utilities...

in the malware domain keyloggers are generally installed by the user without the user knowing what it will do (therefore qualifying it as a trojan horse program)... this can occur by the user running the keylogger directly, or by running a dropper or downloader trojan that installs the keylogger...

keylogger trojans are often used to steal sensitive information like credit card numbers, banking information, even passwords (those designed specifically for passwords are password stealers)... they can also be used for more general electronic surveillance, monitoring email and/or instant message composition, monitoring search terms typed into a search engine (potentially useful for adware), or even monitoring ordinary web-form input for the purpose of identity theft...

hardware keyloggers require the attacker to have physical access to your computer or at least some part of your computer involved in keyboard input (like the keboard itself)... hardware keyloggers obviously don't qualify as trojan horse programs (since they aren't programs) but they are often disguised or otherwise obscured to prevent the victim from becoming aware of their presence...

back to index

Saturday, April 08, 2006

cellphone spyware part 2 1/2

ok so there's apparently some confusion over my previous post about neo-call... i'm going to try and make this as simple as possible, both for the benefit of the confused and as an object lesson for everyone else...

softWARE that can SPY on someone is SPYWARE... this shouldn't be rocket science to anyone... flexispy and neo-call's spyphone both enable spying and so are both spyware...

software that does something bad (like for example spying on people) without disclosing that fact is a trojan horse program... neither flexispy nor neo-call's spyphone let the person being spied on know that it's spying on them, they both do something bad without disclosing the fact and thus are both trojans...

the fact that neo-call's spyphone is several times more expensive than flexispy doesn't stop it from being spyware or a trojan, it just makes it an expensive spyware trojan...

the fact that the installer generated by neo-call, when you give them the code for the target phone, can only be used on that phone doesn't stop it from being a spyware trojan, it just makes it a more limited spyware trojan...

the fact that flexispy can be installed on many phones does not make it a virus... many programs can be installed on many phones, that has nothing to do with being a virus and being a virus has nothing to do with why f-secure added detection for flexispy...

the fact that flexispy has a hidden menu is not what makes it bad and the absense of a similar menu doesn't make neo-call's spyphone good... flexispy is bad because it hides it's menu and every other indication that it's installed (in other words, it doesn't disclose it's spying nature) - neo-call's spyphone has no menu to hide but still hides all the other indications that it's installed and therefore is equally bad...

in short - neo-call's spyphone is just as bad as flexispy, it is just as much a spyware trojan as flexispy... it's limitations (the high cost per installation) make it a much smaller risk to the public, however, and that is why anti-virus vendors don't take it as seriously as they do flexispy...

Tuesday, April 04, 2006

cellphone spyware part deux

so my last posting about cellphone spyware (flexispy) apparently was interesting enough to someone for them to send me my very first non-spam feedback... specifically, someone claiming to be affiliated with neo-call sent me a nice little email with their views on the flexispy story...

this is actually pretty amazing, because apparently the neo-call folks (being industry leaders) developed superior cellphone spying technology months ago and nobody paid any attention to them or talked about them (awwwww)... the email goes on to say that it's very interesting that f-secure picked up on the flexispy story a day after the software was released - and i agree... if it really was only a day after the software was released it would appear that vervata decided that getting a examined by anti-virus vendors would make for a good publicity stunt, and i suppose they may be right... on the other hand, f-secure now detects their product as a spyware trojan so i guess that kinda backfired on them since that detection is going to limit the marketability product (who wants to pay for spyware that an anti-virus product can already detect?)...

finally, the email finished off with a lament about how neo-call is an industry leader (in the field of cellphone spyware, apparently) and how it's a shame that nobody is paying any attention to them or talking about them at all.. clearly they're jealous of all the special lovin' the boys and girls and f-secure have been giving flexispy and they want in on some of that action - and it appears they may be deserving... their product forwards sms messages, lo-jack's the phone through GSM localization, and i gather there's even a bonus add-on for listening in on calls - definitely sounds spyware to me... oh, and get this, the FAQ clearly states that you can't tell the product is installed by examining the phone - yup, it fails to disclose it's true nature just like flexispy, isn't that wonderfully up-front of them to admit to it's trojan nature?

mikko and the rest of the gang at f-secure - these guys are obviously looking for some of your special attention, so go ahead and hook 'em up..

[edit april 7 2006: i don't know what i was thinking posting links to a malware distributor, i guess i must have been laughing too hard to realize what i was doing]

Thursday, March 30, 2006

flexispy vs. the anti-malware industry

if you haven't heard about flexispy (the first spyware trojan for symbian cell phones) then i'd suggest reading about it here and here...

i don't really think it's all that interesting that someone has finally made spyware for cellphones - what i think is amazing, however, is that a member of the commercial spyware industry (vervata) seems to actually not understand why their product (flexispy) is being called a spyware trojan by f-secure...

imagine, you make software that you yourself call a "spy application" and then don't understand why people call it spyware... hello!?!? it's software that spies on you, what do you think people are going to call it?... are these guys for real? well, either they really don't get it, or they think that there are enough other people who don't get it that it's worth it to bother making such a ridiculous argument...

but why is that? well, i think it serves as a stong indication that the anti-malware industry/community in general, and the anti-spyware industry/community in particular, have failed the public in an important way... they've failed to make the threats understandable to ordinary people... look at the anti-spyware coalition's glossary, is their definition of spyware as straight forward as 'software that spys on you'? no, in fact they have 2 separate and contradictory definitions, one of which makes spyware an umbrella term... i've already blogged about stopbadware.org's use of a colloquialism from wikipedia as their definition for spyware, and then there's sunbelt's listing criteria that i was recently made aware of and which is about as easy to read as an end user license agreement unless you already have some familiarity with the malware field...

how are people suppose to get this stuff with literature like that? if it were common knowledge that spyware is software that spies on you then vervata would have no reasonable way to claim ignorance, much less argue the fact... and if it were common knowledge that trojans were programs that do bad things that you thought they didn't do then vervata also should have known that their product (which fails to disclose it's true nature) can be made into a trojan simply by saying it's something good or by installing it on someone's phone and leading (or leaving) them to believe that everying on the phone is normal...

of course, i'm not all about pointing the finger at other people here... while writing this i've realized that even my own definitions could stand some improvement in this area... as much as i try to make the definitions themselves short and sweet (with explanations afterwards for those interested in more detail) they could still be simpler and retain their correctness at the same time... i think we need to compose our definitions like we were talking to 4 year olds, not because people are stupid but because most simply don't have enough of a foundation here to grasp our meaning when we write for other people people in the anti-malware field... i think if we really understand what we're talking about then that shouldn't be too difficult a task... so i guess i'll be tweaking some existing blog entries in the not too distant future..

Sunday, March 26, 2006

what is a downloader?

a downloader is a program that downloads and installs/executes one or more other instances of malware from the internet...

the downloader is similar in purpose to the dropper, it's a means of getting malware into a machine while bypassing the security checks at the entrance... the difference here is that while the dropper carries the malware inside of itself the downloader doesn't, so even if a scanner were able to see through all possible ways of hiding a known piece of malware, a new unknown downloader would be able to get past it because the known malware the scanner could have detected wouldn't actually be present yet...

once again, active monitoring and/or sandboxing can mitigate (but not eliminate) the risk posed by this type of malware... once the known malware is downloaded active monitoring should be able to detect it, and if a downloader tried to download and execute the known malware in a sandboxed environment it should also be detected...

just as with droppers, downloaders secretly introduce malware into the system and are thus a type of trojan... unlike droppers, however, the downloader method isn't geared towards hiding anything so it's completely unrelated to stealth - instead it's more like a backdoor for the particular malware it downloads...

back to index

Saturday, March 25, 2006

what is a dropper?

a dropper is a program that carries an (often hidden) instance of some already known malware within itself and drops (extracts and runs) the malware it carries when it itself gets executed...

droppers are a means of getting malicious content past gateway security checking practices such as scanning downloads and email... they're generally easy to create by performing some arbitrary transformation (like run-time compression or encryption or some other type of encoding) on the malware it carries (which is then reversed when the malware gets dropped) but not necessarily easy for a scanner to see through programmatically unless it has prior knowledge of the transformation algorithm... in it's transformed state the malware may not be recognizable to the security applications that checked the dropper as it entered the machine and if that happens then the malware may go undetected when it gets dropped unless additional measures such as real-time monitoring or sandboxing are used...

the dropper represents a kind of (usually) temporary camoflage and as such is a distant relative of the more conventional stealth techniques... because they secretly introduce malware into a system they are also a type of trojan horse program in their own right...

back to index

Thursday, March 02, 2006

what is a RAT?

a RAT, or remote access trojan (sometimes remote administration tool) is a program that listens for and accepts connections from a remote 3rd party and carries out the commands that 3rd party gives it... essentially it's a server that provides remote control functionality...

as is traditionally the case with trojans, there are some circumstances where this functionality is legitimate or even desirable and some circumstances where it is not... it is legitimate and desirable when you are the administrator of the system with the remote control software on it and are personally using the software to administer the system remotely...it is not legitimate when you are tricked into installing it or are otherwise unaware that it is installed on your computer and unaware that someone else has control of that system (most responsible remote administration tools are made in such a way as to not be easy to install without the user's knowledge or consent)...

it is only in the circumstances where it is not legitmate or desirable that such a remote control program qualifies as a remote access trojan...

back to index

Wednesday, March 01, 2006

what is spyware?

spyware is any program that reports information about you, your activities, or your system back to a 3rd party...

like adware, spyware can sometimes have legitimate uses... for example winamp can (if so configured) report usage statistics back to nullsoft... windows xp, upon encountering a crashed application will offer to send a memory dump of the application to microsoft... even your browser reports information about you back to the websites you're on so that those websites can show you data that is appropriate for you such as the contents of your online shopping cart if you happen to be on an online store's site...

as the name suggests, however, there are more sinister uses for spyware such as stealing passwords or credit card information... this type of spyware generally gets installed or reports to a 3rd party without the user's knowledge and/or permission...

spyware that spies on you without your knowledge and/or permission qualifies as a type of trojan... in fact, the term spyware is so pejorative that it is almost exclusively used to refer to those examples that also qualify as trojan horse programs...

there is a complication in the spyware landscape, however... this complication arises because sometimes the user of a computer and the owner of that computer are not the same person... some organizations use spyware to monitor what their workers are doing on the organization's computers and while the spyware qualify as a trojan in more conventional circumstances it's (arguably) not a trojan in these particular contexts because it has permission from the person/people who matter...

back to index

what is adware?

adware is any program that displays advertisements for something other than itself...

sometimes the display of such advertisements is completely benign and serves as a means of subsidizing the development of software or the provision or services... for example, older versions of the opera web browser displayed ads to users who hadn't paid for the browser in order to help pay for the cost of development of the software... users had the option of using the free version and letting the advertisements take up a certain portion of the screen or paying for the ad-free version and getting more screen real-estate with which to browse with... another example is the internet service providers that used to (and perhaps still do in some locales) provide free internet service so long as you used their custom connection software which utilized part of your screen real-estate to display ads...

while all that sounds ok, that's just the well behaved adware... sometimes 3rd party adware is bundled with software the user downloads... ideally the presence of this adware is made obvious during installation and the user given an opportunity to opt out of the installation - also ideal would be that the adware is easy to find and uninstall once on the system... however, often the presence of the adware is hidden in an EULA (End User License Agreement) that no one reads and is installed in such a way as to make it difficult for the user to find it and/or remove it...

when adware is installed in secret and/or is made difficult to find and/or remove it qualifies as a trojan horse program and it is this combination of adware and trojan that most people are talking about when they speak of adware in a malware context...

back to index

Tuesday, February 14, 2006

what is DRM?

digital rights malware (or digital rights management software if you prefer) is any program bundled with media (text, graphics, audio, video, or some combination thereof) that takes some measure of control over the user's electronic device(s) in order to limit what the user can do with the media, often in contradiction to some extent with what applicable laws say the user should be allowed to do with it...

the user is often unaware of the presence of the digital rights malware his/her media purchase has been crippled with or how it invariably works against his/her interests, so it therefore qualifies as a kind of trojan...

in recent months there has been a trend to label any form of digital rights malware that uses stealth to hide itself (and in order to be effective against any user with half a brain they have to use stealth) as a rootkit... this is part of a larger and rather misguided trend to call anything that uses stealth a rootkit... while DRM is malware, it is not necessarily a rootkit...

there is an older trend (and some well known examples of success) of trying to get protection of digital rights malware enshrined in the law... this moves the creation and maintenance of copyright policy out of the hands of the government and into the hands of various corporate interests and has sometimes been called paracopyright... in places where this has taken place many of those corporate interests have proven themselves uninterested in the user's rights many times over...

(see my previous posting on digital rights malware here)

back to index

Saturday, February 04, 2006

what is a trojan?

a trojan horse program is a program which the user believes performs good (or at least benign) function but which also or instead performs a function the user would not approve of if s/he knew about it...

there are those who think trojan horse programs are synonymous with back doors, however that is only one of the many different types of trojans known...

the most striking thing about this is that it is not a functional definition... we cannot determine if program X belongs in the trojan horse class just by examining it, we must also look at how it gets presented to the user and make guesses as to how an average user might reasonably interpret that presentation...

for example, format.com (the utility used to format disks) is certainly not a bad program - if you need to format a disk then this is the program you want to use... however, if someone were to rename it to best-blowjob-ever.com (an example of social engineering) then someone else could be in for a nasty surprise when they tried to run it...

this may seem like nothing more than a mental exercise so far, but now imagine you were going to write an anti-trojan program to help protect people from trojans - how could your product alarm on best-blowjob-ever.com and not on format.com when their contents are identical? in general it can't be done and so deciding whether or not to detect program X as a trojan becomes a balancing act... one has to try to decide whether it's more important to warn people of the potential trojan or to not create fear among those who happen to have a legitimate program that gets maliciously misused in some circumstances...

these kinds of problems innevitably stymie efforts to help protect people from malware and is why non-functional definitions are such a bad thing... unfortunately, in the case of trojans, that's the kind of definition we're stuck with...

back to index

Tuesday, December 06, 2005

digital rights malware

you might think that there's a legitimate need for DRM... you might think that DRM gives users options and flexibility... you might think that the Sony BMG DRM rootkit fiasco was an isolated incident that would never happen again...

you'd be wrong...

digital rights management, or more accurately digital rights malware is a technology whereby people who provide the user with content exercise what they feel is their right to take some measure of control over the user's electronic equipment...

it doesn't prevent copying (it can't prevent copying), at best it prevents using copies on machines that the content providers (or DRM providers acting as agents of the content providers) don't think the user should be allowed to use the copies on... i say at best because it totally ignores the concept of the darknet which effectively renders copy controls useless as soon as one person finds a way around the controls...

DRM takes control of the user's equipment - not to the same degree (usually) as a remote access trojan, but it's still taking some control and it is doing so without the authorization of the user... even under those circumstances where the full extent of the DRM's behaviour is revealed in an End User License Agreement (EULA), the EULA will go unread (as they all do) because EULA's are so full of legalese that the ordinary person can't actually understand them...

DRM can't work without treating the user as an opponent, it's entire reason for being is to prevent the user from doing things that the user wants to do... there can be no legitimate need to install software on user-owned computers that acts against the user's interests unless you condone a copyright police state...

copyright should be protected by law, not technology, but the content providers don't trust the law to do that so they turn to DRM in order to gain more control... then they lobby for anti-circumvention laws to protect their DRM, effectively legitimizing the control they're grabbing in the eyes of the law and shifting the authority to make copyright policy away from the government and towards content providers (with all their vested interests)... but of course they don't trust the laws that protect DRM anymore than they do the laws that protect copyright so they employ additional offensive technology to protect their DRM as happened in the Sony BMG debacle, and as will continue to happen (though with better PR) and possibly even escalate... it has to keep happening or the content providers have to start relying solely on the law to provide protection, thereby giving up the control they so obviously desire...

ultimately what it comes down to is control... DRM is meant to usurp the user's (and, when combined with anti-circumvention laws, the government's) control and therefore is much deserving of the malware classification (even if anti-virus/anti-spyware/anti-malware vendors can't or won't deal with that particular class of malware (yet)...

Tuesday, July 12, 2005

the importance of good definitions

Techdirt has an article on the recent attempts by a group of organizations to come up with an agreed upon set of definitions for spyware and adware... predictably, Techdirt gets it all horribly, horribly wrong...

the author feels that what the software does or doesn't do is immaterial - that any unwanted application that got on one's machine by unknown means should be classified as spyware... he's not the only one who feels that way but there's a BIG problem with this line of reasoning...

the problem is that classifying instances of software on the basis of how they make some nebulous real world group of users feel (which is essentially what the author's position boils down to) is ridiculously difficult on a number of levels... not only will countless millions be spent on navel-gazing exercises trying to divine whether a particular instance of software in a particular software bundle is going to be unwanted and unnoticed at install time by some fictional average computer user or one if his/her 3.2 kids, but countless millions more will be spent defending against a deluge of specious lawsuits on the grounds that each classification was arbitrary and prejudicial - ultimately leading to a system where the courts, rather than the industry decide which program is spyware and which isn't..

we're computer scientists, not mind readers - we don't deal with this eye of the beholder crap unless we absolutely have to - and in this case we don't have to... we already have an umbrella term for all bad software - it's "malware"... if we're going to classify software for anti-whatever purposes we need to do it based on functional definitions (definitions based on what functions the software performs rather than definitions based on guessing how users will react to it)... we already have one malware classification saddled with an eye of the beholder definition, it's known as the "trojan", and that non-functional catch-all definition has been the bane of anti-trojan detection for years and is probably the reason we've had to make so many other classifications because it's proven totally unworkable as a classification that people can agree upon... classification based on eye of the beholder type criteria excludes widespread agreement by definition...

functional definitions, on the other hand, are much more reasonable... no guessing is involved and legal defense is practically a non-issue - define something based on it's function and it becomes much more feasible to demonstrate that a particular thing belongs or doesn't belong in that class...

on reading the actual document that the group of organizations (the anti-spyware coalition) came up with i think that for the most part the definitions are reasonable but a little on the wordy side... adware, for example could be much more simply defined as any software that advertizes a product or service other than itself... likewise spyware can be defined as any software that surreptitiously collects information from the user's system and sends it back to a remote 3rd party...

they did miss the mark on rootkits again, but the most notable problem is their adoption of spyware as an umbrella term for just about all bad software... they justify this by saying that the public at large is calling it that but this is foolish; 2 years ago the public at large was calling all bad software viruses, 2 years in the future they'll be using yet another term... how will this system cope with that? better to ignore the foibles of the unwashed masses and simply strive for internal consistency... trying to accomodate terminology misuse by people who don't know what they're talking about will never work because the people who don't know what they're talking about will not be consistent over time - leaving those of us who do know what we're talking about having to guess what they're talking about regardless of how accomodating we try to be...

EDIT (07/19/2005): i retract what i said about their definition of rootkits - i don't know what i was looking at before but now it looks fine... turning spyware into an umbrella term is still bad though...

Sunday, March 13, 2005

rootkits for windows

this page tries to explain what rootkits are and the emerging threat they pose for the windows platform...

that's all well and good but there's something that just doesn't sit well with me... let's take a closer look:
The term rootkit is very old and is dated back to the days when UNIX ruled the world. Rootkits for the UNIX operating system were typically used to elevate the privileges of a user to the root level (=administrator). This explains the name of this category of tools.

i like this explanation... it's simple, it's consistent, it makes sense.... a rootkit is a tool used to gain root (*nix speak for administrator) privileges...
Rootkits for Windows work in a different way and are typically used to hide malicious software from for example an antivirus scanner. Rootkits are typically not malicious by themselves but are used for malicious purposes by viruses, worms, backdoors and spyware. A virus combined with a rootkit produces what was known as full stealth viruses in the MS-DOS environment.

now this is not so good... apparently rootkits for windows don't really have anything to do with giving a principle administrative privileges... it does a bunch of the other things it's unix counterpart does (i.e. it uses sophisticated techniques to hide) but no elevation of privilege...

does that make sense to you?

if i take the self-replication out of a virus, regardless of the fact that it can still do all the other things it used to be able to do, it is no longer a virus...

why then if i take the root granting functionality out of a rootkit does it remain a rootkit?

it doesn't seem to make a lot of sense, it is not logically consistent... by rights, what they're calling rootkits for windows should be called (in keeping with the spirit of the rootkit name) stealthkits...

now, this was an f-secure description so you may well be thinking that maybe those f-secure folks are a little confused... but no, if that were the case then why does sophos also seem to think that rootkits are more about hiding than they are about privilege elevation (which they don't even mention)... and then there's sysinternal's explanation of rootkits which also focuses on hiding rather than privilege elevation...

this seems like it might actually be industry wide, in which case i can just site here in awe and wonder because the industry appears to be from a completely different planet than you and me...