Showing posts with label race to zero. Show all posts
Showing posts with label race to zero. Show all posts

Tuesday, May 06, 2008

the anti-av revolt

i briefly made reference before to a growing anti-av revolt... that is the customer base for the anti-virus/anti-malware industry rebelling against the industry out of some perceived wrong-ness in it... i'm sure you've probably heard of people who swore off anti-virus years ago, likewise readers of this blog probably recall more overt manifestations of this revolt such as the "anti-virus is dead" campaign or more topically the "race to zero" contest...

usually it's been technically possible to write off individual av detractors as uninformed cranks, but their numbers are growing and their pool of influence is increasing... bruce schneier crying conspiracy when f-secure attempted responsible disclosure with sony was just the tip of the iceberg... now there are a variety of security experts lending their voices to an escalating sequence of expressions of dissatisfaction with the anti-malware industry...

and it's not even like they don't have just cause to be dissatisfied - they do... vendors have let their marketroids run amok for decades, building false expectations of protection in the customer base that are so in-grained we may never be able to undo them, and then predictably failing to live up to those unreasonable expectations...

on the other hand, however, the marketing folks were just telling people what they wanted to hear... there's a school of thought that says if a marketing person isn't showing you a rose-coloured-glasses version of the world then they aren't doing their job - anything less and they hurt their own company by admitting the product/service isn't the best thing since sliced bread... that's generally not a good idea in a competitive market as your competitors will capitalize on that as a display of weakness...

furthermore, there's no good reason for people to actually believe the marketing... a real life whopper doesn't look as perfect and juicy as the one on tv, beer doesn't come with a bevy of buxom beauties all playfully vying for your attention, and cars can't leap over traffic to get you where you're going faster and with a funky soundtrack... we've all learned these things through our real-life experiences and we should have also learned that anti-virus software cannot provide complete protection so why are people getting so bent out of shape over the inevitable failures?...

it really doesn't make a lot of sense but that's the irrationality of the human element for you... unfortunately i don't think it's good enough to just observe the fact and then go on about you're day like it was business as usual - not if (as i suggest) the problem really is escalating...

this may be hard for most to believe but there's actually been a long history of cooperation between competing companies at the more technical levels... this hasn't held true for marketing however; these are businesses after all, they need to make money and generally that's at the expense of their competitors... on a technical level, anti-malware vendors have always had a common enemy - the malware writers - but on a marketing level their opponents have always been each other... now the various marketing departments have a common foe as well (the anti-av movement), but it remains to be seen if they'll recognize their common interests and start working together as the analysts/researchers have...

the industry needs to get serious about image management... they have to start working to repair the damage their marketing departments have done to the public's perception of both the technology and the industry... that means not selling snake-oil in order to pander to unreasonable desires for complete protection (mcafee total protection)... that means putting your creative new technologies into your existing products instead using them as creative new ways to bilk more money out of customers and thereby reinforcing the image of av as blood sucking parasites (norton anti-bot)... and that definitely means not saying asinine things like the malware problem is solved...

it also means marketing something other than scanners... it's all the vast majority of the public knows and it's all anyone seems to think the industry produces... it's like they've been going to the same grocery store for years but only ever went down this one particular aisle, they're barely aware the rest of the store exists and they're getting fed up with what they're finding in that one aisle... they need to be made aware that scanning alone isn't enough (something the more technical members of the industry have freely admitted in public forums for a decade or more) and that the vendors have other technologies available besides just scanners...

much of the av industry is at the mercy of the big 2-3 av companies, unfortunately... it is those companies that have the most influence over how people perceive av but it is also those that would suffer the least by the destabilizing effects of their own PR gone awry... those with the most capability to do something positive have the least motivation to shape up, and if they just keep on keeping on then the public's perception is unlikely to change and the anti-av revolt will continue to grow...

Saturday, May 03, 2008

race to zero is no pwn2own

from mike rothman on the race to zero controversy:
It's like the PwnToOwn context at CanSec. Some folks will find some interesting holes and the vendors will patch them. Same deal here.
simply put, modifying known malware so that it no longer resembles known malware closely enough for anti-malware products to recognize it is not the same as finding new software flaws that need to be fixed...

with an infinite number of possible modifications, it's technically impossible for known-malware scanning producers to anticipate them all so they stay out of the pointless business of anticipating them entirely... as such failing to anticipate the ones used in this contest doesn't represent a flaw that needs to be fixed anymore than failing to read minds does... dealing with the new/unknown threats is the job of other technologies like behaviour-based HIPS (which i've already shown is available from a surprising number of traditional av vendors)...

coming from the guy who put me on to the phrase "mismatched expectations", this incite was a little off... but i guess i should expect as much when the prevailing wisdom in the security industry can't distinguish between malware research issues and vulnerability research issues...

all in all, the race to zero contest is really nothing like pwn2own... it's more like a cross between anti-virus fight-club and the consumer reports fiasco...

bad really is in the minority

from liam tung's article signature-based antivirus is dead: get over it:
However, there is a problem with the use of blacklists, said Turner. "When the majority of stuff you're handling is malicious, it makes more sense to use a white list because that deals with the exception — blacklists only work if 'bad' is in the minority."
i totally agree with this statement... there's just one thing that turner and just about every other av detractor out there fail to realize... bad really is in the minority... bit9 (an application whitelist vendor) has shown that there are several orders of magnitude more good stuff (on the order of billions) than bad stuff (about a half million at the time) and that microsoft alone produced as many good binaries in a day as there had been bad binaries produced in the previous 20+ years combined (from the bit9 presentation at the international anti-virus testing workshop in 2007)...

furthermore, most of the stuff anyone (other than the anti-malware industry) handles is non-malicious (unless you're looking only at email and are considering spam)... most web pages are safe, most binaries are safe, the majority of stuff most regular people encounter on a day to day basis is safe so if you're going to advocate a security technology that focuses on the exceptions you're going to have to get over your perceptual biases and realize that bad stuff is the exception so blacklists make more sense (at least by that logic)...

you've heard the argument that blacklisting is inferior to whitelisting because the list of all bad things is growing too big too fast, but we have quantifiable proof that the list of all good things is far, far bigger and growing far, far faster... that doesn't mean blacklists don't have serious problems (they do) or that whitelists are unusable (they aren't), it simply means that particular argument is fundamentally flawed and if people took the time to become familiar with the reality of the situation they'd know that...

an inconvenient truth about race to zero

from noah shiffman's article av vendors race-to-zero clue:
New viruses will not be created and no modified or variant code will be publicly released.
it's amazing to me how many people don't seem to realize that when you modify something you are effectively creating something new... this has been one of the more prevalent misunderstandings i've seen from people in favour of the race to zero contest at defcon this year and one i really didn't expect...

now, i realize i haven't always had as good a definition of variant as i do now... i should be more understanding of people who may not know as much as i do on the subject of malware... but even long before my understanding of variants reached it's current state i still had the logical capacity and intuition to realize that when you modify a virus, especially when you modify it to the point where anti-malware products can no longer detect it, then it is no longer the same as the original virus, it is no longer like anything anyone has seen before, it is (dare i say it) new...

the only way the race to zero won't be producing new virus variants is if cdman83 is right about them probably not using actual viruses in the first place (we can only hope they were dumb enough to misuse the terminology)...

even then, though, they will still be producing new malware... creating new threats is really all this contest will accomplish... demonstrating that known-malware scanning can't detect things that no one has ever seen before (ie. things that aren't known) is like demonstrating a spoon can't cut through bone...

Tuesday, April 29, 2008

race to zero in the security special olympics

news has started floating around about a contest in virus obfuscation being held at defcon this year... there have been a couple of mentions of it elsewhere as well, such as robert graham's "race to zero" post, sunnet beskerming's post "defcon competition has antivirus vendors complaining", and even an ars technica post titled "antivirus vendors pan free research from defcon contest" by david cartier...

now i'm obviously opposed to this and think it's irresponsible and unethical... not to mention they've chosen just about the worst malware type to play with - viruses... note to contest organizers, participants, and proponents: in the event that something goes wrong, self-replicators have a tendency to go on and on and on long after they are released or spread (old viruses never die)... they aren't called viruses because they make your computer feel bad, they're called viruses because they spread by themselves just like any infectious biological pathogen... this contest and those in it aim to play with fire...

with that out of the way, it's time i got to debunking a lot of the wrong thought surrounding this contest...

contest organizers (as quoted by pcworld):
Contest organizers say that they're trying to help computer users understand just how much effort is required to skirt antivirus products
if i'm not mistaken one of the key aspects to presenting things is to know your audience... the computer users at defcon already know it's easy to evade a scanner...

race to zero website:
The event involves contestants being given a sample set of viruses and malcode to modify and upload through the contest portal. The portal passes the modified samples through a number of antivirus engines and determines if the sample is a known threat.
this is a logical failure... a modified sample is by definition not a known threat until such time as a signature has been added to the scanner... if you're going to put on this kind of contest you might want to make sure you know what the difference between a known and unknown threat are...

Signature-based antivirus is dead, people need to look to heuristic, statistical and behaviour based techniques to identify emerging threats
this represents a complete failure to understand what the heck they're testing... changing a single bit can often foil signature detection - for contestants to get anywhere in this contest they will have to foil the heuristic, the statistical (also arguably a heuristic), and the behaviour based (heuristic here too) techniques that the scanners also implement... there are no naked known-malware scanners anymore (at least not as far as consumer products go), they all have some kind of heuristic engine in them...

Antivirus is just part of the larger picture,
and this is failure to understand their own messaging/marketing... how can anti-virus be part of the picture if it's dead?... on the one hand they want to tear down the practice of using anti-virus (anti-virus is dead) and on the other they expect people to keep it around as part of the picture... someone needs to make up their mind...

We are not creating new viruses
contrary to their mistaken belief, modifying existing viruses until such time as they're different enough from the original that neither known-malware scanning nor heuristics can recognize them is creating new viruses...

modified samples will not be released into the wild
one wonders how precisely they're going to keep that from happening? they're presenting contestants with samples, not a locked down environment that prevents them from taking their samples with them at the end of the day and doing something stupid/careless/malicious with them after the fact... how do i know this? because providing that kind of environment would be prohibitively expensive and restrictive... it might work in an educational institution (where the costs are offset by student tuition) but not as a contest..

robert graham:
The 'protectors" (product vendors) have big marketing
budgets to tell us their side of the story
it's not their side of the story, it's their attempt to get people to buy their product... on some level we all know that marketing and advertising is just another kind of lying... you don't honestly believe a whopper looks as perfect and juicy in real life as it does on tv, do you? then stop being disingenuous by treating av marketing as anything more factual than that...

We only get one side of the story
that is bullshit... we hear about the failures of anti-virus all the time, we hear about people giving up entirely on anti-virus, and we hear about anti-virus being dead... we get a lot more than just the vendor's side...

Yet, such contests also help customers
defcon isn't a customer education setting, this contest isn't going to teach them anything because they aren't going to be there...

The educating needed here is that the mainstream anti-virus technologies are easily evaded, and that such evasion happens a lot
if it happens so much then why do people need to be educated about it? surely they'll have seen it for themselves or they'll know someone who's seen it and has related the story to them?

Anti-virus vendors publish tests "proving" a 99% detection rate
this is the point where one realizes that robert graham is playing the part of an uninformed crank... anti-virus vendors do not publish tests like that... that kind of self-serving behaviour would absolutely NOT be tolerated by competitors or by the community... vendors point to tests carried out and published by independent 3rd parties...

However, that doesn't apply to customers. Often, the best way to test an anti-virus product is to create your own virus.
this is beyond stupid... you don't test your airbags by smashing your car into things and you don't test your anti-virus product by making new viruses... you leave such testing to the people with the expertise and resources to do it properly... customers generally have neither...

sunnet beskerming:
It should also show up the antivirus tools that
are making use of poor signature detection mechanisms
just like the race to zero website, this is a failure to understand what the contestants will really be bypassing... in order to not be detected by the scanners the samples will have to bypass the heuristic engines in those scanners... getting past a good signature scanner can be as easy as changing a single bit (because a good signature scanner will be very exacting so as to avoid false alarms)...

and those that are using weak heuristics to detect previously unknown malware.
heuristics have to be weakened in order to reduce the number of false alarms to an acceptable level... customers are generally unprepared to resolve potentially false alarms...

It is strange, though, how competitions like CTF, or the recent 0-day competition at CanSecWest, do not attract much complaint, but as soon as antivirus or antimalware tools are targeted it is too much for people
an interesting point, but one that highlights the fact that those other contests revolve around software flaws, whereas showing that new malware doesn't get picked up by blacklists is no more a flaw than notepad's inability to act as a hex editor...

david chartier/ars:
Instead of trying to deride Race to Zero, the AV industry could have a chance at working with the contest to harness what, in reality, could turn out to be some of the best research available on new malicious techniques. "You get what you pay for," as the old saying goes, but in the case of Race to Zero, the AV industry could be passing up a veritable gold mine of free ideas on how to better fight new threats.
except there's nothing for the av industry to learn from this contest... it's already known that malware can be modified, it can be modified in a countably infinite number of ways and if you protect against one the bad guys will just choose (not even find, choose) another... uninformed people think that things would be different if we used heuristics or behaviour blockers or application whitelisting, but the reality is that those can be bypassed in an equally numerous ways... their failures aren't discussed as much because because few people make use of them except for heuristics... and as far as heuristic failures
go people just misinterpret that as a failure in signature scanning, as most people involved in or commenting on this contest have already done...

to repurpose a train of thought from the riskanalys.is blog, the chance of any malware authors coincidentally creating the same malware or using the same modifications as the participants in this contest is basically 0 (n/infinity) so the value of trying to anticipate malware creation/modification techniques and use that knowledge for prevention is also generally 0... conversely, the chance of malware creators/users making use of what is revealed by this contest is greater than zero (because they're lazy, just look at eeye's bootroot to see an example of this having happened) so the value in adding detection for these new samples after the fact (or better still, avoiding the creation of those samples in the first place) is greater than zero...

ultimately i'm reminded once again of something david harley wrote some time ago... he hit the nail on the head when he said the rest of the security industry still doesn't understand av technology, practice, or issues - what people (including the contest organizers) have been saying about this contest proves that much... worse still, robert graham's maligning the credibility of vendors with false statements underscores one of david harley's other points; that the av industry and community remain hugely untrusted...

one has to wonder about the security industry when it doesn't understand one of it's oldest segments (and it's not like the information and people involved aren't available)... the mistrust, on the other hand, is completely understandable under these circumstances - you fear/hate what you do not understand, after all... schneier recently stated that the security industry would be coming to an end and i'll admit i had a bit of a knee-jerk reaction to that (though not so much that i wrote about it - if i did that everytime i disagreed with schneier . . .) but rothman (i think) made a subtle change by saying that security as we know it will come to an end... that's a possibility i almost look forward too - not because i think security should be subsumed by other things, but because the things i'm seeing make me think the security industry has become fundamentally broken (and/or gone mad)... of course, long time readers might recall i have my own prediction about security...