Presentation is loading. Please wait.

Presentation is loading. Please wait.

Dr. Richard Ford  Fundamental Definitions  What is Malcode?  Malcode Overview  Follows: Szor Ch.1 & 2.

Similar presentations


Presentation on theme: "Dr. Richard Ford  Fundamental Definitions  What is Malcode?  Malcode Overview  Follows: Szor Ch.1 & 2."— Presentation transcript:

1 Dr. Richard Ford rford@fit.edu

2  Fundamental Definitions  What is Malcode?  Malcode Overview  Follows: Szor Ch.1 & 2.

3  Like most researchers, I got hit by a Virus  I disassembled the virus, and began on this wonderful journey of discovery…  Making every possible mistake on the way!

4  MMC = Malicious Mobile Code  Critical word: Mobile  MMC is designed to move from one machine to another

5  Viruses  Trojan Horses  Worms  Blended threats

6  A virus is a malicious program that modifies other host files or boot areas to replicate. In most cases, the host object is modified to contain a complete copy (possibly evolved) of the malicious program code. The newly- infected object is capable of spreading the “infection” further

7  A Trojan, or Trojan Horse, is a non-replicating program masquerading as one type of program with its real intent hidden from the user.

8  A worm is a piece of replicating code that uses its own program coding to spread with minimal user intervention. Unlike viruses worms do not “infect” other programs or boot sectors

9  Replication + something else bad (like an exploit)

10  A technology that aids in gathering information about a user or content of a machine without that user’s knowledge

11  Pretty much Spyware that tells you exactly what it’s going to do…  Always read the EULA…

12  Colloquial but descriptive  “Any piece of software that the user doesn’t want”

13  In The Wild  Dr0pper  “Generation 0”<- this is a zero  Payloads  Rootkit

14  Interesting problem  Go ahead and read: http://www.virusbtn.com/magazine/archives/pdf/20 03/200303.pdf: (p14) That Which We Call Rose.A http://www.virusbtn.com/magazine/archives/pdf/20 03/200303.pdf  What really is in a name?  For the other side, read http://www.virusbtn.com/magazine/archives/20030 1/caro.xml or Szor Chapter 2, 2.5. http://www.virusbtn.com/magazine/archives/20030 1/caro.xml or Szor Chapter 2

15  What is the goal of virus naming?  Assignment: Read Szor Ch.1 & 2 for Tuesday’s class

16  Is there any such thing as a good virus?  What do you think about this: http://www.samspublishing.com/articles/prin terfriendly.asp?p=337309&rl=1 http://www.samspublishing.com/articles/prin terfriendly.asp?p=337309&rl=1

17  Viruses and their environment…


Download ppt "Dr. Richard Ford  Fundamental Definitions  What is Malcode?  Malcode Overview  Follows: Szor Ch.1 & 2."

Similar presentations


Ads by Google