• DocumentCode
    1548669
  • Title

    Antivirus Software Shield Against Antivirus Terminators

  • Author

    Hsu, Fu-Hau ; Wu, Min-Hao ; Tso, Chang-Kuo ; Hsu, Chi-Hsien ; Chen, Chieh-Wen

  • Author_Institution
    Dept. of Comput. Sci. & Inf. Eng., Nat. Central Univ., Jhongli, Taiwan
  • Volume
    7
  • Issue
    5
  • fYear
    2012
  • Firstpage
    1439
  • Lastpage
    1447
  • Abstract
    In the last several decades, the arms race between malware writers and antivirus programmers has become more and more severe. The simplest way for a computer user to secure his computer is to install antivirus software on his computer. As antivirus software becomes more sophisticated and powerful, evading the detection of antivirus software becomes an important part of malware. As a result, malware writers have developed various approaches to increase the survivability and concealment of their malware. One of these technologies is to terminate antivirus software right after the execution of the malware. In this paper, we propose a mechanism, called ANtivirus Software Shield (ANSS), to prevent antivirus software from being terminated without the consciousness of the antivirus software users. ANSS uses System Service Descriptor Table (SSDT) hooking to intercept specific Windows APIs and analyzes them to filter out hazardous API calls that will terminate antivirus software. When using several pieces of malware that can terminate various brands of antivirus applications to make our experiments, the results show that ANSS can protect antivirus software from being terminated by them with at most 0.42% CPU performance overhead and 1.77% memory write performance overhead.
  • Keywords
    application program interfaces; invasive software; ANSS; SSDT hooking; Windows API; antivirus programmers; antivirus software shield; antivirus terminators; malware survivability; malware writers; system service descriptor table hooking; Computers; Malware; Materials; Process control; Reverse engineering; Software; API hooking; Antivirus software; malware;
  • fLanguage
    English
  • Journal_Title
    Information Forensics and Security, IEEE Transactions on
  • Publisher
    ieee
  • ISSN
    1556-6013
  • Type

    jour

  • DOI
    10.1109/TIFS.2012.2206028
  • Filename
    6226454