DocumentCode :
3451569
Title :
Re-inforced stealth breakpoints
Author :
Vasudevan, Amit
Author_Institution :
CyLab, Carnegie Mellon Univ., Pittsburgh, PA, USA
fYear :
2009
fDate :
19-22 Oct. 2009
Firstpage :
59
Lastpage :
66
Abstract :
This paper extends VAMPiRE, a stealth breakpoint framework specifically tailored for microscopic malware analysis. Stealth breakpoints are designed to provide unlimited number of code, data and I/O breakpoints that cannot be detected or countered. However, in this paper we present several attacks that can be used to detect and counter VAMPiRE. We then present a solution towards preventing such attacks in the form of a new breakpoint framework named Galanus. Galanus also adds support for legacy I/O breakpoints in kernel-mode, an important feature required to analyze keyloggers, BIOS flashers, CMOS updaters and rootkits. We also evaluate Galanus, comparing it to VAMPiRE in the context of a few real-world malware.
Keywords :
invasive software; software engineering; BIOS flashers; CMOS updaters; Galanus; I/O breakpoints; VAMPiRE; kernel mode; keyloggers; microscopic malware analysis; reinforced stealth breakpoints; rootkits; Counting circuits; Emulation; Hardware; Ice; Microscopy; Performance analysis; Registers; Runtime; Software debugging; Debugging; Malware Analysis; Stealth Breakpoints;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Risks and Security of Internet and Systems (CRiSIS), 2009 Fourth International Conference on
Conference_Location :
Toulouse
ISSN :
2151-4763
Print_ISBN :
978-1-4244-4498-4
Electronic_ISBN :
2151-4763
Type :
conf
DOI :
10.1109/CRISIS.2009.5411978
Filename :
5411978
Link To Document :
بازگشت