Malicious Cryptology and Mathematics

Éric Filiol · InTech eBooks · 2012

Malicious cryptology and malicious mathematics is an emerging domain initiated in Filiol & Josse (2007); Filiol & Raynal (2008;b).It draws its inspiration from crypto virology Young & Yung (2004).However this latter domain has a very limited approach of how cryptography can be perverted by malware.Indeed, their authors consider the case of extortion malware in which asymmetric cryptography is only used inside a malware payload to extort money in exchange of the secret key necessary to recover the file encrypted by the malware (e.g. a computer virus).Malicious cryptology and malicious mathematics make in fact explode Young and Yung's narrow vision.This results in an unlimited, fascinating yet disturbing field of research and experimentation.This new domain covers several fields and topics (non-exhaustive list):• Use of cryptography and mathematics to develop "super malware"( über-malware) which evade any kind of detection by implementing:-Optimized propagation and attack techniques (e.g. by using biased or specific random number generator) Filiol et al. (2007).-Sophisticated self-protection techniques.The malware code protects itself and its own functional activity by using strong cryptography-based tools Filiol (2005b).-Sophisticated auto-protection and code armouring techniques.Malware protect their own code and activity by using strong cryptography.-Partial or total invisibility features.The programmer intends to make his code to become invisible by using statistical simulability Filiol & Josse (2007).• Use of complexity theory or computability theory to design undetectable malware.• Use of malware to perform cryptanalysis operations (steal secret keys or passwords), manipulate encryption algorithms to weaken them on the fly in the target computer memory.The resulting encryption process will be easier to be broken Filiol (2011).• Design and implementation of encryption systems with hidden mathematical trapdoors.The knowledge of the trap (by the system designer only) enables to break the system very efficiently.Despite the fact that the system is open and public, the trapdoor must remain undetectable.This can also apply to the keys themselves in the case of asymmetric cryptography Erra & Grenier (2009).

Read the paper · More papers on PaperTik