Strider GhostBuster: Why It’s A Bad Idea For Stealth Software To Hide Files

Yi‐Min Wang, Binh Dao Vo, Roussi Roussev, Chad Verbowski, Aaron Johnson · 2004

File-hiding through lying APIs [HTB03, NTI04] is an advanced stealth technique used by many popular system-monitoring software such as RootKits, Trojans, and keyloggers (collectively called “ghostware ” in this paper) to make executables or data files invisible. Once the ghostware program is started, it intercepts all file queries at a very low level and uses filtering to ensure that a chosen subset of files are never revealed to any file query operations made by any program, not associated with the ghostware, running on the infected machine. This technique can defeat experienced system administrators who search the file system and Windows Registry for suspicious entries, as well as commonly used malware scanning tools that are based on known-bad file signatures. Most of the existing ghostware detection tools exploit the imperfection of today’s file-hiding implementations. Although such tools are necessary for combating today’s ghostware, they may essentially provide testing resources to help the evolution towards perfect ghostware. In contrast, the Strider GhostBuster targets the fundamental weakness of the file-hiding behavior and turns the problem into its own solution [WVR+04]. The basic idea is very simple: since the hidden files are visible before the ghostware is started and become invisible after that, a diff of the two file-system scans before and after should precisely capture all

Read the paper · More papers on PaperTik