'WANT MY AUTOGRAPH?': THE USE AND ABUSE OF DIGITAL SIGNATURES BY MALWARE
Michael C. Wood · 2010
Encryption has always been a part of malware, from basic ROT13 string encoding to multi-layered packing algorithms. However, malware authors have discovered ways to exploit the existing strengths and weaknesses of public key cryptography in addition to their home-grown crypto. With the many layers that make up the Public Key Infrastructure (PKI) – certifi cate issuance, verifi cation, revocation and all of the protocols and software that go in between – scammers have several weaknesses at their fi ngertips to abuse the overall system. Cheap SSL certifi cates with automated issuance procedures facilitate the fast and anonymous set-up of rogue e-commerce sites. Moreover, malware authors are able to pass their trojans off as binaries from a legitimate source, using valid or invalid signatures, as most users simply click through the related security warnings. Making matters worse, much of the endpoint software consuming digitally signed content has its own weaknesses, including off-by-default certifi cate revocation checking mechanisms. In addition to abuse, malware authors are also exploiting the strengths of public key cryptography for uses including secure botnet command and control. This paper discusses these abuses of digital signatures and possible approaches to turn the criminals’ investment in their fraudulent reputation into additional protection mechanisms.