A New Malware Propagation Technique based on the Send Function Hooking and Its Countermeasure

Jong-Hoi Kim, Jin-Young Lee, Seong-je Cho · Jeongbo gwahaghoe nonmunji. si'seu'tem mich i'lon · 2011

In this paper, we propose a new malware propagation technique which can spread malicious codes by hooking the function send(), and its countermeasure. The send() is one function of a shared library (DLL) used in network communication. The proposed technique propagates malicious codes by modifying the second argument of the send() and inserting the malicious codes whenever the send() is called to transfer executable files or document files. The propagation technique does not require any sort of direct user intervention as well as change the functionality of the files to be sent. In addition, the attacker does not have to calculate the CRC of packets, consider cryptographic protocols, and access directly to the target systems. We have performed some experiments on MS Windows NT/XP and verified that some malicious codes are propagated through all kinds of network applications including web browsers and messengers. As the possible countermeasures against the new mal ware propagation technique, we address the following four methods: the detection of the send function hooking, data integrity verification between network protocol layers, an application-level encryption, and secure binary packing methods.

Read the paper · More papers on PaperTik