Blocking API calls for security
James Douglas Truckenmiller · 2002
The typical user feels comfortable with just having anti-virus software running on their computers. This solution works well if viruses are known and the virus databases are updated frequently. The virus writing community has responded by writing software that mutates the viruses so that these viruses are undetectable to the anti-virus software. Attackers know that anti-virus solutions rely on virus signatures and if the attacker mutates the virus, it will not be detected. Virus writers mutate their product by using software called packers, compressors, and binders. Take an older virus, pass it through one of these mutating programs and now the attacker has a new variant of the old virus that will pass through anti-virus software. A simple example of this type of problem in anti-virus software is the MiniZip worm. A packer called NeoLite was used to create the MiniZip worm, which was a compressed version of the ExploreZip worm. This new variant of the ExploreZip worm spread rapidly even though the original virus was well known. This new variant went completely undetected from the existing anti-virus software. In response to these new threats, a more proactive strategy to counter malicious code must be developed. This thesis focuses on using proactive monitoring techniques to identify code that has malicious intent and to block these operations. To achieve this, the thesis explores digital DNA, system resource monitoring and API monitoring. API monitoring was selected as the method of choice for determining malicious intent. This work discusses different API monitoring technologies, to include: proxy DLL, patching, and binary rewriting. With binary rewriting technology, the author was able to develop a software solution to counter malicious code. As a proof of concept, the author demonstrates his security product monitoring and blocking one of the most costly viruses to date, the "I love you Virus."