Can This Virus Be 'Rooted' out? A New Kind of Hard-to-Detect Malware Is Increasing Our Vulnerability to Hackers and Creating Headaches for Makers of Antiviral Software

Doug Gale · T.H.E. Journal Technological Horizons in Education · 2006

JUST AS REAL VIRUSES mutate to evade antiviral medication, the writers of computer viruses and other forms of malware change their code to elude our antivirus software. If a biological virus were to start mutating more rapidly, it would compromise the ability of medical researchers to develop antiviral drugs. Unfortunately, that's what is now occurring with computer viruses (www.trendmicro.com/en/security/ white-papers/overview.htm). Why is this happening? The short answer is that malware is becoming more modular. An ill-intentioned author can choose from an array of attack strategies. When a new vulnerability is found, a piece of code that exploits the vulnerability can be attached to old, malicious code. Creating more havoc for PC users is the short time it now takes between the announcement of a software vulnerability and the appearance of malware that exploits the vulnerability. This underscores the importance of keeping your computer's antivirus software up to date. Monthly updates are no longer good enough. (See How to Keep Your Campus Safe from Infection, August 2005, for a review of 13 antivirus products; www.thejournal.com/articles/17359.) A Cloak of Invisibility The latest trend in malware is rootkits. A rootkit is a small piece of software code that runs deep within a computer's operating system and can be used to conceal other programs. The term rootkit comes from the Unix world and refers to software tools that give an intruder full, or root, access to a computer's operating system. That access can be used to hide other software code from all but the most technically adept users. For example, the dir command in Windows allows you to see the available files in the current and/or parent directories. With a rootkit, that command can be intercepted and false information returned. This makes a great tool for creating the software version of Harry Potter's invisibility cloak--and creates a real problem for antivirus software writers. The good news is that rootkits are difficult to write; the bad news is that they can be easily downloaded from the internet. Expect to see more of them being used to attack your computer. The use of rootkits to hide software code isn't confined to hackers; companies use this technology as well. Last year Sony BMG (www.sonybmg.com) installed rootkit code on their CDs that would install itself whenever the CD was played on a computer running Windows. Sony's intent was to conceal their copy protection code and prevent people from copying music onto their PCs. Unfortunately, in addition to consuming system resources running in the background, the Sony rootkit could also be used by virus writers to conceal their code. …

Read the paper · More papers on PaperTik