Catching Remote Administration Trojans (RATs)

Zhongqiang Chen, Peter Wei, Alex Delis · Software Practice and Experience · 2007

Abstract A Remote Administration Trojan (RAT) allows an attacker to remotely control a computing system and typically consists of a server invisibly running and listening to specificTCP/UDPports on a victim machine as well as a client acting as the interface between the server and the attacker. The accuracy of host and/or network‐based methods often employed to identifyRATshighly depends on the quality of Trojan signatures derived from static patterns appearing inRATprograms and/or their communications. Attackers may also obfuscate such patterns by havingRATsuse dynamic ports, encrypted messages, and even changing Trojan banners. In this paper, we propose a comprehensive framework termedRAT Catcher, which reliably detects and ultimately blocksRATmalicious activities even when Trojans use multiple evasion techniques. Employing network‐based methods and functioning ininlinemode to inspect passing packets in real time, ourRAT Catchercollects and maintains status information for every connection and conducts session correlation to greatly improve detection accuracy. TheRAT Catcherre‐assembles packets in each data stream and dissects the resulting aggregation according to known Trojan communication protocols, further enhancing its traffic classification. By scanning not only protocol headers but also payloads,RAT Catcheris a truly application‐layer inspector that performs a range of corrective actions on identified traffic including alerting, packet dropping, and connection termination. We show the effectiveness and efficiency ofRAT Catcherwith experimentation in both laboratory and real‐world settings. Copyright © 2007 John Wiley & Sons, Ltd.

Read the paper · More papers on PaperTik