Malicious Code
Robert Guess, Eric Salveggio · 2012
This chapter enumerates the common types and sources of malicious code. It also discusses different methods of malicious code replication and methods of malicious code detection. A malicious logic (or code) is “hardware, software, or firmware that is intentionally included in a system for an unauthorized purpose. Malicious code threats are as numerous as the variety of nonmalicious code. Common types of malicious code include viruses, worms, Trojan horses, spyware, rootkits, and bots. Emerging malicious code threats include kleptographic code, cryptoviruses, and hardware-based rootkits. Present-day malicious code threats do not always fit into neat categories. Authors develop code to achieve some goal or fulfill some purpose just as users run code to achieve some goal or purpose. It is therefore the context of use and the intent of the wielder that determines whether code is malicious. This chapter highlights that prevention of all malicious code is not possible as the problem is demonstrably NP-complete. However, a strategy of defense in depth that uses operational, human, and technical controls can be relatively effective.