On The Insider: Movie Roles the Stars Turned Down
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Jul 31, 2006 11:54:00 AM

The latest threat to intellectual property comes in the shape of malicious software (malware) that is capable of infecting a computer, hiding itself until the user accesses specific files or Web sites--in order to steal files or passwords--and then deleting any trace of itself.

Speaking at the IT Security in Government Conference in Canberra on Friday, Brian Denehy, security assurance engineer at CyberTrust, told delegates that the vast majority of new malware uses "some type of stealth" or anti-forensic technology in an attempt to remain undetected before, during and after an attack.

According to Denehy, techniques used not only include 'the obvious ones' such as encryption and rootkits but also "compression bombs"--which are compressed files that try to make life difficult for forensic tools by attempting to expand to an infinite size when executed.

"Generally these techniques are seen in about 65 percent of all forensic investigation these days.

"Some just do a complete wipe on the disk--equivalent to a low level format--to make sure that some of the remnant magnetization is not left behind. Most of you may well appreciate that just writing on a hard disk still leaves evidence there that can be recovered with the right tools.

"People also use the slack space at the end of files or introduce extras in the bad sectors list to hide their data … it makes life more difficult," said Denehey.

When conducting investigations, it's always Deheney's hope that these techniques haven't been used by hackers."It is pleasing to find an inexperienced hacker that has not used these things and has made it easy to analyze," he said.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 45 Talkback(s)
Sorry for the delay...
I haven't checked this thread for a few days... If you want to read about PC virtualisation (from M$ perspective) - go to:-

(Read the rest)
Posted by: dav1dsm1th Posted on: 08/04/06 You are currently: a Guest | | Terms of Use
Message has been deleted.  Reverend MacFellow | 07/31/06
6.75  Linux User 147560 | 07/31/06
OK ---  rbrucecarter | 07/31/06
Not weird, creative  panzrwagn | 07/31/06
Racist message  adirondackseamus | 07/31/06
Not Racist - Wrong Definition  HowardParr@... | 07/31/06
Walefare is racist?  Canticus | 07/31/06
Racist  rsouza@... | 07/31/06
uh huh  Kamchatka | 07/31/06
If I'm racist, I'm racist against ME!  Reverend MacFellow | 08/01/06
I missed the message...before it was deleted  mdsmedia | 08/01/06
HALLELUIA...  bblackmore | 08/01/06
Love it!  999ad@... | 07/31/06
WHY WAS THIS DELETED?  Reverend MacFellow | 08/01/06
as stated earlier...  mdsmedia | 08/01/06
Sorry I don't have a copy, but .....  Reverend MacFellow | 08/01/06
maybe it's still in your temporary internet files? i have learned through  wessonjoe | 08/02/06
Par for the course  slingzenarrowzuvowtrayjissforchin | 08/02/06
Where's the sense?  reliant1884 | 07/31/06
Caliber  tech.paul@... | 07/31/06
Time to take precausions..!  reliant1884 | 07/31/06
Backups good, but...  chicokhan | 07/31/06
A suggestion of how to solve these attacks...  dav1dsm1th | 08/01/06
Licensing cost double  bblackmore | 08/01/06
Points taken  dav1dsm1th | 08/01/06
dav1dsm1th...  bblackmore | 08/01/06
bblackmore, perhaps we're too deep...  dav1dsm1th | 08/01/06
Tell me more... please  qtrback | 08/01/06
Sorry for the delay...  dav1dsm1th | 08/04/06
The only real threat  DemonX | 07/31/06
Why not start making same?  Langalibalene | 07/31/06
Look Further!  reliant1884 | 08/01/06
Overdue  finalquest@... | 07/31/06
Perfect Weapon, Perfect Excuse  jlzimm | 07/31/06
perfect weapon  strubinsky@... | 08/02/06
Rootkit Detection..! Must Read!  reliant1884 | 07/31/06
Thanx for the info!  pundamentalist | 07/31/06
ROOTKIT MANAGEMENT  interested_amateur@... | 08/01/06
Yes this is a nasty bugger  Linux User 147560 | 07/31/06
eWeek is Running Out of Stories  adsanders@... | 07/31/06
Web Card  bblackmore | 08/01/06
Credit Cards would be better  Wizard Prang | 08/01/06
the new terror alert system, brought to you by m$  nix_hed | 08/01/06
Brian Denehy?  robinsonky | 08/01/06
What a goof!  jgmsys@... | 08/01/06

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here