GOzues

Discussion in 'Computer Security' started by zxspectrum, Jun 2, 2014.

  1. zxspectrum

    zxspectrum Terabyte Poster Forum Leader Gold Member

    2,092
    216
    244
    I caught this on ITV, New malware 'nearly impossible' to wipe out - ITV News

    and was wondering what are your thoughts are and if any, besides what they advise on ITV will be your response???

    Eddie
     
    Certifications: BSc computing and information systems
    WIP: 70-680
  2. Monkeychops

    Monkeychops Kilobyte Poster

    301
    22
    25
    Response would be business as usual, arguably no different to other malware that's out in the wild.

    It's just yet another 'thing' to deal with if you're involved in enterprise security, where you hopefully have plenty of lovely layers of controls in place to try and help mitigate something like this.
     
  3. dmarsh
    Honorary Member 500 Likes Award

    dmarsh Petabyte Poster

    4,305
    503
    259
    Decent malware has always been nearly impossible to spot.

    Shellcode can be as little as 200 bytes, try finding that amongst terabytes, and that is without considering rootkits.

    Encrypting or compressing data to fool 'deep-packet' inspection is trivial in most cases.

    Its Game Over Zeus, you know, the greek god.
     
    Last edited: Jun 2, 2014
  4. Monkeychops

    Monkeychops Kilobyte Poster

    301
    22
    25
    Exactly, hence why this will make little to no difference to people in the grand scheme of things.

    Identifying malware itself is getting harder and more complex, it's something that needs to be complemented by or even driven by other methods such as anomaly detection or behavioural characteristics.

    Given the right tools malware can be spotted and stopped, but it's not necessarily easy (or cheap!) to do it very well.
     

Share This Page

Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.