Home > Ask the Security Channel Experts > Information Security Threats and Countermeasures Questions & Answers > Code mutation, fragmentation and concealment: Hacker techniques to watch
Ask The Security Channel Expert: Questions & Answers
EMAIL THIS

Code mutation, fragmentation and concealment: Hacker techniques to watch

Retired Expert - Russell Dean Vines EXPERT RESPONSE FROM: Retired Expert - Russell Dean Vines

Pose a Question
Other Security Channel Categories
Meet all Security Channel Experts
Become an Expert for this site


Security Channel Update
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 10 January 2007
I have been following the recent buzz about new hacker techniques, including code mutation, code fragmentation and code concealment through rootkits. What recommendations can I make to customers concerned with these new hacking methods?

>

The three attacks you've mentioned, code mutation, code fragmentation and code concealment through rootkits, are some of latest evolution of new malicious code generation techniques. All are designed to make it harder to detect the virus or rootkit, and take the concept of the polymorphic virus one step further.

These programs are being designed to stick around undetected for as long as possible on infected systems. Some malware designers use "packers" to encrypt malware to evade detection.

Others use different routines for decrypting the code to create a virtually unlimited number of mutations, such as the Trojan Swizzor did recently.

Swizzor repacked itself once a minute to get past signature-based tools that work only if they know precisely what to block. Swizzor also recompiled itself once every hour.

Zero-day attacks using well-concealed Trojans present a serious challenge to the security professional. Therefore it's very important to rely on a security product or group of products that really stays on top of current threats and vulnerabilities.

Of course, all of the usual steps your customers take to prevent any type malware always need to be taken, and may help prevent some of these exploits.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Information Security Threats and Countermeasures
Security for mobile broadband
Understanding smurf attacks
What are the network security risks of streaming video?
Spyware removal from computers
Malware removal without antivirus software
Threat matrix and risk analysis resources
Blade server security on a storage area network (SAN)
Blade server security hardware advice
Cross-site scripting vulnerability penetration testing
When should automated penetration testing be supplemented with manual pen testing?

Data breach and leak prevention
Data protection fueled by data leakage prevention products and services
Security channel can't ignore full-disk encryption products, services
Vulnerabilities, regulatory compliance drive data protection market
Sophos integrates encryption into endpoint, email security
Maintaining your customers' security amid layoffs
Making the case for 'live' incident response
Mass. data protection law 201 CMR 17: How to get customers ready
Data breach prevention techniques: Helping customers avoid data breaches
PGP partners with Avnet to boost channel play
Data protection services offer revenue for security solution providers

Spam, antispam and phishing
SonicWall to offer cloud-based antispam service
Book Chapter: Web hacking
What is the future of antivirus or antimalware software?
Common injection attacks
Checklist: Top five security assessment tools
Penetration testing tutorial for service providers
Nmap Tutorial: An introduction for VARs and security consultants
Open source spam management for Outlook: SpamBayes
Combating Dynamic Code Obfuscation
Email security appliances that fight phishers and spambots

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts