Re: Re: virus code is never executed - virus or not?]]]

Antony Stone <Antony-E2RgWYyNWflCkLs28/y7ANBc4/[email protected]> Sun, 11 Jan 2004 13:33:37 +0000
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
On Sunday 11 January 2004 1:22 pm, Fridrik Skulason wrote:

> >> You analyse the virus code and determine how it "infects" the host
> >> program.
> >
> >This seems like something of an undefinable problem to me - very much like
> > the Church - Turing proof I referred to earlier.
>
> No.  That deals with any arbitrary program, but is utterly irrelevant when
> you are talking about manual analysis of a one particular piece of code.

Oh, I agree.   I didn't realise we were talking about just one particular 
piece of code here - I was discussing what to do when we find any arbitrary 
viral code and are trying to work out whether to report it or not.

> This is similar to the situation that it is impossible to determine for any
> arbitrary piece of code on a turing machine whether it is a virus or not
> (see Fred Cohen's thesis), but for any given program it is possible to
> create a Turing machine that says whether it is a virus or not.
>
> It is perfectly possible to analyse any particular piece of code and
> determine whether it is non-working intended semi-viral crap or not.

Yes, I agree with both of these - the specific case is not what I was 
discussing.

> > Much easier in practice to detect the viral code and not bother about
> > what it's doing there - just report it anyway.
>
> I guess you have never written a virus scanner, and you are just wrong
> here.

The point is that I think end users want to know if a file contains some code 
which looks like a virus.   Basically I don't think anyone wants viral code 
on their computer, whether you reassure them that "it's never going to run, 
so don't worry about it" or not.

> >> It may not be practical to find the virus code if it is not executed -
> >> for example if the virus is heavily polymorphic.
> >
> >If that is the case then you don't have yourself a very good virus
> > scanner?
>
> I said "practical", not "possible".

Okay, fair point.

> >What's to stop the virus writer creating such heavily polymorphic code and
> >making sure that it *does* get executed?
>
> Then it does not fall under case 3), but case 1).  For the last time...I am
> talking about non-working crap here.

But it is only non-working because nothing ever calls it.   If some other 
piece of code jumped to the start of the viral section, then you'd still have 
yourself a virus - and I think people want to know that.

>  If the virus does not infect the
> program properly, and if no second-generation samples have a realistic
> chance of working, then this is not evan a virus by definition.  It will
> not become a problem in the wild, and there is simply no serious need to
> detect it.

The original question, however, asked "assuming we do detect this, how should 
we report it?".   I still believe that viral code should always be reported 
as such (perhaps with a modifier such as "damaged", "dormant" or "variant") 
and let the end user decide, but do not make them think there is no virus 
there at all.

Antony.

-- 
There are only 10 types of people in the world:
those who understand binary notation,
and those who don't.

                                                     Please reply to the list;
                                                           please don't CC me.



-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html