Re: Re: virus code is never executed - virus or not?]]]
Antony Stone <Antony-E2RgWYyNWflCkLs28/y7ANBc4/[email protected]> Sun, 11 Jan 2004 13:33:37 +0000
| Newsgroups | gmane.comp.security.virus.openantivirus.general |
|---|---|
| Message-ID | <[email protected]> |
On Sunday 11 January 2004 1:22 pm, Fridrik Skulason wrote:
> >> You analyse the virus code and determine how it "infects" the host
> >> program.
> >
> >This seems like something of an undefinable problem to me - very much like
> > the Church - Turing proof I referred to earlier.
>
> No. That deals with any arbitrary program, but is utterly irrelevant when
> you are talking about manual analysis of a one particular piece of code.
Oh, I agree. I didn't realise we were talking about just one particular
piece of code here - I was discussing what to do when we find any arbitrary
viral code and are trying to work out whether to report it or not.
> This is similar to the situation that it is impossible to determine for any
> arbitrary piece of code on a turing machine whether it is a virus or not
> (see Fred Cohen's thesis), but for any given program it is possible to
> create a Turing machine that says whether it is a virus or not.
>
> It is perfectly possible to analyse any particular piece of code and
> determine whether it is non-working intended semi-viral crap or not.
Yes, I agree with both of these - the specific case is not what I was
discussing.
> > Much easier in practice to detect the viral code and not bother about
> > what it's doing there - just report it anyway.
>
> I guess you have never written a virus scanner, and you are just wrong
> here.
The point is that I think end users want to know if a file contains some code
which looks like a virus. Basically I don't think anyone wants viral code
on their computer, whether you reassure them that "it's never going to run,
so don't worry about it" or not.
> >> It may not be practical to find the virus code if it is not executed -
> >> for example if the virus is heavily polymorphic.
> >
> >If that is the case then you don't have yourself a very good virus
> > scanner?
>
> I said "practical", not "possible".
Okay, fair point.
> >What's to stop the virus writer creating such heavily polymorphic code and
> >making sure that it *does* get executed?
>
> Then it does not fall under case 3), but case 1). For the last time...I am
> talking about non-working crap here.
But it is only non-working because nothing ever calls it. If some other
piece of code jumped to the start of the viral section, then you'd still have
yourself a virus - and I think people want to know that.
> If the virus does not infect the
> program properly, and if no second-generation samples have a realistic
> chance of working, then this is not evan a virus by definition. It will
> not become a problem in the wild, and there is simply no serious need to
> detect it.
The original question, however, asked "assuming we do detect this, how should
we report it?". I still believe that viral code should always be reported
as such (perhaps with a modifier such as "damaged", "dormant" or "variant")
and let the end user decide, but do not make them think there is no virus
there at all.
Antony.
--
There are only 10 types of people in the world:
those who understand binary notation,
and those who don't.
Please reply to the list;
please don't CC me.
-------------------------------------------------------
This SF.net email is sponsored by: Perforce Software.
Perforce is the Fast Software Configuration Management System offering
advanced branching capabilities and atomic changes on 50+ platforms.
Free Eval! http://www.perforce.com/perforce/loadprog.html