Newsletter:

Skip Navigation LinksHome > News > Security > Shape-shifting malware hits the web

Shape-shifting malware hits the web

By Clement James
15 May 2008 10:11PM
Tags: shapeshifting | malware | hits | web

Security experts have warned that new developments in malware are allowing criminals to stay one step ahead of security software.

Marc Henauer, head of the cyber-crime division at the Swiss Justice and Police Department, said in an interview last week that viruses and other malware now have the capability to change their signature every few hours.

This means that the attackers are often one step ahead of protection software.

Geoff Sweeney, chief technology officer at Tier-3, a behavioural analysis IT security firm, echoed the remarks.

"Self-changing code designed to dynamically evade recognition is a fact of life," he said. "It automatically adapts to the anti-spam and anti-malware engines that it encounters."

Unfortunately the know-how and construction kits used to create this shape-shifting threat are now readily available and are unleashing a wave of malware based on social engineering techniques.

"Highly targeted emails containing personalised information and shape-shifting Trojan attachments are the latest development," said Sweeney.

"Each positive infection increases the 'hit rate' for the next wave of emails sent out by the self-learning automated engines used by sophisticated attackers."

Sweeney believes that a non rules-based monitoring process must be set up to defend all ingress and egress points covering SMTP, DNS, HTTP(s), IM etc.

"Once this is in place, defence against shape-shifting threats becomes possible as does the removal of any previously established covert data leakage channels that will be revealed and dealt with," he said.

Copyright © 2008 vnunet.com

   


Ads by Google





Product Reviews

Star Rating
The Aventail EX-1600 is a high-end SSL VPN designed for the needs of medium to large enterprises.
Star Rating
The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of...
Star Rating
The Kerio WinRoute Firewall is an interesting product for this category.
Star Rating
The BiGuard S6000 extends the network to the remote user with features such as Network Extender, Transport...
Star Rating
Sendmail Sentrion DS 3.0 is a rack-mounted email authentication appliance used strictly for applying digital...
ITNews NetSeminars
TopTopics
(18952) -  iphone
(6343) -  telstra
(4226) -  accc
(4113) -  broadband
(4095) -  online
(4093) -  hack
(3743) -  australia
(3615) -  government
(3281) -  smartphone
(2923) -  microsoft
(2686) -  computer
(2091) -  apple
(1904) -  yahoo
(1815) -  spam
(1813) -  security