Evading Antivirus Detection by Abusing File Type Identification

Uloženo v:
Podrobná bibliografie
Název: Evading Antivirus Detection by Abusing File Type Identification
Autoři: Udomwongsa, Chavin
Zdroj: Computer Science Senior Theses
Informace o vydavateli: Dartmouth Digital Commons
Rok vydání: 2024
Sbírka: Dartmouth Digital Commons (Dartmouth College)
Témata: binwalk, polyfile, file type identification, antivirus, security and privacy, Computer Sciences
Popis: File type identification is a vital step in automated file processing, especially in the realm of malware detection. The challenges with file type identification and evasion techniques that take advantage of them were pointed out over a decade ago. We show that this remains the case: file type identification implementations are still fragile, especially for files with ambiguous file types. We present a novel antivirus bypass technique via crafted tar archives that evades all detection from VirusTotal and numerous antiviruses: BitDefender, F-Secure, Kaspersky, Panda Dome, Trend Micro, Quick Heal, IKARUS, Avira. These crafted files evade detection by tricking file type identification implementations, but can still be unpacked on end-host machines using GNU tar or 7-zip. We show that these file type-masquerading archives are also incorrectly labeled by popular file type identifiers. We present a survey of publicly available tools for file type identification and shared file signature databases. Finally, we discuss countermeasures for this evasion technique by detecting files with ambiguous file types.
Druh dokumentu: text
Popis souboru: application/pdf
Jazyk: unknown
Relation: https://digitalcommons.dartmouth.edu/cs_senior_theses/44; https://digitalcommons.dartmouth.edu/context/cs_senior_theses/article/1033/viewcontent/Kris_Thesis.pdf
Dostupnost: https://digitalcommons.dartmouth.edu/cs_senior_theses/44
https://digitalcommons.dartmouth.edu/context/cs_senior_theses/article/1033/viewcontent/Kris_Thesis.pdf
Přístupové číslo: edsbas.D5CD7843
Databáze: BASE
Buďte první, kdo okomentuje tento záznam!
Nejprve se musíte přihlásit.