H-online.com
The report states that "Our results indicate that exploit delivery mechanisms are becoming increasingly complex and evasive." It goes on to describe how the writers of malware are fighting back against the measures used against them, and cites, for example, the growth of social engineering techniques which can thwart VM-based honeypots and JavaScript obfuscation which can be used to evade both browser emulators and anti-virus engines. It also mentions how malware writers are aware of the ranges of IP addresses likely to be used by detection systems, and how there has been a rise in IP cloaking to avoid detection. IP cloaking involves a malware distributing site serving benign content to any visiting detection system but malicious content to a normal visitor.
The report concludes that none of these detection methods are sufficient on their own to provide protection and it recommends that a multi-pronged approach is needed to improve detection rates.
Complete Article Publish : http://www.h-online.com/security/news/item/Google-reports-on-four-years-of-experience-in-malware-detection-1325798.html
No comments:
Post a Comment