Tuesday, June 17, 2014

Malware brief introduction:


Malware is a malicious software program (Mal+Ware=Malicious+software). Computer viruses, Trojan, Rootkits, Bootkits, Adware, Spyware, Backdoor, Crimeware, etc. comes under the category of malware. Malware is intended to infect the system, run the unauthorized programs in the system, utilize the system resources and even steal the credentials.

In dos virus era, computer viruses are used only for destruction purposes. And the earlier malware author did it for a fun and show their talent in the understanding of computers and its program's functionality. But the current trend is totally different. Yes, the current malware author not focusing on just destruction of the programs by infecting, their total focus on stealing the valuable credentials such as banking user name and password, email password, etc. Billions of Dollars were stolen using malware programs by malware authors.

Another important purpose of the malware is used as state of art and in other words as targeted attacks against a country or state, organisation by other arch-rival countries or organisation. It is known as APT (Advance persistent Threats). Threat actor may be underground cyber hacking groups or arch-rival Governments or state sponsored threat actors and its target is as we earlier told a country or state, big organisation (Billions of Dollars worth in terms of revenue).

Common people use the term virus (computer virus) for all the malicious programs, but computer virus is one of the malicious program or one of the categories in the malware. Virus files usually infect the system files and application files. So, it finally results in the malfunction of the computer programs. Only option is through disinfection method used by antivirus program or need to format the whole system and installing the operating system once again. Formatting the  system and installing the OS again, is time consuming work. Also, people will lost the important data stored in the system. If data may be songs and movies, but in greater extent, it was important official documents and it worth more than a movie or songs. In this case, using antivirus program is must. Since it have shield functionality to stop the known malware families or viruses to infect the system. Even infected program can be cleaned or disinfected by antivirus program, since they have cleaning routines for most of the virus families.

Antivirus or anti-malware engines will detect those malicious programs and remove it. Antivirus engine scan for signature in the all computer programs present in the system and notify the user. Signature is nothing but malicious code or routine and it only triggering the malicious event to happen. If such routines present in the file, then it will be detected by the antivirus engine. We can see more about on the same category in upcoming posts.

No comments:

Operating system - Part 1:

 In our blog, we published several articles on OS concepts which mostly on the perspective for malware analysis/security research. In few in...