Security - Standards and Policies on Packer Use

JMH

Banned
Local time
12:59 AM
Messages
6,448
For those people who missed my presentation at Virus Bulletin this year, I co-presented on the topic of "proper" packer usage. The idea of a “proper” way to use packers is two-fold:
(a) It reduces the prevalence of legitimate packers being used to pack malware.
(b) It makes it easier to identify packers which exist only to pack malware.
This is an industry-wide initiative, with backing from over a dozen security companies, including McAfee, Symantec, IBM, and Trend Micro. It also has the backing of some big packer vendors: Enigma, Obsidium, Oreans (the makers of Themida), and VMPSoft (the makers of VMProtect), but it's not limited to the people who sell packers - open-source packers will be supported, too. To quell any concerns, it's not being run by the anti-malware industry - we're just participants. The IEEE is in charge of it all.

Why do it at all? Imagine this situation: Alice is a packer vendor. She sells her product to Bob. Carol is an anti-malware vendor, and she also sells her product to Bob. Then along comes Dave, the malware author, who manages to steal Bob's copy of Alice's product, and uses it to pack malware. Carol now needs a way to identify the malware that is packed using Bob's stolen packer. How? Introducing "taggants."

A "taggant" is a block of data that can be used to identify a packer family, and protect a unique packer license ID, among other things. You might compare taggants to watermarks, which are another form of encoded unique identifier, but taggants provide their identifier information in a cryptographically secure fashion. That block of identifying data is protected by a strong cryptographic algorithm. If a packer includes a taggant in the packed file, then anti-malware software can know immediately if the packed sample was produced by a legitimate packer, or if that copy of the packer was stolen. If the packer was stolen, then the packed file could be immediately prevented from executing. The file doesn't even need to be unpacked to determine that, so the check is fast!

Best of all, the system will be free for all packer vendors to use, and it's completely transparent to the users.

Are you a packer vendor and want to sign on? For more information, you can review our VB 2010 presentation (.PPT), or you can read a paper I’ve co-authored on standards and policies (.PDF) for packer use available from my website.
Source -
Standards and Policies on Packer Use - Microsoft Malware Protection Center - Site Home - TechNet Blogs
 

My Computer My Computer

Computer Manufacturer/Model Number
LAPTOP. HP Pavilion dv7-4010TX .
OS
Win 7 Ultimate 64-bit. SP1.
CPU
Intel i7 -720QM.[1.6GHz Turbo Boost 2.8GHz. 6MB Cache.]
Memory
8 DDR 3 RAM. 1066MHZ
Graphics Card(s)
ATI 1024 MB. DDR3. Radeon HD5650
Monitor(s) Displays
17.3" High Definition Brightview LCD. LED Backlit.
Screen Resolution
1600 x 900.
Hard Drives
640GB
Case
Laptop / notebook.
Mouse
Logitech Anywhere mouse. MX.
Internet Speed
ADSL [ but too slow ]
This sound like it would help honest people only and I think that is what it's meant for. Those that try to steel programs, movies, games, ect. will still get infected and that's good.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Home made Desktop
OS
Windows 10 Pro. 64/ version 1709 Windows 7 Pro/64
CPU
Intel i7-6800K @ 4.3
Motherboard
ASUS X-99 Deluxe II
Memory
Corsair Platinum 16 gig @2400
Graphics Card(s)
EVGA GTX 1070 OC
Monitor(s) Displays
Asus 27" LED LCD/VE278Q
Screen Resolution
1920-1080 or 1280-720 HDMI
Hard Drives
INTEL SSD 730-240 Gb Sata 3.0/
PSU
EVGA Platium 1200W
Case
Phanteks Luxe Tempered Glass 8 fans/ one radiator
Cooling
XSPC/ Water Cooled CPU
Keyboard
Das 4 Professional
Mouse
Logitech M705/MX Anywhere 2-S
Internet Speed
100 mbits
Antivirus
Microsoft Security Essentials/ Malwarebytes Premium 3.0/ SAS
Browser
I.E. 11 default/Firefox/ ISP Time Warner Cable/Spectrum
Other Info
LG BluRay Burner/
Sound system-KLipsch-THX/
Icy Dock ssd Hot Swap bays.
Back
Top