1.6 Typical Examples of Viruses and Trojans
73
– Code packaging and encryption;
– Determining the actual use of tests and anti-debugging.
Let us consider them in more detail.
Code obfuscation—bringing the source code or executable program code to a
form that preserves its functionality, but significantly complicates the analysis and
understanding of the operation algorithms, as well as modification during decompilation. Obfuscation can be carried out at various levels: algorithm level, source
code level, machine code (assembly text) level. In this category, security specialists
separately distinguish obfuscation at the level of virtual machines. To create such an
intricate machine code, specialized compilers using the unobvious or undocumented
features of the program execution environment may come in handy. There are also
special obfuscation programs called obfuscators [35].
Disadvantages of obfuscation:
– Obfuscated code may become more dependent on the used platform or compiler;
– Further program code debugging and testing are impossible after obfuscation;
– Obfuscation provides for hiding malicious logic through the obscurity of program
code, however, none of the popular obfuscators used today can guarantee immunity to a certain level of decompilation complexity and ensure security at the level
of modern cryptographic schemes.
Code Section Packaging and Encryption. In this method, the code for the encoder
and the key generator is embedded in the software. As a result, the program operating
on-the-fly decrypts the machine code instructions and transmits them for execution.
Using this method for countering tests can significantly narrow their testing capabilities. This approach renders direct disassembly of the program code impossible.
Additionally, the storage of memory dumps for subsequent disassembly becomes
extremely inefficient, since each dump contains only a small decoded piece of
program [35].
Determining the Actual Use of Tests and Anti-debugging. There is a number of
techniques known to experts that can be useful in establishing the fact of testing and
debugging. If such fact is established by the program, counter-analysis actions are
automatically taken to change the logic of its operation:
– Algorithm of work is changed;
– Execution of the program code is stopped;
– debugger data are “spoilt.”
Such anti-debugging methods in case of establishing the fact of counteraction are
overcome using tact simulators. In this case, debugging detection is possible only
in case of errors in the simulator, leading to behavior different from the hardware
platform [35].
Polymorphism—generation of different versions of machine code for the same
algorithm. Modern technology of polymorphic machine code generation in some
cases provides for confusing transformations of protected software. For this purpose,
additional or insignificant instructions are embedded in the protected code; the
73
– Code packaging and encryption;
– Determining the actual use of tests and anti-debugging.
Let us consider them in more detail.
Code obfuscation—bringing the source code or executable program code to a
form that preserves its functionality, but significantly complicates the analysis and
understanding of the operation algorithms, as well as modification during decompilation. Obfuscation can be carried out at various levels: algorithm level, source
code level, machine code (assembly text) level. In this category, security specialists
separately distinguish obfuscation at the level of virtual machines. To create such an
intricate machine code, specialized compilers using the unobvious or undocumented
features of the program execution environment may come in handy. There are also
special obfuscation programs called obfuscators [35].
Disadvantages of obfuscation:
– Obfuscated code may become more dependent on the used platform or compiler;
– Further program code debugging and testing are impossible after obfuscation;
– Obfuscation provides for hiding malicious logic through the obscurity of program
code, however, none of the popular obfuscators used today can guarantee immunity to a certain level of decompilation complexity and ensure security at the level
of modern cryptographic schemes.
Code Section Packaging and Encryption. In this method, the code for the encoder
and the key generator is embedded in the software. As a result, the program operating
on-the-fly decrypts the machine code instructions and transmits them for execution.
Using this method for countering tests can significantly narrow their testing capabilities. This approach renders direct disassembly of the program code impossible.
Additionally, the storage of memory dumps for subsequent disassembly becomes
extremely inefficient, since each dump contains only a small decoded piece of
program [35].
Determining the Actual Use of Tests and Anti-debugging. There is a number of
techniques known to experts that can be useful in establishing the fact of testing and
debugging. If such fact is established by the program, counter-analysis actions are
automatically taken to change the logic of its operation:
– Algorithm of work is changed;
– Execution of the program code is stopped;
– debugger data are “spoilt.”
Such anti-debugging methods in case of establishing the fact of counteraction are
overcome using tact simulators. In this case, debugging detection is possible only
in case of errors in the simulator, leading to behavior different from the hardware
platform [35].
Polymorphism—generation of different versions of machine code for the same
algorithm. Modern technology of polymorphic machine code generation in some
cases provides for confusing transformations of protected software. For this purpose,
additional or insignificant instructions are embedded in the protected code; the
