Strong Cryptography Armoured Computer Viruses Forbidding Code Analysis: the bradley virus - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Rapport (Rapport De Recherche) Année : 2004

Strong Cryptography Armoured Computer Viruses Forbidding Code Analysis: the bradley virus

Eric Filiol
  • Fonction : Auteur
  • PersonId : 833484

Résumé

Imagining what the nature of future viral attacks might look like is the key to successfully protecting against them. This paper discusses how cryptography and key management techniques may definitively checkmate antiviral analysis and mechanisms. We present a generic virus, denoted bradley which protects its code with a very secure, ultra-fast symmetric encryption. Since the main drawback of using encryption in that case lies on the existence of the secret key or information about it within the viral code, we show how to bypass this limitation by using suitable key management techniques. Finally, we show that the complexity of the bradley code analysis is at least as high as that of the cryptanalysis of its underlying encryption algorithm.
Fichier principal
Vignette du fichier
RR-5250.pdf (234.49 Ko) Télécharger le fichier

Dates et versions

inria-00070748 , version 1 (19-05-2006)

Identifiants

  • HAL Id : inria-00070748 , version 1

Citer

Eric Filiol. Strong Cryptography Armoured Computer Viruses Forbidding Code Analysis: the bradley virus. [Research Report] RR-5250, INRIA. 2004, pp.10. ⟨inria-00070748⟩
325 Consultations
759 Téléchargements

Partager

Gmail Facebook X LinkedIn More