ºÚÁÏ´«ËÍÃÅ

Friedrich Gross - Hochschule Worms

Universität Ulm

This talk is a practice run for the presentation of our paper "A Warden to Analyze and Counter Stegomalware Activities" at the CUING Workshop.

Abstract: Malware has increasingly been observed using covert communications.
It is possible to perform network-level counterattacks against such malware by manipulating their connections in a way that causes delayed command execution or causes fail-states in the malware.
To this end, we developed an active warden capable of manipulating network traffic live in-flow, either by degrading the connection itself or directly rewriting packet contents.
Its purpose is to provide the scientific community with the ability to arbitrarily edit packets in real time to aid in malware analysis and the development of countermeasures.
We evaluated our warden against remote access tools commonly used for malicious purposes. 
We show that it can be used to cause targeted erroneous behaviour in command-and-control servers and debilitate the connection without outright dropping it. 
The warden was also deployed and evaluated against legitimate browser traffic.