• On MovieTome: TRANSFORMERS 2 SPOILERS!

October 31, 2005 4:55 PM PST

Evasion bug bites virus shields

A flaw in several virus scanners could let a malicious file evade detection, a security researcher has warned. But some in the industry dispute that it's a security bug.

By adding some data to a file, an attacker could trick virus scanners into letting a malicious executable file pass through, security researcher Andrey Bayora wrote in an advisory last week. The problem lies in the scanning engine, which won't detect files that have the extra data. Bayora refers to that extra data as the "Magic Byte."

The problem affects numerous antivirus products, including software from Trend Micro, McAfee, Computer Associates and Kaspersky Lab, said Bayora, who works as a computer security consultant in Israel. His advisory also lists several products that are not affected, including software from Symantec, F-Secure and BitDefender.

"This is one of the most significant antivirus vulnerabilities of recent times, as it affects the majority of scanner software," Bayora wrote in an article on his Web site that details the issue.

Bayora originally disclosed details of the flaw on Oct. 24. Since then, the topic has been the topic of lively discussions on the popular Full Disclosure security mailing list.

The issue is further evidence that researchers are increasingly looking for holes in security products. Protective technology is commonly installed on PCs, servers, network gateways and mobile devices. As security software becomes more widespread, it becomes a more attractive target to cybercriminals, experts have said.

But in this case, what Bayora calls out as a vulnerability in virus-scanning engines, some in the industry see as inherent to signature-based protection of antivirus software.

"It's not a real security vulnerability, as this is the way antivirus scanners work: If someone creates a new malware, the antivirus industry will create a new signature for it," said Andreas Marx, an antivirus software expert at the University of Magdeburg in Germany. "This way always leaves a detection and protection gap."

The signature lists used in antivirus software are like a dictionary of descriptions of known viruses. The virus-scanning process looks for matches against that dictionary. If a new threat is found, a signature is added.

Bayora actually created a variant of a virus, said Ken Williams, a representative of Computer Associates. "Modifying a virus to the point where it is no longer detectable does not qualify as a vulnerability. Most viruses are modified in this way over time on a regular basis, and CA treats this as a new virus variant," he said in a statement.

But Kaspersky and Trend Micro do see the Magic Byte issue as a software flaw and are offering updates to fix it.

"A patch for affected products is currently being tested and should be available within a week," Kaspersky said in a notice on its Web site. Trend Micro has addressed the "potential vulnerability" in the latest version of its virus pattern files, a representative said in an e-mailed statement.

According to Trend Micro, the problem in its product is limited to one specific type of potential virus file that typically would be blocked in most enterprise e-mail systems and would need to be executed manually. In a posting to a security mailing list, Bayora identified that file type as a batch, or .bat, file.

McAfee did not respond to requests seeking comment for this story.

See more CNET content tagged:
Trend Micro Inc., Kaspersky Lab, virus, antivirus software, antivirus

Add a Comment (Log in or register) 7 comments
Sympathy for AV vendors
by n3td3v October 31, 2005 5:22 PM PST
While people are more than happy to discuss technical information over security product bugs, to find resolve, many folks just don't have much sympathy for AV vendors, when things go bad.
Reply to this comment View reply
Attack the illness not the symptom
by Johnny Mnemonic November 1, 2005 12:23 AM PST
I'm not a Windows user, consequently I'm not
afraid of receiving email from total strangers.
Reply to this comment View reply
A chance of litte profit from spam
by Antispambusiness January 10, 2007 6:08 AM PST
While it is impossible to get rid of spam completely, there's a possibility to get some profit from spam emails: read them and try to think of it as of source of ideas for relevant content websites. Because spam emails usually contains pretty popular topics to care about. I'm not talking about phentermine, of course!
Reply to this comment
Powered by Jive Software
advertisement

Latest tech news headlines

Resource center from News.com sponsors
You Need The Speed of Norton 2009
Introducing Norton Internet Security™2009

Click Here!
With one-click, one-minute install, under 8MB of memory usage and fewer, shorter scans, it's the fastest security suite anywhere. Norton. Smart Security, Engineered for Speed. Get a FREE trial today!

Click Here!
The Fastest Security Suite Anywhere

Experience the revolutionary Norton Internet Security™ 2009. With Norton™ Insight, a new feature, you get precision security that targets only at risk files for fewer, faster, shorter scans

Win a Trip to Space!*

Enter the Blast Off with Norton Sweepstakes for your shot at a trip to space. You could experience being fast and weightless, just like the new Norton 2009. *No purchase necessary; click for full details.

FREE Trial!

Act now to get your FREE trial of Norton Internet Security 2009. Try it for the protection. Love it for the speed

Norton Safe Web NEW!

A community-based system that rates web site safety

Norton Labs NEW!

Users can download new security technologies and share input directly with developers. Help us shape our future products!

RSS Feeds

Add headlines from CNET News to your homepage or feedreader.

More feeds available in our RSS feed index.

advertisement

Inside CNET News

Scroll Left Scroll Right