[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]  [Register] 

Status: Not Logged In; Sign In

The White House just held its first cabinet meeting in almost a year. Guess who was running it.

The Democrats' War On America, Part One: What "Saving Our Democracy" Really Means

New York's MTA Proposes $65.4 Billion In Upgrades With Cash It Doesn't Have

More than 100 killed or missing as Sinaloa Cartel war rages in Mexico

New York state reports 1st human case of EEE in nearly a decade

Oktoberfest tightens security after a deadly knife attack in western Germany

Wild Walrus Just Wanted to Take A Summer Vacation Across Europe

[Video] 'Days of democracy are GONE' seethes Neil Oliver as 'JAIL' awaits Brits DARING to speak up

Police robot dodges a bullet, teargasses a man, and pins him to the ground during a standoff in Texas

Julian Assange EXPOSED

Howling mad! Fury as school allows pupil suffering from 'species dysphoria' to identify as a WOLF

"I Thank God": Heroic Woman Saves Arkansas Trooper From Attack By Drunk Illegal Alien

Taxpayers Left In The Dust On Policy For Trans Inmates In Minnesota

Progressive Policy Backfire Turns Liberals Into Gun Owners

PURE EVIL: Israel booby-trapped CHILDRENS TOYS with explosives to kill Lebanese children

These Are The World's Most Reliable Car Brands

Swing State Renters Earn 17% Less Than Needed To Afford A Typical Apartment

Fort Wayne man faces charges for keeping over 10 lbs of fentanyl in Airbnb

🚨 Secret Service Announces EMERGENCY LIVE Trump Assassination Press Conference | LIVE Right Now [Livestream in progress]

More Political Perverts, Kamala's Cringe-fest On Oprah, And A Great Moment For Trump

It's really amazing! Planet chocolate cake eaten by hitting it with a hammer [Slow news day]

Bombshell Drops: Israel Was In On It! w/ Ben Swann

Cash Jordan: NYC Starts Paying Migrants $4,000 Each... To Leave

Shirtless Trump Supporter Puts CNN ‘Reporter’ in Her Place With Awesome Responses

Iraqi Resistance Attacks Two Vital Targets In Israels Haifa

Ex-Border Patrol Chief Says He Was Instructed By Biden-Harris Admin To Hide Terrorist Encounters

Israeli invasion of Lebanon 'will lead to DOOMSDAY' and all-out war,

PragerUMiss Universe Bankrupt after Trans Takeover: Former Judge Weighs In

Longtime Democratic Campaign Operative Quits the Party After What She Saw at the DNC

Dr. Lindsey Doe is teaching people that Pedophilia is a sexual orientation…


Science/Tech
See other Science/Tech Articles

Title: WikiLeaks' latest leak shows how CIA avoids antivirus programs
Source: [None]
URL Source: http://thehill.com/policy/cybersecu ... hows-how-cia-avoids-anti-virus
Published: Apr 1, 2017
Author: Joe Uchill
Post Date: 2017-04-01 08:09:44 by Ada
Keywords: None
Views: 56

WikiLeaks released its third package of CIA documents on Friday which highlight source code used by the CIA to avoid antivirus programs.

The source code is for a tool called "Marble," what is known as an obfuscator or packer.

Obfuscators are principally designed to jumble the execution of malware so that programs designed to spot malware have trouble determining what it is.

The Marble toolkit includes a variety of different algorithms to accomplish that task.

In its release, WikiLeaks describes the primary purpose of Marble as being to insert foreign language text into the malware to cause malware analysts to falsely attribute code to the wrong nation.

This appears to be an inaccurate description of the primary purpose of the code, however.

While the code can insert any language text or sequence of characters into the code, or English text, the point appears to be more about eliminating the original intent of coders than causing an incorrect attribution.

Analysts are more likely to lump together multiple uses of the same packer algorithm featuring text from multiple languages then they are to assume the languages accurately describe the country of origin. Though language artifacts in the code are the easiest investigatory tool to explain to a non-technical audience, the are neither the only nor the most telling piece of evidence used in an attribution.

Nicholas Weaver, a researcher with the International Computer Science Institute at the University of California at Berkeley, said in a statement that releasing the packer will allow antivirus companies to block CIA malware, but notes that is only in the public interest if "disrupting the CIA's operations for the sake of disrupting the CIA's operations is in your 'public interest.'"

While releasing information about security flaws in products being exploited by the CIA may one day be independently discovered and exploited by malicious hackers, obfuscators can only be used to help prevent attacks by the group using that specific obfuscator — in this case, the CIA.

Now, Weaver said, WikiLeaks is forcing antivirus companies to block the CIA packer because, by releasing it publicly, "[t]hey practically guarantee that a bunch of digital miscreants will start using it as well, because 'hey, a CIA packer for my malcode, cool!'" Weaver said.

Marble is the third in a series of leaks from WikiLeaks that purportedly come from a secure CIA network. The first two largely described CIA hacking techniques.

Post Comment   Private Reply   Ignore Thread  



[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]  [Register]