Rootkits And Bootkits: Reversing Modern Malware And Next Generation Threats
Book information
Description
Rootkits and Bootkits will teach you how to understand and counter sophisticated, advanced threats buried deep in a machine's boot process or UEFI firmware. With the aid of numerous case studies and professional research from three of the world's leading security experts, you'll trace malware development over time from rootkits like TDL3 to present-day UEFI implants and examine how they infect a system, persist through reboot, and evade security software. As you inspect and dissect real malware, you'll learn: • How Windows boots—including 32-bit, 64-bit, and UEFI mode—and where to find vulnerabilities • The details of boot process security mechanisms like Secure Boot, including an overview of Virtual Secure Mode (VSM) and Device Guard • Reverse engineering and forensic techniques for analyzing real malware, including bootkits like Rovnix/Carberp, Gapz, TDL4, and the infamous rootkits TDL3 and Festi • How to perform static and dynamic analysis using emulation and tools like Bochs and IDA Pro • How to better understand the delivery stage of threats against BIOS and UEFI firmware in order to create detection capabilities • How to use virtualization tools like VMware Workstation to reverse engineer bootkits and the Intel Chipsec tool to dig into forensic analysis Cybercrime syndicates and malicious actors will continue to write ever more persistent and covert attacks, but the game is not lost. Explore the cutting edge of malware analysis with Rootkits and Bootkits. Covers boot processes for Windows 32-bit and 64-bit operating systems. Brief Contents......Page 11 Contents in Detail......Page 13 Foreword......Page 21 Acknowledgments......Page 25 Abbreviations......Page 27 Introduction......Page 31 What’s in the Book?......Page 32 Part 2: Bootkits......Page 33 How to Read This Book......Page 35 Part I: Rootkits......Page 37 Chapter 1: What’s in a Rootkit: The TDL3 Case Study......Page 39 History of TDL3 Distribution in the Wild......Page 40 Infection Routine......Page 41 Bring Your Own Linker......Page 43 How TDL3’s Kernel-Mode Hooks Work......Page 44 The Hidden Filesystem......Page 46 Conclusion: TDL3 Meets Its Nemesis......Page 48 Chapter 2: Festi Rootkit: The Most Advanced Spam and DDoS Bot......Page 49 The Case of Festi Botnet......Page 50 Dissecting the Rootkit Driver......Page 51 Festi Configuration Information for C&C Communication......Page 52 Plug-in Management......Page 53 Built-in Plug-ins......Page 55 Anti–Virtual Machine Techniques......Page 56 The Method for Hiding the Malicious Driver on Disk......Page 58 The Method for Protecting the Festi Registry Key......Page 61 Work Phase......Page 62 Bypassing Security and Forensics Software......Page 63 The Domain Generation Algorithm for C&C Failure......Page 66 The Spam Module......Page 67 The DDoS Engine......Page 68 Festi Proxy Plug-in......Page 69 Conclusion......Page 70 Chapter 3: Observing Rootkit Infections......Page 71 Intercepting System Events......Page 72 Intercepting System Calls......Page 73 Intercepting the File Operations......Page 76 Intercepting the Object Dispatcher......Page 77 Restoring the System Kernel......Page 79 The Great Rootkits Arms Race: A Nostalgic Note......Page 80 Conclusion......Page 82 Part II: Bootkits......Page 83 Chapter 4: Evolution of the Bootkit......Page 85 Elk Cloner and Load Runner......Page 86 The End of the BSI Era......Page 87 The Kernel-Mode Code Signing Policy......Page 88 Modern Bootkits......Page 89 Conclusion......Page 91 Chapter 5: Operating System Boot Process Essentials......Page 93 High-Level Overview of the Windows Boot Process......Page 94 The Legacy Boot Process......Page 95 The Master Boot Record......Page 96 The Volume Boot Record and Initial Program Loader......Page 98 The bootmgr Module and Boot Configuration Data......Page 100 Conclusion......Page 104 Chapter 6: Boot Process Security......Page 105 API Callback Routines......Page 106 How Bootkits Bypass ELAM......Page 108 Location of Driver Signatures......Page 109 The Legacy Code Integrity Weakness......Page 110 The ci.dll Module......Page 112 Defensive Changes in Windows 8......Page 113 Secure Boot Technology......Page 114 Virtualization-Based Security in Windows 10......Page 115 Virtual Secure Mode and Device Guard......Page 116 Device Guard Limitations on Driver Development......Page 117 Conclusion......Page 118 Chapter 7: Bootkit Infection Techniques......Page 119 MBR Code Modification: The TDL4 Infection Technique......Page 120 MBR Partition Table Modification......Page 126 IPL Modifications: Rovnix......Page 127 VBR Infection: Gapz......Page 128 Conclusion......Page 129 Chapter 8: Static Analysis of a Bootkit Using IDA Pro......Page 131 Loading and Decrypting the MBR......Page 132 Analyzing the BIOS Disk Service......Page 137 Analyzing the Infected MBR’s Partition Table......Page 140 Analyzing the IPL......Page 142 Evaluating Other Bootkit Components......Page 143 Advanced IDA Pro Usage: Writing a Custom MBR Loader......Page 144 Implementing accept_file......Page 145 Implementing load_file......Page 146 Creating the Partition Table Structure......Page 147 Exercises......Page 149 Chapter 9: Bootkit Dynamic Analysis: Emulation and Virtualization......Page 151 Emulation with Bochs......Page 152 Creating a Bochs Environment......Page 153 Infecting the Disk Image......Page 155 Using the Bochs Internal Debugger......Page 157 Combining Bochs with IDA......Page 159 Virtualization with VMware Workstation......Page 160 Configuring the VMware Workstation......Page 161 Combining VMware GDB with IDA......Page 162 Exercises......Page 166 Chapter 10: An Evolution of MBR and VBR Infection Techniques: Olmasco......Page 169 Dropper Resources......Page 170 Tracing Functionality for Future Development......Page 172 Antidebugging and Antiemulation Tricks......Page 173 Bootkit Infection Technique......Page 174 Boot Process of the Infected System......Page 176 Maintaining the Hidden Filesystem......Page 177 Implementing the Transport Driver Interface to Redirect Network Communication......Page 180 Conclusion......Page 181 Chapter 11: IPL Bootkits: Rovnix and Carberp......Page 183 Rovnix’s Evolution......Page 184 The Bootkit Architecture......Page 185 Infecting the System......Page 186 Implementing the Polymorphic Decryptor......Page 188 Decrypting the Rovnix Bootloader with VMware and IDA Pro......Page 189 Taking Control by Patching the Windows Bootloader......Page 195 Loading the Malicious Kernel-Mode Driver......Page 199 Injecting the Payload Module......Page 200 Stealth Self-Defense Mechanisms......Page 202 The Hidden Filesystem......Page 203 Accessing the Hidden Filesystem......Page 204 The Hidden Communication Channel......Page 205 Development of Carberp......Page 207 Dropper Enhancements......Page 209 Leaked Source Code......Page 210 Conclusion......Page 211 Chapter 12: Gapz: Advanced VBR Infection......Page 213 The Gapz Dropper......Page 214 Dropper Analysis......Page 216 Bypassing HIPS......Page 217 Reviewing the BIOS Parameter Block......Page 222 Infecting the VBR......Page 224 Loading the Malicious Kernel-Mode Driver......Page 225 Gapz Rootkit Functionality......Page 227 Hidden Storage......Page 229 Self-Defense Against Antimalware Software......Page 230 Payload Injection......Page 232 Payload Communication Interface......Page 237 Custom Network Protocol Stack......Page 240 Conclusion......Page 242 Chapter 13: The Rise of MBR Ransomware......Page 243 A Brief History of Modern Ransomware......Page 244 Ransomware with Bootkit Functionality......Page 245 The Ransomware Modus Operandi......Page 246 Acquiring Administrator Privileges......Page 248 Infecting the Hard Drive (Step 1)......Page 249 Encrypting with the Malicious Bootloader Configuration Data......Page 251 Crashing the System......Page 255 Encrypting the MFT (Step 2)......Page 256 Wrapping Up: Final Thoughts on Petya......Page 260 The Satana Dropper......Page 261 The MBR Infection......Page 262 Dropper Debug Information......Page 263 The Satana Malicious MBR......Page 264 Wrapping Up: Final Thoughts on Satana......Page 266 Conclusion......Page 267 Chapter 14: UEFI Boot vs. the MBR/VBR Boot Process......Page 269 The Unified Extensible Firmware Interface......Page 270 Disk Partitioning: MBR vs. GPT......Page 271 Other Differences......Page 273 GUID Partition Table Specifics......Page 274 How UEFI Firmware Works......Page 278 The UEFI Specification......Page 279 Inside the Operating System Loader......Page 281 The Windows Boot Loader......Page 286 Conclusion......Page 289 Chapter 15: Contemporary UEFI Bootkits......Page 291 WinCIH, the First Malware to Target BIOS......Page 292 Mebromi......Page 293 An Overview of Other Threats and Counters......Page 294 All Hardware Has Firmware......Page 297 (In)Effectiveness of Memory Protection Bits......Page 299 Checks for Protection Bits......Page 300 Ways to Infect the BIOS......Page 301 Modifying an Unsigned UEFI Option ROM......Page 303 Understanding Rootkit Injection......Page 305 Hacking Team’s Vector-EDK Rootkit......Page 311 Conclusion......Page 319 Chapter 16: UEFI Firmware Vulnerabilities......Page 321 What Makes Firmware Vulnerable?......Page 322 Classifying UEFI Firmware Vulnerabilities......Page 325 Post-Exploitation Vulnerabilities......Page 326 Compromised Supply Chain Vulnerabilities......Page 327 Supply Chain Vulnerability Mitigation......Page 328 A History of UEFI Firmware Protections......Page 329 SPI Flash Protections and Their Vulnerabilities......Page 330 BIOS Protection with Secure Boot......Page 333 Intel Boot Guard Technology......Page 335 Vulnerabilities in Boot Guard......Page 336 Exploiting SMI Handlers......Page 338 Understanding the S3 Boot Script......Page 342 Targeting Weaknesses of the S3 Boot Script......Page 343 Exploiting the S3 Boot Script Vulnerability......Page 344 A History of ME Vulnerabilities......Page 347 Case Studies: Attacks on Intel AMT and BMC......Page 348 Conclusion......Page 351 Part III: Defense and Forensic Techniques......Page 353 Chapter 17: How UEFI Secure Boot Works......Page 355 UEFI Secure Boot Implementation Details......Page 356 The Boot Sequence......Page 357 Executable Authentication with Digital Signatures......Page 358 The db Database......Page 359 The dbx Database......Page 362 Secure Boot Keys......Page 364 UEFI Secure Boot: The Complete Picture......Page 366 Secure Boot Policy......Page 368 Protection Against Bootkits Using Secure Boot......Page 370 Patching PI Firmware to Disable Secure Boot......Page 371 Modifying the UEFI Variables to Bypass Security Checks......Page 373 Protecting Secure Boot with Verified and Measured Boot......Page 374 Intel BootGuard......Page 375 Finding the ACM......Page 376 Exploring FIT......Page 378 Configuring Intel BootGuard......Page 379 ARM Trust Zone......Page 382 ARM Boot Loaders......Page 383 Trusted Boot Flow......Page 384 Conclusion......Page 386 Chapter 18: Approaches to Analyzing Hidden Filesystems......Page 387 Overview of Hidden Filesystems......Page 388 Reading Data on a Live System......Page 389 Hooking the Miniport Storage Driver......Page 390 The HiddenFsReader Tool......Page 396 Conclusion......Page 398 Chapter 19: BIOS/UEFI Forensics: Firmware Acquisition and Analysis Approaches......Page 399 Attacking the Supply Chain......Page 400 Understanding Firmware Acquisition......Page 401 The Software Approach to Firmware Acquisition......Page 403 Locating PCI Configuration Space Registers......Page 404 Using the SPI Registers......Page 405 Reading Data from the SPI Flash......Page 408 Considering the Drawbacks of the Software Approach......Page 409 The Hardware Approach to Firmware Acquisition......Page 410 Reviewing a Lenovo ThinkPad T540p Case Study......Page 411 Locating the SPI Flash Memory Chip......Page 412 Reading the SPI Flash with the FT2232 Mini Module......Page 413 Getting to Know the SPI Flash Regions......Page 416 Viewing SPI Flash Regions with UEFITool......Page 417 Analyzing the BIOS Region......Page 419 Analyzing the Firmware Image with Chipsec......Page 422 Getting to Know the Chipsec Architecture......Page 423 Analyzing Firmware with Chipsec Util......Page 424 Conclusion......Page 426 Index......Page 427
Similar books
Rootkits, infiltration du noyau Windows
2006 · PDF
Rootkits and Bootkits: Reversing Modern Malware and Next Generation Threats
2019 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF
Idries Shah 27 Books Collection : A Perfumed Scorpion, A Veiled Gazelle, Caravan of Dreams, Darkest England, Destination Mecca, Evenings with Idries Shah, Knowing How to Know, Learning How to Learn, Letters and Lectures of Idries Shah, Neglected aspects of Sufi study, Observations, Oriental Magic, Reflections, Seeker after Truth, Special Illumination, Special Problems in the study of Sufi ideas, Sufi thought and action, Tales of the Dervishes, The Dermis Probe, The Elephant in the Dark, The Englishman Handbook, Idries Shah Antology, The Magic Monastery, The natives are restless, wisdom of the Idiots PDF.
2022 · PDF