|
|
|
|
|
by weinzierl
695 days ago
|
|
"that all inputs are absolutely trusted" This is something funny to say when the inputs contain malware signatures, which are essentially determined by the malware itself. I mean, how hard would it be to craft a malware that has the same signature as an important system file? Preferably one that doesn't cause immediate havoc when quarantined, just a BSOD after reboot, so it slips through QA. Even if the signature is not completely predictable, the bad guys can try as often as they want and there would not even be way to detect these attempts. |
|
No they're not. The tool vendor decides the signature, they pick something characteristic that the malware has and other things don't, that's the whole point.
> how hard would it be to craft a malware that has the same signature as an important system file?
Completely impossible, unless you mean, like, bribe one of the employees to put the signature of a system file instead of your malware or something.