Virtual Machine Detection in Malware via Commercial Tools
More About Sophisticated Malware
http://isc.sans.org/diary.php?storyid=1871
Virtual machine detection is a self-defensive property of many malware specimens. It is aimed at making it harder to examine the malicious program, because virtualization software, such as VMware, is a very popular tool among malware analysts. For instance, 3 our of 12 malware specimens recently captured in our honeypot refused to run in VMware.
It is getting harder to detect malware after it has found some entry point into a system, and malware is getting better at sneaking onto systems through normal channels, and not waiting for published vulnerabilities.
About Logik!
Andrew S. Baker aka ASB aka Logik!
Andrew is an accomplished, hands-on executive with broad technology expertise and proven track record of generating sustainable business results through implementation of effective processes and controls, design and deployment of superior technology infrastructure, and strategic and tactical leadership of IT teams.
He regularly provides thought leadership on business and technology issues via mailing lists, technical forums, blogs, professional networking groups, as well as contributions to podcasts, webinars, and technical/business magazine articles. Additionally, Andrew holds active roles on several boards and committees for non-profit organizations, and within the Seventh-day Adventist church.
His personal interests include Astronomy, Basketball, Bible Study, Chess, Comics, Computers,
Family Life Ministries, Reading, Strategy/Role Playing games, and Professional Networking...
A condensed version of
Andrew's current resume is available here.