Ȱ Trojan ϸ Ʈ ħ, ȭ
ۼ 2008-12-02
ȸ : 11,309
By Walaika Haskins TechNewsWorld
01/15/08 2:28 PM PT
2008 2 , ̹ ˵ ε ġ Ʈ ݲ ξ ϰ . Ʈ ϴ Finjan software Ͽ ǥ Ʈ ϸ, ȣ Ͽ Ǽڵ带 չ Ʈ Ӻϰ ִ.
̱ ϸ Ѵ Ʈ 12 ֽ malware ݿ Ǿ. random js toolkit̶ Ҹ ͳݿ ִ ε ָڿ 鼭, ǻ ǻ ϴ ص ó ϱ Ʈ̸̴. ġ ͵鿡 ڵ ̸ ִ ťƮ, н, Ÿ ΰ Ե ִٰ Finjan ߴ.
2007 ߹ݿ, 3 Ǵ ȴٴ ְ ִ. Ʈ ȣϰų damage Ʈ ִ ٿε带 ϴ 80ۼƮ ŷ չ Ʈ ġϰ ִ. ó Ȳ ȭǰ ִٰ Finjan CTO, Yuval Ben-Itzhak ߴ.
ڵ
Finjan Software 12 ڵ Ʈ мϴ ÿ ̹ ֽ scheme ߰ߴ. random js toolkit Ǵ Javascript-x codeμ ѹ ִ random filename Ѵ. , ȴ.
code obfuscation̶ ˷ Ӻ ̷ ڰ Ǽ ڵ尡 Ӻ ϴ , 湮 Ǵ IP ּҷκ û ִ ٽ ̴. ̹ ˴ 湮 ǻ IPּҸ Ͽ, JavaScript-x ̻ Ʈ ҽ HTML ϵ Ѵ. ̴ signature-based anti-malware ǰ malware Ž Ұɡϵ ٰ Finjan ߴ.
̷ Ȱ ȿ ȸ Ű ÿ Ž ȸ ϱ Ͽ Ǽڵ ü δ. ϳ Ǽ Trojan ǻ Ű 13 ٸ exploit Ѵ.
̷ exploit zero-day ġ麸 ռ ϱ dynamic script-x signaturing ȿ ʴ. Exploiting code ü singaturingϴ ȿ ʴٰ Ben-Itzhak ߴ. ſ Ȯ ǽɽ ε ֽ Ʈ ϴ ̷ Ϳ ϴ ѵ åμ ۿ ̴.
Ŀ URL Ǵ reputation service ǰ Ž ϱ س Ѱ谡 ִٰ ȸ ߴ.
̹ ˵ Ʈ ٸ 湮ڿ Ǽ ϸ鼭, web crawler ϵ ϴ ݵͿ ִ web crawler-URL reputation service database ֿ ó- Ʈ ν ý ߸ ִ.
ϴ ͳ reputation service Ǽ Ʈȭ ϴ Ǵٸ ̴. Ʈ 湮 ǰ Ǵ ũ URL Ѵ. Finjan ߰ Ʈ Ŭ highly trusted ̾.
Ʈ Iframe-x/script-x ϴ ϰ ִ ̹ Ʈ Ϻ random js exploit ͷμ ȣ Ͽ û 鿡 . ̹ ˴ ȣ ŻϿ Ʈ Ͽ ħص ȣõǴ ε ڵ鿡 Trojan ų ̴. Finjan ϸ, request Ǽ ڵ带 ߰ ûϴ ʷ ̴.
ϰ ȣ
̹ ˰ Ϸ ϱ malware ȣǴ ͷμ ̾ ִٰ Sophos Graham Cluley ߴ.
Ŀ Ʈ Ʈ鿡 Ǽ script-x ɴ Ϲ ǰ ִ١ TechNewsWorld ߴ. Sophos 6,000 . ̷ Ʈ 5 1 ǵ Ʈ, hacker site̴.
80ۼƮ ŷ Ʈ̰ų Ǵ Ʈ ΰ 3ڿ ħص Ʈ̴١" Ư ۶߸ Ʈ 鿡 ٸ ̴" Cluley ̾ ߴ.
2009 malware ϴµ ſ ȿ ̱ , advertising network desktop ִ malware 30% å ̶ Gartner м Avivah Litan ߴ.
̰ ϴ ϳ̰-- ̷ Ͼ ַ ϱ ֵ ɻϴ Ұϴ١ ׳ TechNewWorld ߴ.
̰ ó ε Ǿ ɻϰ Ǵ Google ٸ ͳݿ ϵ Ѵ-- Ŀ malware Ե ִ.
ȭ ʴ´. ̰ ̴. ù°, óϴµ ﰡ μƼ갡 . ̰ Һڵ鿡 ظ , Ʈũ Ǹ Ұ ƮũԴ ظ ̴. , malware ǵ ߰ν adware ſ ı ̴ Litan ߴ.
Ǽ Ž ȸϰ м ư obfuscated JavaScript-x Ѵ. Obfuscated script-x ýۿ ߰ malware component ٿεϴ brower exploit Ѵ. װ͵ DZ , ̷ Ʈ Žϰ ϴ ƴ١ Cluley ߴ.
ܼ Ǵ Ʈ ϴ ̷ 鿡 Ͽ ڵ ȣϴµ ϴ. ǻ ڵ ȣϴ ַ īװ ִ װͿ ȣõǴ malware ִ ϱ , ż(on-the-fly) 湮 ˻ ִٸ, ̷ ٸ ϴµ ִ ״ ٿ.