Rootkits vs. Stealth by Design malware…

Posted by Xavier Ashe on February 3, 2006

The presentation I gave at Black Hat Federal
last week about new generation of stealth malware, so called Stealth by
Design (SbD) malware, which doesn't use any of the classic rootkit
technology tricks, but still offers full stealth, can be downloaded here:

And you can also get AVI demos here (10MB):

The presentation also focuses on limitations of the current
anti-rootkit technology and why it’s not useful in fighting SbD
malware. Consequently, alternative method for compromise detection is
advocated in this presentation, Explicit Compromise Detection (ECD), as
well as the challenges which Independent Software Vendors encounter
when trying to implement ECD for Windows systems – I call it Memory
Reading Problem (MRP).

Read the full blog post by Joanna.


