Researchers 'Map' Android Malware Genome
yahoi writes "Researchers at NC State are sharing their analysis and classification of Android malware samples under a new project that they hope will help shape a new way of fighting malware, learning from the lessons of the PC generation and its traditional anti-malware products. Xuxian Jiang, the mastermind behind the Android Malware Genome Project, says defenses against this malware today are hampered by the lack of efficient access to samples (PDF), as well as a limited understanding of the various malware families targeting the Android. The goal is to establish a better way of sharing malware samples and analysis, and developing better tools to fight it, he says."
Remember how Slashdot spent 10+ years mocking Windows for being a malware-laden cesspool of unremovable OEM junkware with an antivirus industry built around it? Embarrassed yet?
The malware genome points to Java ?
Muchas Gracias, Señor Edward Snowden !
the size of a Windows map?
In fact, I don't think there's a super computer capable of mapping it.
Why is it that there is no malware for IOS? There are millions of these devices out there, so there certainly is an incentive for malware writers.
I believe that it has something to do with the fact that only Apple approved and checked software can be installed thereon. This closed system may not appeal to many here on /., but it is certainly as close as we have gotten to a malware proof computing experience we are likely to get anytime soon. Mac users will be able to enjoy this form of security with OS X 10.8 this summer.
A sufficiently advanced simulation is indistinguishable from reality.
It comes from One Microsoft way in Redmond?
DARPA has a project going on this right now...it's called the "Cyber Genome" project. The idea is that you can perform a fair bit of attribution to the person/organization that wrote a piece of malware based on the characteristics of the code. It's true, as well...examination of Stuxnet, for example, made it clear that it was probably written by a highly organized team of diverse and very skilled individuals. And that's just looking at a single piece of malware; looking at things like Zeus has shown the progression of it, and even how malware can fork and develop along different lines. If you take it to the next step, the goal is to be able to predict the characteristics of an iteration before it's even written. Yeah, nobody said DARPA tries to solve easy problems :)
For your security, this post has been encrypted with ROT-13, twice.
Who says I'm reading?
Notice how one makes sense, the other doesn't:
How to get Android and Malware in the same article.
AccountKiller
"didn't stop files named like c:\playerhost.dll from ending up in my home directory, on Linux. I guess you can say that I was saved by Linux's lack of popularity on the desktop, nothing else".
..
No, you couldn't say that, how playerhost.dll got onto your home directory was you saved it there. And even if it was a Linux executable you would still have to perform a numbr of steps to get it to run, as well as supply the root password.
"You can claim that many of those vulnerabilities are gone now that Adobe has stopped developing Flash for Linux"
That's news to me,
'Download Adobe Flash Player
Adobe Flash Player version 11.2.202.235
Your system: Linux 32-bit, Firefox` link
AccountKiller
"I was under the impression that most Android malware was of the trojan variety"
Microsoft Researcher produces a report on 'Android` malware, well who would have thought?
How's it feel knowing that ur YEARS of "FUD" b.s. is crumbling around ur ears, boys?
Question: What's it LIKE being known as a pack of utter bullshit artists online now, & especially after a DECADE OF SOLID CRAP along the lines of "Windows != Secure & Linux = Secure" horseshit... hmmm??
I knew the day would come when Linux (or variants like ANDROID) would take "top spot" on SOME computing platform (in this case, smartphones) & get "NUKED" as badly as Windows does due to its MASSIVE DOMINANCE of the combined PC & Server world... well, that's day's here on ANDROID (a linux) on smartphones).
It's simply because malware makers in general are JUST LIKE PICKPOCKETS, & go where the "easy meat victims" are, which IS where "the masses" go. They get better "ROI" for their creation of their bogus machinations that way... just like shooting ducks in a pack in the sky.
Of course, I have to "toss this in" also for "good measure" as well from 2011-2012 (which ALWAYS gets "downmodded", facts in it OR NOT):
2012:
Medicaid hack update: 500,000 records and 280,000 SSNs stolen:
http://www.zdnet.com/blog/security/medicaid-hack-update-500000-records-and-280000-ssns-stolen/11444
So, what's dts.utah.gov running everyone?
LINUX (and yes, it got HACKED) -> http://uptime.netcraft.com/up/graph?site=dts.utah.gov
What's health.utah.gov running too??
YOU GUESSED IT: LINUX AGAIN -> http://uptime.netcraft.com/up/graph?site=health.utah.gov
* Ah, yes - see the YEARS OF /. "BS" FUD is CRUMBLING AROUND THE PENGUINS EARS HERE & 2012's starting out just like 2011 did below!
===
2011:
KERNEL.ORG COMPROMISED - The Cracking of Kernel.org: (that's VERY bad - do you trust it now?)
http://linux.slashdot.org/story/11/08/31/2321232/Kernelorg-Compromised
---
Linux.com pwned in fresh round of cyber break-ins:
http://www.theregister.co.uk/2011/09/12/more_linux_sites_down/
---
Mysql.com Hacked, Made To Serve Malware:
http://it.slashdot.org/story/11/09/26/2218238/mysqlcom-hacked-made-to-serve-malware
What's that site running? You guessed it - Linux -> http://uptime.netcraft.com/up/graph?site=mysql.com
---
London Stock Exchange serving malware:
http://slashdot.org/submission/1484548/London-Stock-Exchange-Web-Site-Serving-Malware
(I mean hey - NOT ONLY DID LINUX FALL FLAT ON ITS FACE less than a few minutes into the job http://linux.slashdot.org/story/11/02/19/0147232/London-Stock-Exchange-Price-Errors-Emerged-At-Linux-Launch, & crash not only ONCE, but TWICE there? You see "Linux 'fine security'" in motion @ the LSE too!)
---
DUQU ROOTKIT/BOTNET BEING SERVED FROM LINUX SERVERS:
http://it.slashdot.org/story/11/11/30/1610228/duqu-attackers-managed-to-wipe-cc-servers
---
Linux Foundation, Linux.com Sites Down To Fix Security Breach:
http://linux.s