Certified Malware: Measuring Breaches of Trust in the Windows Code-Signing PKI
Doowon Kim, Bum Jun Kwon, Tudor Dumitras
摘要
Digitally signed malware can bypass system protection mechanisms that install or launch only programs with valid signatures. It can also evade anti-virus programs, which often forego scanning signed binaries. Known from advanced threats such as Stuxnet and Flame, this type of abuse has not been measured systematically in the broader malware landscape. In particular, the methods, effectiveness window, and security implications of code-signing PKI abuse are not well understood. We propose a threat model that highlights three types of weaknesses in the code-signing PKI. We overcome challenges specific to code-signing measurements by introducing techniques for prioritizing the collection of code-signing certificates that are likely abusive. We also introduce an algorithm for distinguishing among different types of threats. These techniques allow us to study threats that breach the trust encoded in the Windows code-signing PKI. The threats include stealing the private keys associated with benign certificates and using them to sign malware or by impersonating legitimate companies that do not develop software and, hence, do not own code-signing certificates. Finally, we discuss the actionable implications of our findings and propose concrete steps for improving the security of the code-signing ecosystem.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper7
- Survivalism: Systematic Analysis of Windows Malware Living-Off-The-LandFrederick Barr-Smith, Xabier Ugarte-Pedrero, Mariano Graziano, Riccardo Spolaor 等S&P 2021 · 被引用 73 次
- The Broken Shield: Measuring Revocation Effectiveness in the Windows Code-Signing PKIDoowon Kim, Bum Jun Kwon, Kristián Kozák, Christopher Gates 等USENIX Security 2018 · 被引用 32 次
- Countering Malicious Processes with Process-DNS AssociationSuphannee Sivakorn, Kangkook Jee, Yixin Sun, Lauri Korts-Pärn 等NDSS 2019 · 被引用 22 次
- SIRAJ: A Unified Framework for Aggregation of Malicious Entity DetectorsSaravanan Thirumuruganathan, Mohamed Nabeel, Euijin Choo, Issa Khalil 等S&P 2022 · 被引用 13 次
- Measuring and Modeling the Label Dynamics of Online Anti-Malware EnginesShuofei Zhu, Jianjun Shi, Limin Yang, Boqin Qin 等USENIX Security 2020
它引用的顶会 Paper4
- Measurement and Analysis of Private Key Sharing in the HTTPS EcosystemFrank Cangialosi, Taejoong Chung, David R. Choffnes, Dave Levin 等CCS 2016 · 被引用 89 次
- Investigating Commercial Pay-Per-Install and the Distribution of Unwanted SoftwareKurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod 等USENIX Security 2016 · 被引用 77 次
- Measuring PUP Prevalence and PUP Distribution through Pay-Per-Install ServicesPlaton Kotzias, Leyla Bilge, Juan CaballeroUSENIX Security 2016 · 被引用 74 次
- Catching Worms, Trojan Horses and PUPs: Unsupervised Detection of Silent Delivery CampaignsBum Jun Kwon, Virinchi Srinivas, Amol Deshpande, Tudor DumitrasNDSS 2017 · 被引用 30 次
相关 Paper
- Understanding the Status and Strategies of the Code Signing Abuse EcosystemHanqing Zhao, Yiming Zhang, Lingyun Ying, Mingming Zhang 等NDSS 2026
- Unveiling BYOVD Threats: Malware's Use and Abuse of Kernel DriversAndrea Monzani, Antonio Parata, Andrea Oliveri, Simone Aonzo 等NDSS 2026 · 被引用 5 次
- A Comprehensive Measurement Study of Domain Generating MalwareDaniel Plohmann, Khaled Yakdan, Michael Klatt, Johannes Bader 等USENIX Security 2016 · 被引用 252 次
- DRSM: De-Randomized Smoothing on Malware Classifier Providing Certified RobustnessShoumik Saha, Wenxiao Wang, Yigitcan Kaya, Soheil Feizi 等ICLR 2024 · 被引用 6 次
- Bamboozling Certificate Authorities with BGPHenry Birge-Lee, Yixin Sun, Anne Edmundson, Jennifer Rexford 等USENIX Security 2018 · 被引用 83 次
