HomeinetResearchers managed to detect the "invisible" malware DAGGER

Researchers managed to detect the “invisible” malware DAGGER

daggerLast year, security researchers Patrick Stewinand Iurii Bystrov managed to develop a malware called DAGGER, (PDF) that can target specific computer hardware, such as network and graphics cards, to launch attacks by leveraging direct memory access (DMA).

Now researchers from the Technical University of Berlin claim to have discovered a way to detect malware like DAGGER. Their research is funded by the German government.

Initially, DAGGER was a keylogger that could be used on both Linux and Windows systems. Meanwhile, DMA-based malwarecannot be detected by current security mechanisms.

In a presentation to be given during the 16th International Symposium on Research in Attacks, experts will demonstrate a method that can be used to detect DMA-based attacks.

“We are the first to present a new method for detecting and preventing DMA-based attacks. Our method is based on modeling the expected memory bus activity and comparing it with actual activity,” the presentation abstract states.

Stewin told SC Magazine that there have been some detectors in the past. However, they did not work without modifying the peripherals or without a special debug feature. The detector developed by the experts does not require any modifications and does not use excessive resources from the system running it.

SC Magazine published a video demonstrating how DAGGER is able to obtain passwords stored on a system:

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS