By Nikos Karampatziakis, Jack W. Stokes, Anil Thomas, Mady Marinescu (auth.), Ulrich Flegel, Evangelos Markatos, William Robertson (eds.)

This booklet constitutes the refereed post-proceedings of the ninth foreign convention on Detection of Intrusions and Malware, and Vulnerability evaluate, DIMVA 2012, held in Heraklion, Crete, Greece, in July 2012. the ten revised complete papers provided including four brief papers have been conscientiously reviewed and chosen from forty four submissions. The papers are equipped in topical sections on malware, cellular protection, safe layout, and intrusion detection structures (IDS).

Out-of-Band Network Channel. The ME environment introduces Out-Of-Band (OOB) communication, i. , a special network traffic channel used by iAMT. The iAMT enabled computer platform is managed by a remote management console using OOB. OOB is also available regardless of the power state. OOB can be considered to be a separate network connection, running on the same hardware. The ICH implements necessary components to support the ME environment with the OOB feature. The firmware filters network traffic intended for, e.

Attacking Intel TXT via SINIT code execution hijacking. pdf 34. : Following the White Rabbit: Software attacks against Intel VT-d technology. pdf 35. : Another Way to Circumvent Intel(R) Trusted Execution Technology. de Abstract. Downloaders are malicious programs with the goal to subversively download and install malware (eggs) on a victim’s machine. In this paper, we analyze and characterize 23 Windows-based malware downloaders. , P2P), carrier protocols and encryption schemes. Using dynamic malware analysis traces from over two years, we observe that 11 of these downloaders actively operated for at least one year, and identify 18 downloaders to be still active.

A lot of targets were found near 0x36e0000, i. , search times of around 12,500 ms that could also be saved. This increases the probability to miss keyboard buffer addresses. That is, we can get better (similar to the Windows attack) search times at the expense of effectiveness. The best case Understanding DMA Malware 35 search times are sufficient to capture hard disk encryption passwords, for example. We tested this successfully with a Linux system. The Windows kernel can swap out memory pages to the hard disk – Linux does not.

