Behavioural modelling of social engineering based malicious software

Matthew Braverman Microsoft

Some of the most active threats in the wild today exploit weaknesses in the component with the largest attack surface area in the end-to-end operation of a computer: the user. Malicious software such as Sober, Netsky, Bagle, and Mywife can take control of a computer not because of any software bug or vulnerability but because they somehow lure the user to execute them, usually by running an attachment of an email. This paper will provide examples of poignant social engineering 'exploits' over the past few years and attempt to construct a model, using telemetry from Microsoft's Windows Malicious Software Removal Tool, that can predict the prevalence of a specific social engineering threat based on its characteristics and appeal to the user.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

VB2010

VB2010 VB2010 will take place 29 September-1 October 2009 at the Westin Bayshore, Vancouver, BC, Canada. Early bird discount available until 15th June 2010.
Virus Bulletin currently has 190,911 registered users.