home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!cs.utexas.edu!zaphod.mps.ohio-state.edu!pacific.mps.ohio-state.edu!cis.ohio-state.edu!news.sei.cmu.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: bontchev@fbihh.informatik.uni-hamburg.de (Vesselin Bontchev)
- Newsgroups: comp.virus
- Subject: Re: How to measure polymorphi
- Message-ID: <0003.9301221631.AA12947@barnabas.cert.org>
- Date: 14 Jan 93 10:46:30 GMT
- Sender: virus-l@lehigh.edu
- Lines: 23
- Approved: news@netnews.cc.lehigh.edu
-
- bill.lambdin%acc1bbs@ssr.com (Bill Lambdin) writes:
-
- > How about releasing a polymorphic virus on a test machine with several
- > thousand bait files that are identical. 2-5 thousand bait files should be
- > enough.
-
- > infect these bait files, then use a program that would generate CRC's of
- > all of the infected files then delete the duplicates.
- >
- > If the MtE generates fewer dupes than the others, call it the most
- > polymorphic
-
- Not good enough... A virus that puts a single word (two bytes) of
- random garbage in the decryptor will be flagged as more polymorphic
- than MtE by your scheme...
-
- Regards,
- Vesselin
- - --
- Vesselin Vladimirov Bontchev Virus Test Center, University of Hamburg
- Tel.:+49-40-54715-224, Fax: +49-40-54715-226 Fachbereich Informatik - AGN
- < PGP 2.1 public key available on request. > Vogt-Koelln-Strasse 30, rm. 107 C
- e-mail: bontchev@fbihh.informatik.uni-hamburg.de D-2000 Hamburg 54, Germany
-