Antivirus Evasion through Antigenic Variation (Why the Blacklisting Approach to AV is Broken)

Think of the last time you got sick. Your immune system is an amazing piece of machinery, but every now and then, something gets past it. Antivirus evasion techniques can become more effective when modeled after infectious diseases. This talk highlights many of the antivirus evasion techniques in use today. Going further, this talk shows how genetic algorithms can quickly and repeatedly “evolve” code to evade many malicious code detection techniques in use today. Trenton will be releasing a BETA version of a tool for the shellcode Ghostwriting process.

Presented by