arXiv · 1401.6120
Analysis and Diversion of Duqu's Driver
Abstract
The propagation techniques and the payload of Duqu have been closely studied over the past year and it has been said that Duqu shared functionalities with Stuxnet. We focused on the driver used by Duqu during the infection, our contribution consists in reverse-engineering the driver: we rebuilt its source code and analyzed the mechanisms it uses to execute the payload while avoiding detection. Then we diverted the driver into a defensive version capable of detecting injections in Windows binaries, thus preventing further attacks. We specifically show how Duqu's modified driver would have detected Duqu.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Guillaume Bonfante, Jean-Yves Marion, Fabrice Sabatier, Aurélien Thierry. 2014-01-08. Analysis and Diversion of Duqu's Driver. https://arxiv.org/abs/1401.6120
Cite the original work for its findings. Save a collection to share your selection of sources.