News: 1589970605

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Tech's Volkswagen moment? Trend Micro accused of cheating Microsoft driver QA by detecting test suite

(2020/05/20)


Trend Micro is on the defensive after it was accused of engineering its software to cheat Microsoft's QA testing, branding the allegation "misleading."

Bill Demirkapi, an 18-year-old computer security student at the Rochester Institute of Technology in the US, told The Register on Tuesday he was researching methods for detecting rootkits when he came across Trend's Rootkit Buster for Windows PCs.

A rootkit, for the uninitiated, is malware that, once on a machine with admin-level privileges, grants other malicious code or miscreants administrative access to the computer. It deliberately hides itself from view, which is why rootkit detectors are a thing.

While reverse-engineering Trend's rootkit-hunting tool and its kernel-mode driver, which appears to be common among Trend products, Demirkapi found some shortcomings in the code, and [1]publicly documented them. You need administrator access to exploit the holes he found, though that's beside the point: they are an easy way into the kernel for, ironically enough, rootkits and other malware that have gained admin access.

"Most of the security concerns I have with Trend Micro's driver were shocking because most of them were not mistakes," said Demirkapi, who has [2]presented at hacking super-conference DEF CON and is due to discuss Windows rootkits at Black Hat USA 2020.

"Trend Micro simply designed the driver to provide a significant amount of functionality to privileged callers in user-mode, allowing attackers to misuse the driver in several ways. The problem is that Trend Micro's driver is insecure by design, making it a perfect candidate for abuse by malicious actors around the world."

Crucially, a function named MysteriousCheck() in the kernel-level driver code caught Demirkapi's eye. Digging in further, he said he made a startling discovery. MysteriousCheck() appears to detect whether or not a specific Microsoft test suite – the driver verifier – is running on the computer.

This test suite is designed to ensure drivers meet Microsoft's Windows Hardware Quality Labs ( [3]WHQL ) requirements. If a driver meets this standard, it can be digitally signed by Microsoft, is trusted by Windows, and potentially can be distributed via Windows Update and similar mechanisms.

11 MILLION VW cars used Dieselgate cheatware – what the clutch, Volkswagen? [4]READ MORE

Demirkapi believes Trend's kernel driver is cheating on Microsoft's WHQL driver verification test: if the driver detects it is installed on a computer running the test, it alters its behavior to pass the examination, whereas outside the test, it would fail to meet Microsoft's quality standards.

So, what is the driver allegedly covering up? To pass Microsoft's tests, the software should, as a security precaution, allocate its memory from the operating system's [5]no-execute non-paged pool , aka NonPagedPoolNx. This is memory marked as non-executable for the system's CPU cores. That means even if miscreants or malware manage to stash malicious code in this memory, by exploiting a security hole, they can't just jump to these instructions and run them.

Microsoft's tests ensure a driver uses this non-executable memory. When Trend's driver is running on a computer under test, it is claimed, the software alters its operations to use the no-execute non-paged pool as expected; when the test isn't running, it allocates memory from the executable non-paged pool, which can be exploited and would fail Microsoft's tests. One reason for using executable dynamically allocated memory is to run code decompressed, decrypted, or otherwise generated or loaded on the fly; this is dangerous for kernel-level software.

"Passing [Microsoft's] driver verifier has been a long-time requirement of obtaining WHQL certification," Demirkapi noted on his website.

"On Windows 10, the driver verifier enforces that drivers do not allocate executable memory. Instead of complying with this requirement designed to secure Windows users, Trend Micro decided to ignore their user’s security and designed their driver to cheat any testing or debugging environment which would catch such violations.

"Honestly, I’m dumbfounded. I don’t understand why Trend Micro would go out of their way to cheat in these tests ... The only working theory I have is that for some reason most of their driver is not compatible with NonPagedPoolNx, and that only their entry point is compatible, otherwise there really isn’t a point."

Demirkapi went on:

I reverse a lot of drivers, and you do typically see some pretty dumb stuff, but I was shocked ... Most of the driver feels like proof-of-concept garbage that is held together by duck tape.

Although Trend Micro has taken basic precautionary measures, such as restricting who can talk to their driver, a significant amount of the code inside of the IOCTL handlers includes very risky direct kernel object manipulation.

In response, Trend Micro criticized Demirkapi's decision to disclose his findings publicly rather than privately, and attempted to downplay the research. It also denied it was circumventing Microsoft's tests.

"We believe this allegation is misleading," a spokesperson for the antivirus maker told The Register .

"The researcher did not inform us whereas standard and effective reporting for the industry would have required that he contact us first. Given this approach, one might assume the researcher is looking for attention over resolution.

We believe this allegation is misleading

"We are working closely in partnership with the Microsoft security driver team, and at no time was the Trend Micro team avoiding certification requirements.”

When pressed for an explanation as to why the driver was behaving in the manner described by the undergraduate, Trend had nothing more to offer. Demirkapi, meanwhile, said he can think of no reason for the inclusion of the MysteriousCheck() code, aside from evading the driver security test.

Microsoft said it is aware of the issue, and is "working closely with Trend Micro to investigate these claims."

Those of you with a good memory will remember way, way back to October when Trend's antivirus tools, during file scans, [6]automatically ran malware if its filename was cmd.exe or regedit.exe . ®



[1] https://d4stiny.github.io/How-to-use-Trend-Micro-Rootkit-Remover-to-Install-a-Rootkit/

[2] https://www.youtube.com/watch?v=HTj6zZd2jXE

[3] https://docs.microsoft.com/en-us/windows-hardware/drivers/install/whql-release-signature

[4] https://www.theregister.co.uk/2015/09/22/volkswagen_admits_11_million_cars_dieselgated/

[5] https://docs.microsoft.com/en-us/windows-hardware/drivers/kernel/no-execute-nonpaged-pool

[6] https://www.theregister.co.uk/2019/10/21/flaw_trend_micro/

Petty or Pedant?

Kevin Johnston

I know I shouldn't rise to this but...

"Most of the driver feels like proof-of-concept garbage that is held together by duck tape"

There is a brand name of Duck Tape but generically it is Duct Tape designed to be used when joining large hoses in ducting which need strength and flexibility at the joints.

Grrrrrr

Re: Petty or Pedant?

Scotthva5

Pedantic but correct.

Re: Petty or Pedant?

Anonymous Coward

Sticky-back-plastic please

Re: Petty or Pedant?

Anonymous Coward

Not Fablon?

Re: Petty or Pedant?

KittenHuffer

The stories I've seen is that it dates back to WW2 and was originally for providing a waterproof seal on ammo cases, and was named 'duck tape' by the squaddies that used it.

Does anyone have conclusive proof that this is, or is not, so?

Re: Petty or Pedant?

Anonymous Coward

Duct tape is an Americanism, a British squaddie would have known it as gaffer tape.

Re: Petty or Pedant?

Archivist

I think you'll find Gaffer Tape was invented for the film industry. The only squaddies were actors.

Petty or Pedant?

diodesign

No, you're just wrong.

Duck tape is an [1]alternative spelling of duct tape. Duck tape came before duct tape.

C.

[1] https://en.wikipedia.org/wiki/Duct_tape

I Guess

Julz

That MysteriousCheck() is less obvious than NSACheck().

If there is no God, who pops up the next Kleenex?
-- Art Hoppe