Archive notice: This article was originally published on May 5, 2008. Links and embedded videos are preserved as part of the historical record.
Modifying known viruses as quickly as possible so that they can slip past virus scanners’ signature detection is the aim of the competition “The Race to Zero”. It will be held at the DEF CON 16 hacker conference in Las Vegas in August. Among other things, the organisers want the competition to demonstrate how easily and quickly signature-based antivirus solutions can be tricked. “Signature-based virus protection is dead”, is one of the central statements. This insight is no longer new to the antivirus industry, however; proactive techniques are already widespread.
According to pressetext.de, the organisers want the competition to convey messages such as “Reverse engineering and code analysis are fun”. Over several rounds of increasingly complex tasks, participants are to disguise malware samples so that a range of antivirus tools no longer recognises them. The winner of a round is the individual or team that first tricks all the protection solutions. In addition to an overall winner, other winners are to be chosen, for example for particularly elegant obfuscation or the “dirtiest hack”. The organisers also want to show which antivirus solutions perform particularly poorly in the competition. “Comparing the quality of different antivirus software certainly offers benefits to users, but a hacker contest is not necessarily needed for that”, comments antivirus specialist Martin Penzes of Sicontact in an interview with pressetext.
The competition aims to prove that signature-based detection methods in antivirus solutions are no longer sufficient. The organisers stress that no new viruses will be created. Nor are modified samples to be released “into the wild”, in other words onto the World Wide Web. However, there are also no plans to pass the techniques used to mutate viruses on to antivirus manufacturers without the participants’ permission. “Race to Zero’s website links to known virus-exchange sites and suggests that interested people should ‘improve their skills’ by practising with malware from those sites. The risk of amateurs making mistakes and releasing malicious code ‘into the wild’ is alarmingly high”, warns Graham Cluley, Senior Technology Consultant at Sophos, in an interview with British IT publication The Register.
Further Links:
- Competition Information
Def Con