
एप्पल के अंतर्निहित मैलवेयर सुरक्षा में शैक्षिक गहन अध्ययन: सिग्नेचर डेटाबेस, YARA नियम, Gatekeeper एकीकरण, रिमेडिएशन बाइनरी, और macOS डिटेक्शन प्रवाह।
macOS परिचय पर अपनी ब्लॉगपोस्ट श्रृंखला को जारी रखते हुए, मैंने XProtect को एक छोटी ब्लॉगपोस्ट समर्पित करने का निर्णय लिया है।
XProtect, macOS के लिए Apple का अंतर्निर्मित एंटीवायरस और मैलवेयर सिग्नेचर सिस्टम है।
यह XProtectService के भाग के रूप में कार्य करता है, जो ज्ञात मैलवेयर सिग्नेचर के लिए एप्लिकेशन और अन्य निष्पादन योग्य सामग्री को स्कैन करता है।
XProtect पृष्ठभूमि में कार्य करता है और Apple द्वारा XProtectRemediator तंत्र के माध्यम से चुपचाप अपडेट किया जाता है (इस पर बाद में और अधिक)।
इसके 3 प्राथमिक कार्य हैं:
निर्देशिका /Library/Apple/System/Library/CoreServices/XProtect.bundle मुख्य बंडल है जिसमें XProtect कॉन्फ़िगरेशन और सिग्नेचर परिभाषाएँ होती हैं।
यह एक केवल-पठनीय सिस्टम निर्देशिका है और Apple द्वारा XProtect अपडेट के माध्यम से चुपचाप अपडेट की जाती है।
इसके अंतर्गत, हमें कुछ रुचिकर फ़ाइलें मिल सकती हैं, जो सभी समय-समय पर Apple द्वारा अपडेट की जाती हैं और System Integrity Protection (SIP) द्वारा सुरक्षित होती हैं।
फ़ाइल /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist XProtect द्वारा ज्ञात खतरों का पता लगाने के लिए उपयोग किए जाने वाले मैलवेयर सिग्नेचर संग्रहीत करती है।
इसमें मैलवेयर परिवारों को विशिष्ट पहचान नियमों, जिनमें हैश और फ़ाइलनाम पैटर्न शामिल हैं, से मैप करने वाली प्रविष्टियाँ होती हैं।
यहाँ एक मैलवेयर परिवार का उदाहरण है - Bundalore:
<dict>
<key>Description</key>
<string>OSX.Bundlore.D</string>
<key>LaunchServices</key>
<dict>
<key>LSItemContentType</key>
<string>com.apple.application-bundle</string>
</dict>
<key>Matches</key>
<array>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>46617364554153</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20006500630068006F002000</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
</dict>
</array>
</dict>
यह काफी मानव-पठनीय है, एकमात्र उल्लेखनीय भाग यह है कि प्रत्येक मैच में string तर्क हेक्साडेसिमल-प्रस्तुति है, जैसे 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073 -salt -A -a -d | bash -s के अनुरूप है।
यह, निश्चित रूप से, मैलवेयर लेखकों के लिए एक सोने की खान है, जो जानते हैं कि किन पैटर्न से बचना है।
फ़ाइल /Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist एक मेटाडेटा फ़ाइल है जो XProtect के लिए अतिरिक्त नियमों को परिभाषित करती है, जिसमें प्रवर्तन नीतियाँ और संस्करण जानकारी शामिल हैं।
यह निर्दिष्ट करती है कि कौन से macOS संस्करण कुछ XProtect नियमों को लागू करते हैं और पहचान पर की जाने वाली कार्रवाइयाँ, साथ ही प्लगइन्स के लिए ब्लैकलिस्ट भी।
यहाँ एक उदाहरण है:
<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
<key>10</key>
<dict>
<key>com.apple.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.apple.java.JavaPlugin2_NPAPI</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player ESR.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>18.0.0.382</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>32.0.0.101</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.microsoft.SilverlightPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>5.1.41212.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.oracle.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>1.8.51.16</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
</dict>
</dict>
जैसा कि आप देख सकते हैं, उनमें उदाहरण के लिए "ब्लैकलिस्टेड" प्लगइन्स के लिए संस्करण जानकारी होती है।
हाल के संस्करणों में, XProtect ने YARA का समर्थन करना शुरू कर दिया है।
फ़ाइल /Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara में टेक्स्ट-प्रारूप में कई YARA नियम हैं, यहाँ इसका एक छोटा उदाहरण है: