
Apple의 내장 악성코드 보호 기능에 대한 교육적 심층 분석: 서명 데이터베이스, YARA 규칙, Gatekeeper 통합, 복구 바이너리 및 macOS 탐지 흐름.
macOS 소개 블로그 포스트 시리즈에 이어서, XProtect에 관한 짧은 블로그 포스트를 작성하기로 했습니다.
XProtect는 Apple이 macOS에 내장한 안티바이러스 및 악성코드 시그니처 시스템입니다.
XProtectService의 일부로 작동하며, 알려진 악성코드 시그니처가 있는지 애플리케이션 및 기타 실행 콘텐츠를 검사합니다.
XProtect는 백그라운드에서 작동하며 Apple이 XProtectRemediator 메커니즘을 통해 자동으로 업데이트합니다(자세한 내용은 나중에 설명).
다음과 같은 3가지 주요 기능이 있습니다:
/Library/Apple/System/Library/CoreServices/XProtect.bundle 디렉터리는 XProtect 구성과 시그니처 정의가 포함된 기본 번들입니다.
읽기 전용 시스템 디렉터리이며 Apple이 XProtect 업데이트를 통해 자동으로 업데이트합니다.
그 아래에는 흥미로운 파일 몇 개가 있는데, 모두 Apple이 주기적으로 업데이트하며 시스템 무결성 보호(SIP)로 보호됩니다.
/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.plist 파일에는 XProtect가 알려진 위협을 탐지하는 데 사용하는 악성코드 시그니처가 저장되어 있습니다.
이 파일에는 해시와 파일명 패턴을 포함하여 악성코드 패밀리를 특정 탐지 규칙에 매핑하는 항목이 포함되어 있습니다.
다음은 한 악성코드 패밀리인 Bundalore의 예시입니다:
<dict>
<key>Description</key>
<string>OSX.Bundlore.D</string>
<key>LaunchServices</key>
<dict>
<key>LSItemContentType</key>
<string>com.apple.application-bundle</string>
</dict>
<key>Matches</key>
<array>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>46617364554153</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20006500630068006F002000</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>20007C0020006F00700065006E00730073006C00200065006E00630020002D006100650073002D003200350036002D0063006600620020002D007000610073007300200070006100730073003A</string>
</dict>
<dict>
<key>MatchFile</key>
<dict>
<key>NSURLTypeIdentifierKey</key>
<string>com.apple.applescript.script</string>
</dict>
<key>MatchType</key>
<string>Match</string>
<key>Pattern</key>
<string>002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073</string>
</dict>
</array>
</dict>
이 표현은 꽤 읽기 쉬운 편이며, 주목할 만한 유일한 부분은 각 매치의 string 인자가 16진수 표현이라는 점입니다. 예를 들어 002D00730061006C00740020002D00410020002D00610020002D00640020007C002000620061007300680020002D0073는 -salt -A -a -d | bash -s에 해당합니다.
물론 이는 정확히 어떤 패턴을 피해야 하는지 알 수 있는, 악성코드 작성자에게는 금광과 같은 정보입니다.
/Library/Apple/System/Library/CoreServices/XProtect.bundle/XProtect.meta.plist 파일은 적용 정책과 버전 정보를 포함하여 XProtect에 대한 추가 규칙을 정의하는 메타데이터 파일입니다.
특정 XProtect 규칙을 적용하는 macOS 버전, 탐지 시 수행되는 조치, 그리고 플러그인 블랙리스트를 지정합니다.
다음은 예시입니다:
<key>JavaWebComponentVersionMinimum</key>
<string>1.6.0_45-b06-451</string>
<key>PlugInBlacklist</key>
<dict>
<key>10</key>
<dict>
<key>com.apple.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.apple.java.JavaPlugin2_NPAPI</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>14.8.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player ESR.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>18.0.0.382</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.macromedia.Flash Player.plugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>32.0.0.101</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.microsoft.SilverlightPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>5.1.41212.0</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
<key>com.oracle.java.JavaAppletPlugin</key>
<dict>
<key>MinimumPlugInBundleVersion</key>
<string>1.8.51.16</string>
<key>PlugInUpdateAvailable</key>
<true/>
</dict>
</dict>
</dict>
보시다시피, 여기에는 예를 들어 "블랙리스트에 등재된" 플러그인에 대한 버전 정보가 포함되어 있습니다.
최근 버전에서 XProtect는 YARA를 지원하기 시작한 것으로 보입니다.
/Library/Apple/System/Library/CoreServices/XProtect.bundle/Contents/Resources/XProtect.yara 파일에는 텍스트 형식의 여러 YARA 규칙이 포함되어 있습니다. 그중 짧은 예시는 다음과 같습니다:
rule XProtect_MACOS_SLEEPYSTEGOSAURUS_SYM {
meta:
description = "MACOS.SLEEPYSTEGOSAURUS.SYM"
uuid = "BB4F7D16-C939-4047-A9AF-E74E7B51FAC1"
strings:
$a1 = { 45 78 65 63 43 6D 64 }
$a2 = { 47 65 74 48 6F 73 74 49 6E 66 6F }
$a3 = { 52 75 6E 53 63 72 69 70 74 }
$a4 = { 52 75 6E 53 63 72 69 70 74 55 72 6C }
$a5 = { 4C 61 75 6E 63 68 50 6C 69 73 74 }
$a6 = { 43 68 65 63 6B 50 72 6F 63 65 73 73 }
$a7 = { 43 68 65 63 6B 49 6E }
$a8 = { 52 75 6E 43 6D 64 46 69 6C 65 }
$a9 = { 53 68 6F 77 48 74 6D 6C }
$a10 = { 50 6C 69 73 74 48 65 6C 70 65 72 }
$a11 = { 4C 61 75 6E 63 68 64 48 65 6C 70 65 72 }
$a12 = { 43 6F 6D 6D 61 6E 64 46 69 6C 65 }
$a13 = { 57 72 69 74 65 50 6C 69 73 74 }
$a14 = { 4A 53 4F 4E 46 69 6C 65 50 72 6F 63 65 73 73 6F 72 }
$a15 = { 43 68 72 6F 6D 65 48 65 6C 70 65 72 }
$a16 = { 53 61 6E 64 62 6F 78 65 72 }
condition:
Macho and filesize < 2MB and all of them
}
이 글은 YARA 규칙에 관한 블로그 포스트는 아니지만, 앞서 말한 대로 이는 악성코드 작성자에게 금광과 같은 정보입니다 (예: 43 68 65 63 6B 50 72 6F 63 65 73 73는 CheckProcess).