Tuesday, June 16, 2009

PyAv - A Virus detection tool in Python

This is an antivirus project created in python.
The aim of this project is to create a tool which can detect a possible virus infection. By virus in this context, I mean the true virus ,that is programs which can attach themselves (or infect in other words)to the executable files (and possibly corrupting them too)so as to effect a reproductive mechanism. The virus code is loaded into memory first when the infected file is loaded. The loaded malicious code then continues to infect other files while executing the very task for which it was developed


In fact,the project can be modified to verify the integrity of any file indeed and hence can be altered as a file corruption detection tool . And with this tool,only the detection of an infection is possible and the way to disinfect/heal the infected file is not presented here.

The Source code can be downloaded here.

If you are interested in this project,just send a mail to appusajeev@gmail.com


Working:

The tool discussed here can detect if an executable is infected with a virus or not. It works in the following way:
First,in the assumed uninfected stage, the program calculates the md5 hash of all the executables in the system and stores it in a local database against the exe name. That done, periodic check can be done by in which the md5 hash of each executable is calculated and verified with the corresponding md5 sum stored in the database. In the event of an infection, the binary contents of the executable and hence the md5 hash changes and this change can point to a possible virus infection. And its up to the user to decide what he should do with the infected file.

Coding:

The coding is done in Python 2.5 and uses OOP model. It uses md5 ,sqlite3,os and glob modules which comes with the default installation

The md5 module provides the methods to calculate the md5 sum of a string.To calculate the md5 sum of a file, the entire contents of the file are read and the md5 sum of the stream is calculated.

Sqlite3 module is used for routine database operations like add , retrieve,delete using SQL. It implements a simple and compact DBMS which i guess,would suffice for this project. The database file used is md5db.db. There are two tables-md5s whose fields are exefile and md5sum and the second table is folders with the field folders.

So far, I have not integrated a GUI part into it, but that can be done.


Methods:

The module pyav.py contains the class pyav which presents the following methods

sync_folder(path)

This method takes a path given by the user, traverses the directory recursively (dfs) and for each executable found, the md5 hash is calculated and stored in the local database against its exe name
For example:
sync_folder(”C:\\windows”) would calculate and store the md5 hash of all the executables in the windows folder and its subfolders downto all levels.

verify_integrity(path)

This method takes a path provided by the user, does recursive directory traversal and verifies the integrity of all the executables found by calculating its md5 hash and comparing the hash with the corresponding hash stored in the database. If the hashes don’t match, the file has been modified since is entry to the database it points to a possible virus infection(exes modification can also be due to a patch applied the user may ignore this as the case may be).
Upon detection, the user may take the appropriate decision.
Also, if the path given as argument has not been synced yet, corresponding message will be outputted

add_exe(path)

Adds the exe and the corresponding hash into the database.

verify_exe(path)

Calculates the md5 hash of the executable specified in path,compares it with the corresponding hash stored in the database and returns 1 if the hashes match and zero otherwise

compare_exes(file1,file2)

Calculates and compares the md5 hash of the files files1 and file2. If the hashes are equal, 1 is returned and 0 is returned otherwise…this can be used to verify the integrity of file1 wrt file 2 which is the same file1 which is supposed to be infection free.

return_infected(clear=0)

This method returns the list of all the infected files ie files whose contents have been found to be modified when the verify_integrity() method was invoked. The clear argument is by default set to 0.If it is set to 1,the infected list will be cleared after it is returned.

update_list_exes()

This method during runtime,updates and returns the list of executables whose hash has been entered into the database .

update_list_folders()

Updates and returns the list of folders which have been synced using sync_folder().

cleardb()

This method clears the database off all the entries.

read_all()

Prints all the exes and corresponding hashes that have been added to the database.

closedb()

This method closes the database connection. It is recommended to call this method before the termination of the program.


No comments:

Post a Comment