/dev/null: Anti-Cheat Kernel Driver (2020)
leagueoflegends.com
leagueoflegends.com
> Now, while most players might find the idea of a corrupted Windows installation objectionable, a disturbing number of cheaters have shown themselves to be downright enthusiastic about the opportunity to jump onto some guy’s botnet in exchange for the ability to orbwalk
Kernel mode cheats do not require joining some guy’s botnet or installing a rootkit, even if they use similar techniques. If this claim was true, Riot would have every incentive to publish more detailed analysis in order to deter people from cheating. However, popular cheats aren’t malware, so they can’t do that. Instead, they’ll just stick to vague insinuations.
It’s a lost battle anyway, DMA cheats keep getting better every day. They will inevitably render clientside anticheat obsolete.
These require buying physical harder instead of someone being able to just download a cheat for free. Also if you are writing memory to cheat / sending weird packets you can detect that and ban them.
Decent hacks are already rather expensive, it’s not unusual for people to pay above $100/mo.
> Also if you are writing memory to cheat […] you can detect that and ban them.
There is no generic way to detect this.
You have the anticheat hook the game to monitor the game setting the memory and then the anticheat waits for the cheat to modify a location in memory.
It's a cat and mouse game, but that's the nature of anticheats.
and they're not cheap, $59.99/month would be pretty middle of the road
a cheap $30 card is nothing
once economies of scale take off they'll be $19.99
Oh, thanks for mentioning those! I wasn't keeping track of what's going on with "cheats/anti-cheats" and I've just learned those are finally a thing. The concept was obvious since forever, of course, but I've searched for the phrase and realized it had actually materialized and seem to became fairly mainstream (mass production PCI Express cards, neat!) rather than just a theoretical idea or proof-of-concept hardware.
It’s very cool.
Non proctored hacking is totally defeated, the last available bastion is audio hacking (just continuously play beeps where enemies are so even if they’re hiding and not moving, even a proctored session would be able to make use of it).
Meh, https://github.com/EngineOwningSoftware/pcileech-webradar
Obviously this doesn't scale, so it'll be limited to paid leagues and tournaments.
I didn't know anything about this world, but this video was a great explanation/demo:
It is a rather popular practice to bundle things like discord token stealers amongst cheat developers to find people acting against them. While more uncommon, it isn't unheard of shipping a whole RAT alongside with the cheat.
> It’s a lost battle anyway, DMA cheats keep getting better every day. They will inevitably render clientside anticheat obsolete.
If an anti-cheat manages to stop all client-side cheating - it has already won. Requiring a hardware device to be shipped / being unable to start cheating right after a quick online purchase will deter most of the people that are considering purchasing cheats.
No anticheat, kernel mode or not, has come even close to that. The situation has remained mostly unchanged for at least a decade now.
It’s the cheat developers who have an opportunity to seriously demoralize anticheat developers, not the other way around. The proliferation of DMA cheats will make any time spent fighting software based cheating significantly less valuable.
While the situation has mostly "unchanged" from the perspective of the end-user, the barrier of entry to start making cheats has been raised quite a bit.
I'd say making a commercially viable cheat (assuming you actually care about your customers not getting hit by every ban wave) isn't exactly a trivial matter nowadays.
> The proliferation of DMA cheats will make any time spent fighting software based cheating significantly less valuable.
The future you talk about is not yet here. External device based cheats are a miniscule part of the current cheating market.
Doubt it. There is no alternative on open platforms. Serverside anticheats are dead on arrival, they are and will always be easy to fool.
So they acknowledge that running third-party stuff in kernel mode increases the likelihood your machine gets owned by malware, in the very same blog post where they tell you that from now on, they demand the ability to run their own third-party stuff in kernel mode on your machine.
Which is utter nonsense. Nothing will touch this kernel mode stuff unless they’ve already owned your machine. All the data you care about is accessible from usermode anyway.
The risks of kernel mode anticheat have been wildly overstated, Riot is engaging in the same to spread silly FUD regarding cheats.
I think on Windows, such actions lead to an overlay that ask for authorization and can't be auto-clicked ? If so, I think having such a prompt when not expected will rise attention from the tech-savy users which may report the culprit binary. A bug in the driver being exploited would lead to the absence of the symptom, potentially increasing the time before a first user notices it.
None of this matters, because all the files you care about live in your homedir anyway. In a desktop environment, the malware can tamper with your .profile to replace e.g. the sudo binary and gain root access without any exploits.
How many things like https://github.com/Luohuayu/evil-mhyprot-cli and https://mobile.twitter.com/TheWack0lian/status/7793978407622... have to happen before you'll believe that there really is a significant amount of risk here?
Besides, Windows LPEs are a dime a dozen anyway.
Besides, Windows LPEs are a dime a dozen anyway.
If you’re concerned about one use affecting the other you’re much better off dual-booting two Windows installations, both using BitLocker. They’d use separate keys and AES-XTS means there’s tamper protection as well. One partition could, at worst, destroy the other.
Bullshit. In real life nobody will hack you with a videogame anticheat kernel driver exploit.
They will hack you with a browser exploit, a ms office exploit, or just because you downloaded a malicious executable and decided to run it.
Have you ever seen a real world example of super common and super insecure AV drivers being exploited for LPE? Probably not, it’s not worth the trouble.
That's just not true - for example, the infamous capcom.sys
That's the whole point, is it not? Anticheat is malicious software burning up CPU cycles and reducing security whether you're cheating or not...
Aimbots have gone analog (src: https://hackaday.com/2022/04/30/aimbot-does-it-in-hardware/)
What can they do next? Demand webcam access with your mouse visible, I guess?
Not to mention that you would have to comb through all this footage to detect cheaters... It is honestly a laughable solution.
The cheater does not even really need to generate fake video like I've described. Aimbots can be as subtle as the cheater wants them to be, offering <5% precision adjustments which won't be visible on a webcam. Not to mention that half of cheating is just information assistance like wallhacks which this doesn't even cover.
It would be possible to solve if the incentives are not that strong to cheat, but the status game associated with multiplayer games takes care of the "sufficiently motivated part".
It would be possible to solve at a small scale (e.g. at a tournament) by manually vetting hardware and manually reviewing footage.
But preventing cheating at scale against motivated attackers is so expensive as to be uneconomical. The devs will probably try to install whatever malware they can get away with in order to demonstrate to their shareholders that they care about it, but I'm guessing even the devs will be relieved when Microsoft just blocks their kernel-level malware because they know the risks it entails.
Can you imagine your child saying “Mom / Dad I need to buy a webcam to play this game”. Alarm bells will be going off immediately.
Financially speaking, every player needs to buy a webcam to play even a free to play game ?
Do you need a camera of a specific quality ? What if the light in your room is off and the object detection can’t work out where your hand is ?
Do you get kicked from the game because the sun went down and you didn’t turn on the light ?
Can’t imagine the compute resources required to pull this off. The skins in the game will probably have to cost 10x more.
This is just what comes to mind after thinking about this for 2 mins.
Users who are not attempting world record attempts or playing tournaments where money or fame is on the line.. in other words.. 99.99% of the user base will have no incentive to bother with webcam hand recording anti-cheat systems.
They will just move onto another less bothersome game that doesn’t require it, and that game will eat the webcam-required always recording game's market share.
For the ones that are sick of having their games ruined by hackers they’ll angle their webcam down at their hands (or use the app on their smartphone) and join the server that supports it.
I can decide to cheat, stick my CC info into a website and download a program in less than 5 minutes. To get hardware I need to provide my shipping info and wait a couple of days. If the hardware is banned, I need to wait a few days before my replacement hardware is there, or with software I just update and restart.
It's not an all or nothing thing, it's a game of cat and mouse. The aim isn't to completely stamp out cheaters at any cost, it's to raise the bar sufficiently high to make it so that enough games aren't destroyed by cheaters.
Except perhaps the first few iterations, the hardware won’t be banned. You’ll just have to load a software update for your DMA hardware.
Security-by-obscurity is a game of cat-and-mouse where the cat is blind and the mouse is invulnerable.
The hardware will become widely available once kernel-level anticheat becomes widely used.
>if the anticheat detects the hardware being used.
The only thing the anticheat will be able to detect is ordinary hardware. My cheating device will capture input from HDMI or PCI, the software sees it as a graphics card or a display. My cheating device lets me inspect memory directly, the motherboard just sees a normal stick of RAM. My cheating device lets me bhop and aimbot- the OS just sees an ordinary USB keyboard and mouse
You're right and my wording was sloppy. Often account bans come with "hardware" bans which are an attempt at stopping this from happening but like any other form of anticheat they're not 100% effective (and nor do they need to be to be worth having).
> The hardware will become widely available once kernel-level anticheat becomes widely used.
Sure, and then the barrier for entry has been raised to buying the correct hardware, having it and keeping it up to date.
> The only thing the anticheat will be able to detect is ordinary hardware.
That's a very bold claim. There's no reason to assume that the hardware will match exactly - I expect that as the cheaters pick devices to spoof the cheat detectors will look for (and find) discrepancies.
It is not impossible to have mechanical actuators pressing keys and moving a mouse, and a webcam watching a real monitor. While that's an awful lot of work compared to just reading data off a bus and simulating a HUD device, consider that some decades ago (when the fight was entirely about API hooking and ReadProcessMemory) DMA snooping was considered merely an unrealistic, theoretical possibility.
how? it can report itself as any pci device
the PCI card doesn't
it can be a regular perfectly functioning NIC with a different ROM chip
Right now, the analog option is out of reach except to those with the right skills. But the hardware isn't that expensive even now, and will only get cheaper. All it takes is someone to commodify it.
What skills? Buying something online, then plugging it in once it shows up on your doorstep?
If you're assuming everyone knows how to wire up motors to a microcontroller and get the software set up and calibrated, that's not accurate. If you want to minimize that to a term besides "skills," that's your prerogative.
All the devices I've seen were hobbyist DIY proof-of-concept hardware. And if we're talking about real hardware assist (a machine that sees a screen and helps human operator with their inputs), it needs a machine vision trained for a specific game/setup and that's also quite an effort.
In the same tune, I genuinely do want to see what Olympic Games could become if anything they consider "cheating" would be allowed - I honestly want to see what humans are actually capable of (though, of course, I won't be happy if people would ruin themselves over merely a silly goal of "winning"). I believe that - unlike most arms races in history (except the Space Race, I guess) - this kind of stuff is going to be actually beneficial for humanity.
I'm not a smart guy, and probably there are some issues that I entirely miss (or maybe even not register as they don't match my beliefs), but that's a honest opinion. And yeah, I'm a sucker for science fiction.
Better to have few cheaters than a million of them running baby’s-first-Python-script that just sends plain old WM_MOUSE.
I think this is an important line. Regardless of how people feel about anti-cheating efforts, I don't believe many people realize how much access games already have to their system to the point where it's kind of a miracle there aren't more malicious games out in the wild.
Discord currently has this problem[0] where people send DMs stating 'will you playtest my game' and that exe just steals the user's stored Discord login token and uses it to proliferate the scam to more people, and/or uses the token to buy tons of gifted nitro.
0: https://www.reddit.com/r/discordapp/comments/s1f1vs/the_rece...
Unfortunately what you're suggesting is a hacky half measure.
From a servers perspective there is no difference between a client with a shitty connection and a client who is pretending they have a shitty connection to cheat. The reality is that servers trust clients for some cases (and verifies that those things are possible) because it provides a better experience for a large number of players.
> No brittle assumptions about client environment resulting in potential breakages or false bans.
Let's be honest, server side anticheat is no less susceptible to this than client side. If you're banning on heuristics there's going to be false bans at some point, and you are making assumptions about a perfect client environment with this approach.
> No opportunity for the client to reverse engineer or instrument the binary to patch out the cheat detection methods.
Except you can analyse the ban rates based on how "aggressive" your cheat is across all your players and adjust the effectiveness to keep it under that threshold. If we're going to make the claim that cheaters can always adapt to client side cheats, we can make the same claim for server side cheats.
Lag switching is only one kind of cheat that applies mainly to multiplayer FPS games, and as I said, it can be mitigated through statistical analysis. A simple method would be to kick players (but not ban) from a match if they have too many latency spikes. A better method would be to analyze how often a player's latency spikes coincide with their kills, and ban them if there is excessive correlation.
You are right that preventing any and all forms of cheating is impossible, especially where such methods would negatively impact the player experience. But a perfect solution isn't necessary. Issuing bans after the fact is still effective, as long as the cheaters don't make too much progress or otherwise cause too much impact within that time frame.
> Let's be honest, server side anticheat is no less susceptible to this than client side. If you're banning on heuristics there's going to be false bans at some point, and you are making assumptions about a perfect client environment with this approach.
But that tradeoff is entirely under your control. With server side heuristics, you are in a better position to understand how it works and document it so that others on your team understand it as well. You can tweak its parameters and specialize it with assumptions specific to your game mechanics, and minimize false positives to some probability interval. You can identify specific cheating patterns (e.g. perfectly tracking an enemy behind walls long since the enemy is last seen) and tailor your heuristic to detect such cases. You can feed it more sample data to increase its accuracy. You can set up processes to verify ambiguous cases with human moderators in the loop. None of this requires any assumptions about the client environment, it only requires analyzing the player inputs received by the server over the network. Client side heuristics, on the other hand, tend to be based on things that serve as rather poor proxies for cheating. Running the game in a virtual machine? Banned. Running the client in WINE on Linux? Banned. Driver signature enforcement disabled? Flagged. User running AutoHotKey or WinDbg or Ghidra? Flagged. New Windows update that breaks some internal NT kernel ABI that my anti-cheat rootkit was relying on? Uh oh. These detection methods are better than nothing, but heavy reliance on them has made it easy for cheaters to circumvent anti-cheats while still causing issues for legitimate players whose setup might deviate slightly from the norm.
> Except you can analyse the ban rates based on how "aggressive" your cheat is across all your players and adjust the effectiveness to keep it under that threshold. If we're going to make the claim that cheaters can always adapt to client side cheats, we can make the same claim for server side cheats.
While true, this sort of signal carries much less information than what you can gain from reverse engineering client side cheat detection. You can make it more difficult by issuing ban waves at fixed intervals, and slightly varying the thresholds by some small random amount each time. Larger ban wave intervals mean that it takes longer for cheaters to infer the behavior of your server side anti-cheat, at the cost of taking longer to ban cheaters. But again, that tradeoff is under your control.
> Lag switching is only one kind of cheat that applies mainly to multiplayer FPS games, and as I said, it can be mitigated through statistical analysis <...>
These methods are already in use with client side cheat detection. The thing about latency spikes is that there are many things that cause them. To use your example of checking when spikes appear near a kill in an FPs, presumably a kill is associated with a spike in traffic (multiple users shooting, extra movement, etc). So it's far more likely that you see spikes at the point of extra network traffic. Lag spikes wee also only one example.
> With server side heuristics, you are in a better position to understand how it works and document it so that others on your team understand it as well
You have control over all of these things with client side heuristics and cheat detection too don't forget.
> Running the game in a virtual machine? Banned. Running the client in WINE on Linux? Banned. Driver signature enforcement disabled? Flagged. User running AutoHotKey or WinDbg or Ghidra? Flagged. New Windows update that breaks some internal NT kernel ABI that my anti-cheat rootkit was relying on?
Firstly, the NT interface is probably the most stable of any software im aware of. I don't personally keep up with kernel breakages but my understanding of them is they're incredibly incredibly rare. They're also very well documented and published on a mostly expected cadence. If an anticheat isn't being kept up to date, it's ineffective, whether or not that's in relation to it's heuristics or its support for OS features. Secondly, there's a reason all of those things are suspicious. (And as an aside many games don't actually ban you for running them, they pop up and tell you to turn them off before killing the game . They _do_ ban if you bypass that check though).
> causing issues for legitimate players whose setup might deviate slightly from the norm.
Having ghidra or windgb running, or running via wine isn't "slightly" out of the norm, it's a statistical anomaly that would be flagged as "massive outlier" if heuristics were applied. Also, why is it ok for players whose software setup deviates from the norm, but not ok for players with outlying network setups?
> You can make it more difficult by issuing ban waves at fixed intervals, and slightly varying the thresholds by some small random amount each time.
So exactly the same methods in use right now?
So (2020)?
Also kinda funny a Unix-y element is referenced (/dev/null) whereas the target is only Windows.
In one of my earlier roles, I was responsible for a system used to filter internet access for about a million school students. The students were absolutely easily able to bypass our filtering in a bunch of ways we could not address, as we had no control over the client devices.
Being a team of professionals in a situation where we were constantly being defeated by a bunch of kids felt humiliating, even as we acknowledged the uneven battleground we were fighting on.
I suspect a similar feeling was behind this blog post. Why else say things like "as much as we might like the idea of an ever-escalating appsec war with teenagers"? This comes off as bitter and insincere to me. As though they're trying to put down their adversary while simultaneously acknowledging they're losing the battle and need to deploy the nuclear option.
Edit: not that "teenager" is necessarily a put down. If there's one thing I learned from that job, it's that teenagers are incredibly resourceful.
Separating out the requirement to run games, from the general-purpose computing requirements, opens up more options. It also pushes fewer people towards buying into Windows way of life for everything desktop/laptop.
Ironic that the post title indicates Linux-awareness but the post content breaks any chance of playing Riot's games on a Linux computer.
I'm no expert on anti-cheat but other popular games (e.g. Apex Legends) run without BSoD and as far as I can see don't have serious issues with cheating.
I don't think this is an issue of technical necessity so much as an issue of there being very few Linux gamers and even fewer using something like VFIO to run games rather than dual-booting.
And IIRC Vanguard is purposefully strict.
It doesn't work.
You just chase the cheats higher and higher up the stack and once they're in the hardware, you're boned. And they're already in the hardware. Between direct memory access and actually external AI devices, people can cheat.
So either audit client actions to make sure they only do what they can do (via peers and server) or do the rendering server-side to stop information leaks. Anything else is dishonest and a waste of everyone's time and safety.
Apple would never approve such a mechanism, for sure.
Apple do allow this through kernel extensions, but its very much opt in from users.
[0] https://docs.microsoft.com/en-us/windows-hardware/drivers/de...
For Apple, kexts have been deprecated for a while, with more modern APIs available for ensuring privacy and security in device drivers[1].
Edit: good to know about MS, I didn't actually know that!
Given that it’s one of the biggest online PvP games around, I don’t think you or Riot are really making a strong case here.
A 3D game like Valorant or Call of Duty is much more fast-paced and also introduces a third dimension. This means that transferring the visible game state to the player every frame is much more difficult, both for the server to keep track of, and for the network bandwidth available to the players. This means that in 3D games, there is often client-side data that the user is not supposed to see (such as the exact position of an enemy who has ducked behind a wall, but the server hasn't stopped sending you position data for yet). This poses a huge advantage to whoever can get access to that data and display it somehow. These are called cheats... And they can run in kernel space. This is why they need their own kernel rootkit to detect them.
This article seems to be a bit unclear, but it seems like their point is to justify kernel-mode anti-cheat in broad strokes. I don't think they're just talking about League here. Adding anti-cheat to League is probably not a priority, for reasons I've outlined above.
Compared to old school FPS like COD and CSGO, I'll throw out Overwatch as a good example of a game that de-emphasizes the relative importance of knowing an enemy's position by dramatically raising TTK and placing importance on team coordination, mechanics, and character selection. A cheating sniper in OW can easily get shut down by the coordinated actions of two enemy tank players. Designing the game in a way that limits the ability of a single wall-hacking sniper to ruin the experience is IMO much more effective than getting into a kernel-level AC arms race. Valorant still has cheats available for it, after all.
This is not just a regular customer or user relationship between the user and the developer. This is something else, some kind of controlling behavior that we need to get rid of.
You can't force someone to stop doing something as long as they do it on their own computer. You have to choose; either people use your computer with your rules or they use their own computer with their rules.
If players want to cheat, that's the player's problem, not the developer's problem.
It bothers you and (relatively) few others that they need to run a kernel driver to prevent cheats, but it bothers countless players when a game is plagued with cheaters, and yes, there’s some prevention done by anti-cheats. Call of Duty: Warzone has/had a notorious cheating problem and absolutely no anti-cheat system.
They can and they do, but there is too much of this behavior that companies require too much access and control of people's computers. My computer is my private thing. It's like my home. No company requires to come home to me when I want to do something; they send mail. I want more things to work like the web: everyone has 100% control of their computer and web browser and they can connect to web servers and those web servers can have whatever rules they want but they don't try to get into people's computers.
For example, BattlEye started out as 3rd party anti-cheat for Battlefield Vietnam because the players wanted better anti-cheat. Similarly Face-IT and ESEA run their own anti-cheats that are opt-in and not part of the developer's game.
Otherwise if you want to play at a bigger scale, I don't know how you would do that. Maybe that's just the lesson you have to learn, that random people on the internet can't be trusted.
Why is your right to disrupt a service for other people more important than their right to enjoy that service?