PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
July 1, 2004275 citations

Testing malware detectors

View Full Paper
MCMihai ChristodorescuSJSomesh Jha

Key Points

Key points are not available for this paper at this time.

Abstract

In today's interconnected world, malware, such as worms and viruses, can cause havoc. A malware detector (commonly known as virus scanner) attempts to identify malware. In spite of the importance of malware detectors, there is a dearth of testing techniques for evaluating them. We present a technique based on program obfuscation for generating tests for malware detectors. Our technique is geared towards evaluating the resilience of malware detectors to various obfuscation transformations commonly used by hackers to disguise malware. We also demonstrate that a hacker can leverage a malware detector's weakness in handling obfuscation transformations and can extract the signature used by a detector for a specific malware. We evaluate three widely-used commercial virus scanners using our techniques and discover that the resilience of these scanners to various obfuscations is very poor.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Christodorescu et al. (2004) studied this question.

synapsesocial.com/papers/6a20174676ec520ee9a1a515https://doi.org/10.1145/1007512.1007518
Ask AI
Helpful
Bookmark
Share
View Full Paper

Also Consider

Synapse has enriched 5 closely related papers on similar clinical questions. Consider them for comparative context:

  1. 1Attacking Malicious Code: A Report to the Infosec Research Council2000 · 235 citations
  2. 2Art of Software Testing1979 · 566 citations
  3. 3Adaptive testing1976 · 10 citations
  4. 4On comparisons of random, partition, and proportional partition testing2001 · 68 citations
  5. 5An empirical study of the robustness of Windows NT applications using random testing2000 · 266 citations