• DocumentCode
    665555
  • Title

    A study of the relationship between antivirus regressions and label changes

  • Author

    Gashi, Ilir ; Sobesto, Bertrand ; Mason, Stephen ; Stankovic, Vladimir ; Cukier, Michel

  • Author_Institution
    Centre for Software Reliability, City Univ. London, London, UK
  • fYear
    2013
  • fDate
    4-7 Nov. 2013
  • Firstpage
    441
  • Lastpage
    450
  • Abstract
    AntiVirus (AV) products use multiple components to detect malware. A component which is found in virtually all AVs is the signature-based detection engine: this component assigns a particular signature label to a malware that the AV detects. In previous analysis [1-3], we observed cases of regressions in several different AVs: i.e. cases where on a particular date a given AV detects a given malware but on a later date the same AV fails to detect the same malware. We studied this aspect further by analyzing the only externally observable behaviors from these AVs, namely whether AV engines detect a malware and what labels they assign to the detected malware. In this paper we present the results of the analysis about the relationship between the changing of the labels with which AV vendors recognize malware and the AV regressions.
  • Keywords
    invasive software; program diagnostics; regression analysis; antivirus products; antivirus regressions; label changes; malware detection; signature-based detection engine; Databases; Educational institutions; Engines; IP networks; Malware; Testing; antivirus; empirical analysis; intrusion detection; malware; security assessment;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Software Reliability Engineering (ISSRE), 2013 IEEE 24th International Symposium on
  • Conference_Location
    Pasadena, CA
  • Type

    conf

  • DOI
    10.1109/ISSRE.2013.6698897
  • Filename
    6698897