Skip to main content
Log in

Evaluation methodology and theoretical model for antiviral behavioural detection strategies

  • Extended version of WTCV'06
  • Published:
Journal in Computer Virology Aims and scope Submit manuscript

Abstract

Behavioural analysis for detection of malware has recently emerged as a new promising set of antiviral techniques: function-based detection is now considered along with sequence-based detection. Most of the antivirus publishers now claim to use behavioral analysis as a marketing argument. But the real impact of these “new” techniques seems to be mitigated since no real progress in the general antiviral fight has been noticed nowadays. This paper presents an evaluation methodology of the real capabilities of antivirus software with respect to the behavioral analysis. It is shown that contrary to the claims of some publishers, behavioural analysis is still very marginally used and implemented. These techniques are quite always either validated by or dependant on classical form-based detection methods (detection pattern as an example). In this context, we propose a generalised, theoretical detection model which considers at the same time both form-based and function-based detection and give some essential properties this model should exibhit to achieve a real behavioural-based detection.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Similar content being viewed by others

References

  1. Beauchamp, K.G.: Applications of Walsh and Related Functions. In: Microelectronics and Signal Processing Series. Academic Press, ISBN 0-12-084180-0 (1984)

  2. Chakrabarty, K., Hayes, J.P.: Balanced Boolean functions. IEE Proc. Comput. Digit. Tech. 145(1) (1998)

  3. Cohen, F.: Computer viruses. Ph.D. Thesis, University of Southern California, Janvier 1986

  4. http://www.trendmicro.com/vinfo/virusencyclo/defaults.asp? VName=WORM_MYDOOM.A

  5. Filiol, E.: Designs, intersecting families and weight of Boolean functions. In: Proceedings of the 7th IMA Conference on Cryptography and Coding. Lecture Notes in Computer Science vol. 1746. Springer Berlin Heidelberg New York (1999)

  6. Filiol, E.: “Le ver MyDoom”. J. Sécurité Informat. MISC 13 (2004)

  7. Filiol, E.: Malware pattern scanning schemes secure against black-box analysis. J. Comput. Virol. 2(1) (2006)

  8. Filiol, E., Jacob, G., Le Liard, M.: Evaluation methodology of function-based malware detection. In: Proceedings of the First Workshop in Theoretical Computer Virology, Bonfante, G., Marion, J.- Y. (eds.) Nancy, May 2006

  9. Jacob, G., Le Liard, M.: Evaluation des méthodes de détection comportementale des virus. Rapport de projet Mastère SSI, Laboratoire de virologie et de cryptologie et Supélec Bretagne (2006)

  10. Josse, S.: How to measure the effectiveness of an antivirus. J. Comput. Virol. 2(1) (2006)

  11. Menezes, A.J., van Oorschot, P.C., Vanstone, S.A.: Handbook of Applied Cryptography. CRC Press, ISBN 0-8493-8523-7 (1997)

  12. Morin, B.: Intrusion detection vs virology. In: Proceedings of the First Workshop in Theoretical Computer Virology, , G., Marion, J.-Y. (eds.) Nancy, May 2006

  13. Rothaus O.S. (1976) On bent functions. J. Combin. Theory 20, 300–305

    Article  MATH  MathSciNet  Google Scholar 

  14. Sperner E. (1928) Ein Satz über Untermengen einer endlichen Menge. Math. Z. 27, 544–548

    Article  MathSciNet  Google Scholar 

  15. Xiao G.-Z., Massey J.L. (1988) A spectral characterization of correlation-immune combining functions. Trans. Inform. Theory IT-34(3): 569–571

    Article  MATH  MathSciNet  Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Eric Filiol.

Additional information

This paper is the extended version of the paper presented at WTCV’06 (Workshop in Theoretical Computer Virology) in Nancy, France, May 2006.

Rights and permissions

Reprints and permissions

About this article

Cite this article

Filiol, E., Jacob, G. & Liard, M.L. Evaluation methodology and theoretical model for antiviral behavioural detection strategies. J Comput Virol 3, 23–37 (2007). https://doi.org/10.1007/s11416-006-0026-9

Download citation

  • Received:

  • Revised:

  • Accepted:

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1007/s11416-006-0026-9

Keywords

Navigation