首页> 外文会议>Information Security for South Africa Conference >Testing antivirus engines to determine their effectiveness as a security layer
【24h】

Testing antivirus engines to determine their effectiveness as a security layer

机译:测试防病毒发动机以确定其作为安全层的有效性

获取原文

摘要

This research has been undertaken to empirically test the assumption that it is trivial to bypass an antivirus application and to gauge the effectiveness of antivirus engines when faced with a number of known evasion techniques. A known malicious binary was combined with evasion techniques and deployed against several antivirus engines to test their detection ability. The research also documents the process of setting up an environment for testing antivirus engines as well as building the evasion techniques used in the tests. This environment facilitated the empirical testing that was needed to determine if the assumption that antivirus security controls could easily be bypassed. The results of the empirical tests are also presented in this research and demonstrate that it is indeed within reason that an attacker can evade multiple antivirus engines without much effort. As such while an antivirus application is useful for protecting against known threats, it does not work as effectively against unknown threats.
机译:已经开展了本研究以凭经验测试假设绕过防病毒应用,并在面对许多已知的逃避技术时衡量抗病毒发动机的有效性。已知的恶意二进制文件与逃避技术相结合,并针对几种抗病毒发动机部署,以测试其检测能力。该研究还记录了建立测试防病毒发动机的环境的过程,以及建立测试中使用的逃避技术。这种环境促进了确定防病毒安全控制很容易被绕过的假设所需的经验测试。本研究还介绍了实证测试的结果,并证明它确实在理性的情况下,攻击者可以毫不费力地逃避多个防病毒发动机。因此,虽然抗病毒应用对于保护危害的威胁是有用的,但它并不能有效地反对未知威胁。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号