2011 IEEE 22nd International Symposium on Software Reliability Engineering 2011
DOI: 10.1109/issre.2011.15
|View full text |Cite
|
Sign up to set email alerts
|

Diversity for Security: A Study with Off-the-Shelf AntiVirus Engines

Abstract: We have previously reported [1] the results of an exploratory analysis of the potential gains in detection capability from using diverse AntiVirus products. The analysis was based on 1599 malware samples collected from a distributed honeypot deployment over a period of 178 days. The malware samples were sent to the signature engines of 32 different AntiVirus products hosted by the VirusTotal service. The analysis suggested significant gains in detection capability from using more than one AntiVirus product in … Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
5

Citation Types

2
43
1

Year Published

2013
2013
2019
2019

Publication Types

Select...
3
2

Relationship

2
3

Authors

Journals

citations
Cited by 27 publications
(46 citation statements)
references
References 7 publications
2
43
1
Order By: Relevance
“…And just as experimentation in the natural sciences is supported by laboratories, experimentation for a science of cybersecurity will require test beds where controlled experiments can be run." In this paper we present results of an empirical study about possible benefits of diversity with currently spreading malware and compare our findings with those reported in [6][7][8]. The main aim of our study is to verify the extent to which the findings previously reported are relevant with more recent malware.…”
Section: Introductionmentioning
confidence: 61%
See 4 more Smart Citations
“…And just as experimentation in the natural sciences is supported by laboratories, experimentation for a science of cybersecurity will require test beds where controlled experiments can be run." In this paper we present results of an empirical study about possible benefits of diversity with currently spreading malware and compare our findings with those reported in [6][7][8]. The main aim of our study is to verify the extent to which the findings previously reported are relevant with more recent malware.…”
Section: Introductionmentioning
confidence: 61%
“…The results presented in [6][7][8] are intriguing. However, they concern a specific snapshot in the detection capabilities of AVs against malware threats prevalent in that time period: 1599 malware samples collected from a distributed honeypot deployment over a period of 178 days from February to August 2008.…”
Section: Introductionmentioning
confidence: 90%
See 3 more Smart Citations