DocumentCode :
1597977
Title :
Evaluating detection and treatment effectiveness of commercial anti-malware programs
Author :
Morales, Jose Andre ; Sandhu, Ravi ; Xu, Shouhuai
Author_Institution :
Inst. for Cyber Security, Univ. of Texas at San Antonio, San Antonio, TX, USA
fYear :
2010
Firstpage :
31
Lastpage :
38
Abstract :
Commercial anti-malware programs consist of two main components: detection and treatment. Detection accuracy is often used to rank effectiveness of commercial anti-malware programs with less emphasis on the equally important treatment component. Effectiveness measures of commercial anti-malware programs should consider equally detection and treatment. This can be achieved by standardized measurements of both components. This paper presents a novel approach to evaluate the effectiveness of a commercial anti-malware program´s detection and treatment components against malicious objects by partitioning true positives to incorporate detection and treatment. This new measurement is used to evaluate the effectiveness of four commercial anti-malware programs in three tests. The results show that several anti-malware programs produced numerous incorrectly treated or untreated true positives and false negatives leaving many infected objects unresolved and thereby active threats in the system. These results further demonstrate that our approach evaluates the detection and treatment components of commercial anti-malware programs in a more effective and realistic manner than currently accepted measurements which primarily focus on detection accuracy.
Keywords :
invasive software; software performance evaluation; commercial anti malware programs; detection evaluation; treatment evaluation; Equations; Malware; Mathematical model; Software; Testing; Workstations;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Malicious and Unwanted Software (MALWARE), 2010 5th International Conference on
Conference_Location :
Nancy, Lorraine
Print_ISBN :
978-1-4244-9353-1
Type :
conf
DOI :
10.1109/MALWARE.2010.5665797
Filename :
5665797
Link To Document :
بازگشت