hh.sePublikationer
Ändra sökning
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf
Into the Gates of Troy: A Comparative Study of Antivirus Solutions for the Detection of Trojan Horse Malware.
Högskolan i Halmstad, Akademin för informationsteknologi.
2024 (Engelska)Självständigt arbete på avancerad nivå (magisterexamen), 10 poäng / 15 hpStudentuppsats (Examensarbete)
Abstract [en]

In the continuously evolving field of malware investigation, a Trojan horse, which appears as innocent software from the user's perspective, represents a significant threat and challenge for antivirus solutions because of their deceptive nature and the various malicious functionalities they provide. This study will compare the effectiveness of three free antiviruses for Linux systems (DrWeb, ClamAV, ESET NOD32) against a dataset of 1919 Trojan malware samples. The evaluation will assess their detection capabilities, resource usage, and the core functionalities they offer. The results revealed a trade-off between these three aspects: DrWeb achieved the highest detection rate (93.43%) but consumed the most resources and provided the most comprehensive functionalities. While ClamAV balanced detection and resource usage with less functionality, ESET NOD32 prioritised low resource usage but showcased a lower detection rate than the other engines (80.93%). Interestingly, the results showed that the category of Trojan horse malware and the file format analysed can affect the detection capabilities of the evaluated antiviruses. This suggests that there is no “silver bullet” for Linux systems against Trojans, and further research in this area is needed to assess the detection capabilities of antivirus engines thoroughly and propose advanced detection methods for robust protection against Trojans on Linux systems.

Ort, förlag, år, upplaga, sidor
2024. , s. 57
Nyckelord [en]
Malware analysis, Antivirus, Linux, Malware, Static analysis, Dynamic Analysis, Hybrid Analysis, Trojan horse
Nationell ämneskategori
Datorsystem
Identifikatorer
URN: urn:nbn:se:hh:diva-53912OAI: oai:DiVA.org:hh-53912DiVA, id: diva2:1872390
Ämne / kurs
Digital forensik
Utbildningsprogram
Magisterprogram i nätverksforensik
Handledare
Examinatorer
Tillgänglig från: 2024-05-24 Skapad: 2024-06-18 Senast uppdaterad: 2025-10-01Bibliografiskt granskad

Open Access i DiVA

fulltext(925 kB)317 nedladdningar
Filinformation
Filnamn FULLTEXT02.pdfFilstorlek 925 kBChecksumma SHA-512
3240adbf982f34c34970e3ce96c51e7c8da8501db5efa4fd7c0ea3a81bd4765b4682d2fcc9ed5fc53e97ca80d533f9370d6c26609718a938b8f41de90f9a6015
Typ fulltextMimetyp application/pdf

Sök vidare i DiVA

Av författaren/redaktören
Hinne, Tom
Av organisationen
Akademin för informationsteknologi
Datorsystem

Sök vidare utanför DiVA

GoogleGoogle Scholar
Totalt: 319 nedladdningar
Antalet nedladdningar är summan av nedladdningar för alla fulltexter. Det kan inkludera t.ex tidigare versioner som nu inte längre är tillgängliga.

urn-nbn

Altmetricpoäng

urn-nbn
Totalt: 993 träffar
RefereraExporteraLänk till posten
Permanent länk

Direktlänk
Referera
Referensformat
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Annat format
Fler format
Språk
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Annat språk
Fler språk
Utmatningsformat
  • html
  • text
  • asciidoc
  • rtf