hh.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Into the Gates of Troy: A Comparative Study of Antivirus Solutions for the Detection of Trojan Horse Malware.
Halmstad University, School of Information Technology.
2024 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In the continuously evolving field of malware investigation, a Trojan horse, which appears as innocent software from the user's perspective, represents a significant threat and challenge for antivirus solutions because of their deceptive nature and the various malicious functionalities they provide. This study will compare the effectiveness of three free antiviruses for Linux systems (DrWeb, ClamAV, ESET NOD32) against a dataset of 1919 Trojan malware samples. The evaluation will assess their detection capabilities, resource usage, and the core functionalities they offer. The results revealed a trade-off between these three aspects: DrWeb achieved the highest detection rate (93.43%) but consumed the most resources and provided the most comprehensive functionalities. While ClamAV balanced detection and resource usage with less functionality, ESET NOD32 prioritised low resource usage but showcased a lower detection rate than the other engines (80.93%). Interestingly, the results showed that the category of Trojan horse malware and the file format analysed can affect the detection capabilities of the evaluated antiviruses. This suggests that there is no “silver bullet” for Linux systems against Trojans, and further research in this area is needed to assess the detection capabilities of antivirus engines thoroughly and propose advanced detection methods for robust protection against Trojans on Linux systems.

Place, publisher, year, edition, pages
2024. , p. 57
Keywords [en]
Malware analysis, Antivirus, Linux, Malware, Static analysis, Dynamic Analysis, Hybrid Analysis, Trojan horse
National Category
Computer Systems
Identifiers
URN: urn:nbn:se:hh:diva-53912OAI: oai:DiVA.org:hh-53912DiVA, id: diva2:1872390
Subject / course
Digital Forensics
Educational program
Master's Programme in Network Forensics, 60 credits
Supervisors
Examiners
Available from: 2024-05-24 Created: 2024-06-18 Last updated: 2025-10-01Bibliographically approved

Open Access in DiVA

fulltext(925 kB)305 downloads
File information
File name FULLTEXT02.pdfFile size 925 kBChecksum SHA-512
3240adbf982f34c34970e3ce96c51e7c8da8501db5efa4fd7c0ea3a81bd4765b4682d2fcc9ed5fc53e97ca80d533f9370d6c26609718a938b8f41de90f9a6015
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Hinne, Tom
By organisation
School of Information Technology
Computer Systems

Search outside of DiVA

GoogleGoogle Scholar
Total: 307 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 980 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf