AV-Meter: An Evaluation of Antivirus Scans and Labels
Omar Alrawi (Qatar Computing Research Institute) Joint with Aziz Mohaisen (VeriSign Labs)
AV-Meter: An Evaluation of Antivirus Scans and Labels Omar Alrawi - - PowerPoint PPT Presentation
AV-Meter: An Evaluation of Antivirus Scans and Labels Omar Alrawi (Qatar Computing Research Institute) Joint with Aziz Mohaisen (VeriSign Labs) Overview Introduction to problem Evaluation metrics Dataset gathering and use
AV-Meter: An Evaluation of Antivirus Scans and Labels
Omar Alrawi (Qatar Computing Research Institute) Joint with Aziz Mohaisen (VeriSign Labs)
2
Overview
4
Example of labels
5
Applications
classification)
6
Approach
7
Metrics (4Cs)
8
Completeness (detection rate)
engine
Malware ¡Set ¡ Detected ¡Set ¡
9
Correctness
normalized by the set size
Malware ¡Set ¡ Detected ¡Set ¡ Correct ¡Label ¡Set ¡
10
Consistency
S’^S’’
11
Coverage
complete set of malware
¡ ¡ ¡ ¡ ¡ Malware ¡Set ¡
AV1 ¡ AV2 ¡ AV3 ¡ AV4 ¡ AV6 ¡ AV5 ¡
12
Data
JKDDos, Ddoser, Darkness, Avzhan
13
Data Vetting
cosmu, etc.)
15
Experiment - Completeness
zeus zaccess lurid n0ise
jkddos dnscalc ddoser darkness bfox avzhan 10 20 30 40 Number of scanners
16
Experiment - Completeness
eSafe NANO Malwarebytes Agnitum MicroWorld NOD32 VirusBuster Antiy.AVL Kingsoft Rising ClamAV TotalDefense SAntiSpyware ViRobot CAT.QuickHeal PCTools F.Prot Commtouch TheHacker ESET.NOD32 Jiangmin VBA32 nProtect Symantec AhnLab.V3 TrendMicro K7AntiVirus Emsisoft TrendMicro.1 Comodo Sophos Fortinet DrWeb Norman Panda VIPRE Microsoft Avast McAfee.GWE AVG Ikarus F.Secure AntiVir McAfee BitDefender Kaspersky GData 0.0 0.2 0.4 0.6 0.8 1.0 Completeness
17
Experiment - Completeness
median of 69 labels
18
Experiment - Correctness
completeness close to 98%
19
Experiment - Correctness
Correctness 0.0 0.2 0.4 0.6 0.8 1.0 eTrust.Vet eSafe NANO Malwarebytes Agnitum MicroWorld NOD32 VirusBuster Antiy.AVL Kingsoft Rising ClamAV TotalDefense SA.Spyware ViRobot CAT.QuickHeal PCTools F.Prot Commtouch TheHacker ESET.NOD32 Jiangmin VBA32 nProtect Symantec AhnLab.V3 TrendMicro K7AntiVirus Emsisoft TrendMicro.HC Comodo Sophos Fortinet DrWeb Norman Panda VIPRE Microsoft Avast McAfee.GWE AVG Ikarus F.Secure AntiVir McAfee BitDefender Kaspersky GData Correctness 0.0 0.2 0.4 0.6 0.8 1.0
20 1 2 3 4 5 6 7 8 9 11 13 15 17 19 21 23 25 27 29 31 33 35 37 39 41 43 45 47 0.0 0.2 0.4 0.6 0.8 1.0 Antivirus Scanner Consistency
Experiment – Consistency
21
Experiment - Coverage
engines) depending on family
with all 48 engines)
correctness is 97.6% 0.7 0.75 0.8 0.85 0.9 0.95 1 5 10 15 20 25 Coverage Number of Antivirus Scanners Completeness - Zeus Correctness - Zeus Completeness - JKDDoS Correctness - JKDDoS
22
Implications
problematic at best;
cause long-lasting harm.
23
Conclusion
incompleteness of labels/detection
Omar Alrawi
+974 4544 2955