Malware stands for MALicious softWARE that aims to compromise digital systems and devices, interrupt services, and leak sensitive information. The antiviruses’ detection capability is largely experimented by companies and organizations.However, such experiments: (i) focus only on the antiviruses’ detection rate, without performing any in-depth analysis, and (ii) often report an almost perfect antiviruses’ detection capability achieved under not clearly documented experiments’ setup. This paper reports on two experiments conducted to evaluate the detection capability of antiviruses, explore the role of defense evasion techniques, and the use of crowd-sourced detection rules.While the first experiment has been conducted installing the antiviruses locally, the second and larger one has been conducted viaVirusTotal, an onlinemulti-antivirus platform. The results show that: (i) a non-trivial percentage of malware samples (up to 26.8%) remained undetected by antiviruses in VirusTotal, sometimes for a long period (e.g., 5%more than 23 days), and most of them are related to potentially critical threats; (ii) groups of AVs demonstrated similar behaviors in terms of malware detection trends, agreement patterns, and overall effectiveness; (iii) few defense evasion techniques result to be frequently incorporated into malware samples for which we observed a high detection delay; (iv) specific defense evasion techniques support malicious tactics; and (v) more than half of malware samples (up to 54%) do not trigger crowd-sourced detection rules in the online platform. Furthermore, we identified a set of lessons learned that can represent future research directions to improve the antiviruses detection capability. The experiments show that antiviruses on VirusTotal can miss or delay malware detection for a long period. Furthermore, we observe that malware samples frequently use specific defense evasion techniques to elude these antivirus engines, and often do not trigger crowd-sourced detection rules.

On the antivirus detection delay and malware defense evasion techniques: a VirusTotal-based evaluation / Marchetto, A.. - In: JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES. - ISSN 2263-8733. - 22:83(2026). [10.1007/s11416-026-00663-8]

On the antivirus detection delay and malware defense evasion techniques: a VirusTotal-based evaluation

Alessandro Marchetto
2026-01-01

Abstract

Malware stands for MALicious softWARE that aims to compromise digital systems and devices, interrupt services, and leak sensitive information. The antiviruses’ detection capability is largely experimented by companies and organizations.However, such experiments: (i) focus only on the antiviruses’ detection rate, without performing any in-depth analysis, and (ii) often report an almost perfect antiviruses’ detection capability achieved under not clearly documented experiments’ setup. This paper reports on two experiments conducted to evaluate the detection capability of antiviruses, explore the role of defense evasion techniques, and the use of crowd-sourced detection rules.While the first experiment has been conducted installing the antiviruses locally, the second and larger one has been conducted viaVirusTotal, an onlinemulti-antivirus platform. The results show that: (i) a non-trivial percentage of malware samples (up to 26.8%) remained undetected by antiviruses in VirusTotal, sometimes for a long period (e.g., 5%more than 23 days), and most of them are related to potentially critical threats; (ii) groups of AVs demonstrated similar behaviors in terms of malware detection trends, agreement patterns, and overall effectiveness; (iii) few defense evasion techniques result to be frequently incorporated into malware samples for which we observed a high detection delay; (iv) specific defense evasion techniques support malicious tactics; and (v) more than half of malware samples (up to 54%) do not trigger crowd-sourced detection rules in the online platform. Furthermore, we identified a set of lessons learned that can represent future research directions to improve the antiviruses detection capability. The experiments show that antiviruses on VirusTotal can miss or delay malware detection for a long period. Furthermore, we observe that malware samples frequently use specific defense evasion techniques to elude these antivirus engines, and often do not trigger crowd-sourced detection rules.
2026
83
Marchetto, Alessandro
On the antivirus detection delay and malware defense evasion techniques: a VirusTotal-based evaluation / Marchetto, A.. - In: JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES. - ISSN 2263-8733. - 22:83(2026). [10.1007/s11416-026-00663-8]
File in questo prodotto:
File Dimensione Formato  
s11416-026-00663-8.pdf

accesso aperto

Tipologia: Versione editoriale (Publisher’s layout)
Licenza: Creative commons
Dimensione 2.96 MB
Formato Adobe PDF
2.96 MB Adobe PDF Visualizza/Apri

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11572/500410
Citazioni
  • ???jsp.display-item.citation.pmc??? ND
  • Scopus 0
  • ???jsp.display-item.citation.isi??? ND
  • OpenAlex ND
social impact