Malware stands for MALicious softWARE that aims to compromise digital systems and devices, interrupt services, and leak sensitive information. The antiviruses’ detection capability is largely experimented by companies and organizations.However, such experiments: (i) focus only on the antiviruses’ detection rate, without performing any in-depth analysis, and (ii) often report an almost perfect antiviruses’ detection capability achieved under not clearly documented experiments’ setup. This paper reports on two experiments conducted to evaluate the detection capability of antiviruses, explore the role of defense evasion techniques, and the use of crowd-sourced detection rules.While the first experiment has been conducted installing the antiviruses locally, the second and larger one has been conducted viaVirusTotal, an onlinemulti-antivirus platform. The results show that: (i) a non-trivial percentage of malware samples (up to 26.8%) remained undetected by antiviruses in VirusTotal, sometimes for a long period (e.g., 5%more than 23 days), and most of them are related to potentially critical threats; (ii) groups of AVs demonstrated similar behaviors in terms of malware detection trends, agreement patterns, and overall effectiveness; (iii) few defense evasion techniques result to be frequently incorporated into malware samples for which we observed a high detection delay; (iv) specific defense evasion techniques support malicious tactics; and (v) more than half of malware samples (up to 54%) do not trigger crowd-sourced detection rules in the online platform. Furthermore, we identified a set of lessons learned that can represent future research directions to improve the antiviruses detection capability. The experiments show that antiviruses on VirusTotal can miss or delay malware detection for a long period. Furthermore, we observe that malware samples frequently use specific defense evasion techniques to elude these antivirus engines, and often do not trigger crowd-sourced detection rules.
On the antivirus detection delay and malware defense evasion techniques: a VirusTotal-based evaluation / Marchetto, A.. - In: JOURNAL OF COMPUTER VIROLOGY AND HACKING TECHNIQUES. - ISSN 2263-8733. - 22:83(2026). [10.1007/s11416-026-00663-8]
On the antivirus detection delay and malware defense evasion techniques: a VirusTotal-based evaluation
Alessandro Marchetto
2026-01-01
Abstract
Malware stands for MALicious softWARE that aims to compromise digital systems and devices, interrupt services, and leak sensitive information. The antiviruses’ detection capability is largely experimented by companies and organizations.However, such experiments: (i) focus only on the antiviruses’ detection rate, without performing any in-depth analysis, and (ii) often report an almost perfect antiviruses’ detection capability achieved under not clearly documented experiments’ setup. This paper reports on two experiments conducted to evaluate the detection capability of antiviruses, explore the role of defense evasion techniques, and the use of crowd-sourced detection rules.While the first experiment has been conducted installing the antiviruses locally, the second and larger one has been conducted viaVirusTotal, an onlinemulti-antivirus platform. The results show that: (i) a non-trivial percentage of malware samples (up to 26.8%) remained undetected by antiviruses in VirusTotal, sometimes for a long period (e.g., 5%more than 23 days), and most of them are related to potentially critical threats; (ii) groups of AVs demonstrated similar behaviors in terms of malware detection trends, agreement patterns, and overall effectiveness; (iii) few defense evasion techniques result to be frequently incorporated into malware samples for which we observed a high detection delay; (iv) specific defense evasion techniques support malicious tactics; and (v) more than half of malware samples (up to 54%) do not trigger crowd-sourced detection rules in the online platform. Furthermore, we identified a set of lessons learned that can represent future research directions to improve the antiviruses detection capability. The experiments show that antiviruses on VirusTotal can miss or delay malware detection for a long period. Furthermore, we observe that malware samples frequently use specific defense evasion techniques to elude these antivirus engines, and often do not trigger crowd-sourced detection rules.| File | Dimensione | Formato | |
|---|---|---|---|
|
s11416-026-00663-8.pdf
accesso aperto
Tipologia:
Versione editoriale (Publisher’s layout)
Licenza:
Creative commons
Dimensione
2.96 MB
Formato
Adobe PDF
|
2.96 MB | Adobe PDF | Visualizza/Apri |
I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione



