An analysis of malware evasion techniques against modern AV engines

dc.contributor.advisorIrwin, Barry
dc.contributor.advisorMotara, Yusuf
dc.contributor.advisorSchoeman, Adam
dc.contributor.authorHaffejee, Jameel
dc.date.accessioned2026-03-05T13:28:02Z
dc.date.issued2015
dc.description.abstractThis research empirically tested the response of antivirus applications to binaries that use virus-like evasion techniques. In order to achieve this, a number of binaries are processed using a number of evasion methods and are then deployed against several antivirus engines. The research also documents the process of setting up an environment for testing antivirus engines, including building the evasion techniques used in the tests. The results of the empirical tests illustrate that an attacker can evade multiple antivirus engines without much effort using well-known evasion techniques. Furthermore, some antivirus engines may respond to the occurrence of an evasion technique instead of the presence of any malicious code. In practical terms, this shows that while antivirus applications are useful for protecting against known threats, their effectiveness against unknown or modified threats is limited.
dc.description.degreeMaster's thesis
dc.description.degreeMSc
dc.format.extent123 pages
dc.format.mimetypeapplication/pdf
dc.identifier.otherhttp://hdl.handle.net/10962/5821
dc.identifier.urihttps://researchrepository.ru.ac.za/handle/123456789/9098
dc.languageEnglish
dc.publisherRhodes University, Faculty of Science, Department of Computer Science
dc.rightsHaffejee, Jameel
dc.subjectUncatalogued
dc.titleAn analysis of malware evasion techniques against modern AV engines
dc.typeAcademic thesis

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
vital_20979+SOURCE1+SOURCE1.1.pdf
Size:
488.58 KB
Format:
Adobe Portable Document Format