Question

What techniques can be applied to detect Polymorphic and Metamorphic viruses?

How difficult is to implement these techniques?

Are these techniques being applied in modern day anti-virus softwares?

Was it helpful?

Solution

I thought most of the virus scanners nowadays use sandbox techniques to check for "bad" behavior. Therefore the polymorphic virusses will also be detected.
of course these detection techniques are also known to virus creators, and can easily be bypassed using a bunch of random, unharmfull, code executions before the actual payload.

OTHER TIPS

It's impossiable to detect all known poly/metamorphic bad-code. White lists verification is the only provable technique. It's not always possiable, especially if your infrastructure/computer has not been maintainedd very well. Which is a good reason why signature, heuristic, emulation based detection is still valuable.

Licensed under: CC-BY-SA with attribution
Not affiliated with StackOverflow
scroll top