Taxonomy on malware evasion countermeasures techniques
Chandra Sekar Veerappan, Peter K. K. Loh, Zhaohui Tang, Forest Tan · 2018
One of the major threats on the Internet is Malware — malicious software which intends to harm IT infrastructures and systems. In the context of Internet-of-Things (IoT), the public attention has been particularly drawn to the growing number of malware programs targeting IoT devices and related security in the recent years. Increasingly the malware, being polymorphic or metamorphic, changes behavior or remains inactive until a specific environment changes. These behaviors are the malware's detection evasion techniques to avoid detection and capture. Such highly evasive malicious programs are on the rise, resulting in extensive research efforts needed on evasion countermeasures. However, there is still a lack of a comprehensive and useful taxonomy to classify the existing countermeasures. This work fills the gap by presenting a survey on available malware evasion countermeasures from both academia and industry. Our main goal of proposing this taxonomy is, help to build a scalable classification of evasion countermeasures which will support malware analysis and classification as well as to guide the design of future evasion countermeasures.