Review of Encrypted Virus: Detection analyses Methods
Harith Ghanim Ayoub, Aamer Tahseen Suhail · 2021
Most of the recent researchers had a great interest in encrypted virus detection. This interest came after the continuous production of encrypted viruses. The machine learning algorithms had been implemented to build an efficient detector. Some of these researches proposed a signature-based method that might not be able to detect recent encrypted viruses. Therefore, other researchers built their methods upon the encrypted virus's behaviour without seeking its signature. The behaviour-based or heuristic-based methods could detect encrypted malicious, including encrypted viruses. The detection methods had analyzed their inputs through either static or dynamic analysis. Some other researches had analyzed their inputs via hybrid analysis. Several monitor applications had been used in several virtual machine types. Most of the researches had been performed in a windows environment, where others in an android environment. An evaluation of these methods had been performed via criteria of comparison to determine the most effective method. The comparison results showed that the mainstream virus divided detection had 100% in windows, and a run-time mobile malware detector had 100% accuracy.