Skip to content

Computer Science · Ch 12 — Security Aspects

Methods of Malware Identification used by Antivirus

12.3.1

Methods of Malware Identification used by Antivirus

Antivirus software does not rely on a single trick to catch malware. Different threats behave differently, so the software uses several complementary methods. Each method answers a different question: What does the malware look like? What does it do? What pattern does it follow? Is it active right now? The five methods below cover these angles.

Signature-based detection

This is the oldest and most direct approach. The antivirus works with a signature database called the Virus Definition File (VDF). A virus signature is a consecutive sequence of bytes that is commonly found in a certain malware sample — think of it as a unique fingerprint embedded inside the malicious code. The VDF stores these signatures and is updated continuously on a real-time basis.

Because the database must stay current, regular updates of the antivirus software are a must. An outdated VDF is as good as having no antivirus software installed at all — new malware will infect the system without being detected. The signature is contained within the malware or the infected file, not in unaffected files, which is what makes it a reliable identifier.

This method has a clear weakness: it fails against malware that can change its signature (called polymorphic malware) and against malware that has some portion of its code encrypted. If the bytes keep shifting, the fixed signature no longer matches.

Sandbox detection

Here, a new application or file is executed inside a virtual environment — the sandbox — and its behavioural fingerprint is observed for signs of malware. The sandbox is a controlled, isolated space that mimics a real system without actually being one.

Depending on the behaviour observed, the antivirus engine decides whether the file is a potential threat and proceeds accordingly. If the file tries to delete files, modify system settings, or connect to suspicious addresses, the engine flags it.

This method is a little slow because the file must actually run and be watched. But it is very safe, since the unknown application is never given access to the actual resources of the system. Even if the file is malicious, it can only cause damage inside the sandbox.

Data mining techniques

This method employs various data mining and machine learning techniques to classify the behaviour of a file as either benign or malicious. Instead of looking for a fixed signature, the software learns from large datasets of known good and known bad files. Over time, the model recognises patterns in behaviour that separate a harmless file from a harmful one.

This is a statistical approach — the antivirus builds a profile of what malicious behaviour looks like and then compares new files against that profile.

Heuristics

Often, a malware infection follows a certain pattern. In this method, the source code of a suspected program is compared to viruses that are already known and stored in the heuristic database. If the majority of the source code matches any code in that database, the code is flagged as a possible threat.

Notice the difference from signature detection: heuristics does not demand an exact byte-for-byte match. It looks for similarity — a large overlap with known malicious code is enough to raise suspicion. This helps catch new variants of old malware, even if the exact signature has never been seen before.

Real-time protection

Some malware remains dormant or gets activated only after some time. Such malware needs to be checked on a real-time basis. In this technique, the anti-malware software keeps running in the background and observes the behaviour of an application or file for any suspicious activity while it is being executed — that is, when it resides in the active (main) memory of the computer system. …

(A)

Signature-based detection

Signature-based detection works like a digital fingerprint scanner for malware. The system keeps a database of known virus signatures — unique byte patterns or strings that appear in malicious files — and scans incoming data against this list. When a match is found, the antivirus flags the file as infected.

The NCERT text demonstrates this with a simple Python example that checks a file for a known virus signature:

# Signature-based detection example
signature = "virus_signature_123"
with open("sample.txt", "r") as file:
    content = file.read()
    if signature in content:
        print("Virus detected!")
    else:
        print("File is clean.")
``` …
(B)

Sandbox detection

Sandbox detection is a technique used to identify whether a program is running inside a sandboxed environment, which is often used by security researchers to safely analyze malware. The NCERT textbook explains this by demonstrating how a program can check for the presence of a sandbox by attempting to execute a command that would typically fail or behave differently in a restricted environment. The specific example given uses Python's os module to run a system command and observe the output, as shown below:

import os
os.system('dir')
``` …
(C)

Data mining techniques

Data mining is the process of discovering hidden patterns and relationships in large datasets, and in this section you’ll see how SQL and Python can be used to pull out useful information from a database. The textbook introduces two main techniques: association rules (finding items that frequently appear together) and classification (grouping data into predefined categories). For association rules, you use the SQL command SELECT with GROUP BY and COUNT to find frequent item sets, and for classification you can use Python’s pandas library to sort and filter data based on conditions. The worked example in the book uses a simple sales table to show how to count how often pairs of products are bought together, and then how to classify customers into groups like “high” or “low” spenders based on a threshold.

-- Finding frequent item sets (association rules)
SELECT item1, item2, COUNT(*) AS frequency
FROM purchases
GROUP BY item1, item2
HAVING COUNT(*) >= 2;
# Classification using pandas
import pandas as pd
df = pd.read_csv('sales.csv') …
(D)

Heuristics

Heuristics is a problem-solving approach that uses a practical method, not guaranteed to be optimal or perfect, but sufficient for reaching an immediate goal. In the context of security, it refers to a technique used to detect potential threats by examining the behavior or characteristics of a program rather than relying on known signatures. This allows the system to identify new or previously unknown malware by looking for suspicious patterns or actions. The idea is to catch threats t …

(E)

Real-time protection

Real-time protection is the shield that stays awake while you work — it watches every file you open, every program you run, and every download that lands on your system, checking each one against known threat signatures the moment it appears. The textbook walks you through a concrete Python example using the os module to simulate this behaviour: it scans a directory, and for each file, it checks whether the filename contains a suspicious substring like "malware" or "virus". If a match is found, the program prints a warning and removes the file using os.remove(), mimicking how an antivirus would quarantine a threat on the spot.

import os

def scan_directory(path):
    for filename in os.listdir(path):
        if "malware" in filename or "virus" in filename:
            print(f"Threat detected: {filename}")
            os.remove(os.path.join(path, filename))
            print(f"Removed: {filename}")

scan_directory("/path/to/scan")
``` …