The Experts below are selected from a list of 2064 Experts worldwide ranked by ideXlab platform

Yutzu Lin - One of the best experts on this subject based on the ideXlab platform.

  • the magnitude of switching costs for corporate Antivirus Software switching decision
    Pacific Asia Conference on Information Systems, 2007
    Co-Authors: Cheng Yu Hou, Ching Chin Chern, Yutzu Lin
    Abstract:

    Today’s businesses environment is forcing companies to become increasingly more efficient in applying Internet technology to conduct transactions. AS the possibility of infection by computer virus is much greater now than ever before, businesses search for appropriate corporate Antivirus Software to safeguard their computer systems. This paper considers corporate Antivirus Software switching as one of the major security selection problem and proposes possible avenues for Software switching decision and management. In conceptual model, we draw upon switching costs where transaction costs, learning costs, and artificial costs were examined as main costs for Software switching decision. Our findings shown only two out of three types of switching costs have influence over corporate Antivirus Software switching decisions. Despite the existence of switching costs, businesses continue to repeat Software switching because the perceived risks of security threats are much greater than the switching cost itself. Furthermore, we examine various approaches to the cost of switching and then propose an index map to evaluate switching decision. Five sets of propositions are advanced to help guide this research.

Sencun Zhu - One of the best experts on this subject based on the ideXlab platform.

  • SecureComm (2) - Uncovering the Dilemmas on Antivirus Software Design in Modern Mobile Platforms
    Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2015
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Sencun Zhu
    Abstract:

    With the rapid increase in Android device popularity, a new evolving arms-race is happening between the malware writers and Antivirus Detectors (AVDs) on the popular mobile system. In its latest comparison of AVDs, independent test lab AV-TEST reported that AVDs have around 95 % malware recognition rate. However, as mobile systems are specially designed, we consider that the power of AVDs’ should also be evaluated based on their runtime malware detection capabilities. In this work, we performed a comprehensive study on ten popular Android AVDs to evaluate the effectiveness of their scanning operations. During our analysis, we identified the design dilemmas related to two types of malware scanning operations, namely local malware scan and cloud-based malware scan. Our work opens a new research direction in designing more effective and efficient malware scan mechanisms for current Antivirus Software on mobile devices.

  • towards discovering and understanding unexpected hazards in tailoring Antivirus Software for android
    Computer and Communications Security, 2015
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Chuangang Ren, Sencun Zhu
    Abstract:

    In its latest comparison of Android Virus Detectors (AVDs), the independent lab AV-TEST reports that they have around 95% malware detection rate. This only indicates that current AVDs on Android have good malware signature databases. When the AVDs are deployed on the fast-evolving mobile system, their effectiveness should also be measured on their runtime behavior. Therefore, we perform a comprehensive analysis on the design of top 30 AVDs tailored for Android. Our new understanding of the AVDs' design leads us to discover the hazards in adopting AVD solutions for Android, including hazards in malware scan (malScan) mechanisms and the engine update (engineUpdate). First, the malScan mechanisms of all the analyzed AVDs lack comprehensive and continuous scan coverage. To measure the seriousness of the identified hazards, we implement targeted evasions at certain time (e.g., end of the scan) and locations (certain folders) and find that the evasions can work even under the assumption that the AVDs are equipped with "complete" virus definition files. Second, we discover that, during the engineUpdate, the Android system surprisingly nullifies all types of protections of the AVDs and renders the system for a period of high risk. We confirmed the presence of this vulnerable program logic in all versions of Google Android source code and other vendor customized system images. Since AVDs have about 650-1070 million downloads on the Google store, we immediately reported these hazards to AVD vendors across 16 countries. Google also confirmed our discovered hazard in the engineUpdate procedure, so feature enhancements might be included in later versions. Our research sheds the light on the importance of taking the secure and preventive design strategies for AVD or other mission critical apps for fast-evolving mobile-systems.

  • uncovering the dilemmas on Antivirus Software design in modern mobile platforms
    Security and Privacy in Communication Networks, 2014
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Sencun Zhu
    Abstract:

    With the rapid increase in Android device popularity, a new evolving arms-race is happening between the malware writers and Antivirus Detectors (AVDs) on the popular mobile system. In its latest comparison of AVDs, independent test lab AV-TEST reported that AVDs have around 95 % malware recognition rate. However, as mobile systems are specially designed, we consider that the power of AVDs’ should also be evaluated based on their runtime malware detection capabilities. In this work, we performed a comprehensive study on ten popular Android AVDs to evaluate the effectiveness of their scanning operations. During our analysis, we identified the design dilemmas related to two types of malware scanning operations, namely local malware scan and cloud-based malware scan. Our work opens a new research direction in designing more effective and efficient malware scan mechanisms for current Antivirus Software on mobile devices.

Kai Chen - One of the best experts on this subject based on the ideXlab platform.

  • SecureComm (2) - Uncovering the Dilemmas on Antivirus Software Design in Modern Mobile Platforms
    Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2015
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Sencun Zhu
    Abstract:

    With the rapid increase in Android device popularity, a new evolving arms-race is happening between the malware writers and Antivirus Detectors (AVDs) on the popular mobile system. In its latest comparison of AVDs, independent test lab AV-TEST reported that AVDs have around 95 % malware recognition rate. However, as mobile systems are specially designed, we consider that the power of AVDs’ should also be evaluated based on their runtime malware detection capabilities. In this work, we performed a comprehensive study on ten popular Android AVDs to evaluate the effectiveness of their scanning operations. During our analysis, we identified the design dilemmas related to two types of malware scanning operations, namely local malware scan and cloud-based malware scan. Our work opens a new research direction in designing more effective and efficient malware scan mechanisms for current Antivirus Software on mobile devices.

  • towards discovering and understanding unexpected hazards in tailoring Antivirus Software for android
    Computer and Communications Security, 2015
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Chuangang Ren, Sencun Zhu
    Abstract:

    In its latest comparison of Android Virus Detectors (AVDs), the independent lab AV-TEST reports that they have around 95% malware detection rate. This only indicates that current AVDs on Android have good malware signature databases. When the AVDs are deployed on the fast-evolving mobile system, their effectiveness should also be measured on their runtime behavior. Therefore, we perform a comprehensive analysis on the design of top 30 AVDs tailored for Android. Our new understanding of the AVDs' design leads us to discover the hazards in adopting AVD solutions for Android, including hazards in malware scan (malScan) mechanisms and the engine update (engineUpdate). First, the malScan mechanisms of all the analyzed AVDs lack comprehensive and continuous scan coverage. To measure the seriousness of the identified hazards, we implement targeted evasions at certain time (e.g., end of the scan) and locations (certain folders) and find that the evasions can work even under the assumption that the AVDs are equipped with "complete" virus definition files. Second, we discover that, during the engineUpdate, the Android system surprisingly nullifies all types of protections of the AVDs and renders the system for a period of high risk. We confirmed the presence of this vulnerable program logic in all versions of Google Android source code and other vendor customized system images. Since AVDs have about 650-1070 million downloads on the Google store, we immediately reported these hazards to AVD vendors across 16 countries. Google also confirmed our discovered hazard in the engineUpdate procedure, so feature enhancements might be included in later versions. Our research sheds the light on the importance of taking the secure and preventive design strategies for AVD or other mission critical apps for fast-evolving mobile-systems.

  • uncovering the dilemmas on Antivirus Software design in modern mobile platforms
    Security and Privacy in Communication Networks, 2014
    Co-Authors: Heqing Huang, Kai Chen, Peng Liu, Sencun Zhu
    Abstract:

    With the rapid increase in Android device popularity, a new evolving arms-race is happening between the malware writers and Antivirus Detectors (AVDs) on the popular mobile system. In its latest comparison of AVDs, independent test lab AV-TEST reported that AVDs have around 95 % malware recognition rate. However, as mobile systems are specially designed, we consider that the power of AVDs’ should also be evaluated based on their runtime malware detection capabilities. In this work, we performed a comprehensive study on ten popular Android AVDs to evaluate the effectiveness of their scanning operations. During our analysis, we identified the design dilemmas related to two types of malware scanning operations, namely local malware scan and cloud-based malware scan. Our work opens a new research direction in designing more effective and efficient malware scan mechanisms for current Antivirus Software on mobile devices.

  • SERE - Vulnerability-Based Backdoors: Threats from Two-step Trojans
    2013 IEEE 7th International Conference on Software Security and Reliability, 2013
    Co-Authors: Kai Chen, Yingjun Zhang, Yifeng Lian
    Abstract:

    Attackers like to install trojans in a target system to control it. However, it becomes more and more difficult to deceive a user into installing such trojans. One reason is that Antivirus Software uses more strict policies on the first run of unknown Software. The other reason is that users also become more cautious. Some attackers try to find system vulnerabilities to evade the Antivirus Software and users. But it is not easy to find suitable vulnerabilities because they are usually patched in a short time. In this paper, we present a new type of threat called vulnerability-based backdoor (VBB). It is a two-step trojan. In the first step, attackers deceive users into installing an application. This application is transformed from the original one such as “Adobe PDF Reader” by only creating one or more vulnerabilities in it. It runs as a normal one without any malicious code. So it can escape the detection of Antivirus Software and users. In the second step, attackers can make use of the vulnerability and control the target system just as they use a pre-existing vulnerability. We present a method to automatically create a VBB in several minutes. In this process, no source code is needed. VBB is stable enough to reside in a system for a long time since it does not conflict with operating systems, Antivirus Software, other backdoors or even other VBBs. We also show how to prevent VBBs.

Li Qian-lu - One of the best experts on this subject based on the ideXlab platform.

  • One Application for the Principle of Biological Immune Computer Virus Detection Methods
    Computers & Security, 2011
    Co-Authors: Li Qian-lu
    Abstract:

    described in detail the characteristics of computer viruses and detection methods,and principles and methods of biological immune.Draw on artificial immune principle.Draw on artificial immune principles,the design of a new computer virus detection method compared to traditional Antivirus Software,an increase of virus defense intelligence,through a preliminary experimental test of the ability of the virus detection method,detection accuracy and proactive intelligence to detect the virus,the results show the adaptability of this method is efficient,self-learning and robustness,and efficient protection from unknown viruses.

Cheng Yu Hou - One of the best experts on this subject based on the ideXlab platform.

  • the magnitude of switching costs for corporate Antivirus Software switching decision
    Pacific Asia Conference on Information Systems, 2007
    Co-Authors: Cheng Yu Hou, Ching Chin Chern, Yutzu Lin
    Abstract:

    Today’s businesses environment is forcing companies to become increasingly more efficient in applying Internet technology to conduct transactions. AS the possibility of infection by computer virus is much greater now than ever before, businesses search for appropriate corporate Antivirus Software to safeguard their computer systems. This paper considers corporate Antivirus Software switching as one of the major security selection problem and proposes possible avenues for Software switching decision and management. In conceptual model, we draw upon switching costs where transaction costs, learning costs, and artificial costs were examined as main costs for Software switching decision. Our findings shown only two out of three types of switching costs have influence over corporate Antivirus Software switching decisions. Despite the existence of switching costs, businesses continue to repeat Software switching because the perceived risks of security threats are much greater than the switching cost itself. Furthermore, we examine various approaches to the cost of switching and then propose an index map to evaluate switching decision. Five sets of propositions are advanced to help guide this research.