Finding and Solving Contradictions of False Positives in Virus Scanning

نویسنده

  • Umakant Mishra
چکیده

False positives are equally dangerous as false negatives. Ideally the false positive rate should remain 0 or very close to 0. Even a slightest increase in false positive rate is considered as undesirable. Although the specific methods provide very accurate scanning by comparing viruses with their exact signatures, they fail to detect the new and unknown viruses. On the other hand the generic methods can detect even new viruses without using virus signatures. But these methods are more likely to generate false positives. There is a positive correlation between the capability to detect new and unknown viruses and false positive rate. While a traditional approach tries to achieve a right balance between false positives and false negatives a TRIZ approach looks forward to achieve the Ideal Final Result. The Ideal final result is to 'detect and prevent viruses with full certainty. The chances of error should be nil and the method should not raise any false positive or false negative.' The article shows many contradictions relating to false positives and their solutions.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Contradictions in Improving Speed of Virus Scanning

Although everything in computing industry moves faster including the processor, memory speed, memory size, storage space etc. there is no improvement in virus scanning time. Although the processing speed has substantially increased, a typical full scanning is still taking several hours for an average computer. There is a serious need to improve the scanning time. Contradiction is a stage of pro...

متن کامل

Improved Procedure for Screening Expression Libraries for Novel Autoantigens

The standard method for immunoscreening of a cDNA expression library is time-consuming becauseof the production of a large proportion of false positives during the first and second round of screening.This problem is more important when a sensitive chemiluminescence detection system is used. Due tothe high sensitivity of the detection system, there is a need to avoid false posi...

متن کامل

Security Response A False Positive Prevention Framework for Non-Heuristic Anti-Virus Signatures

False positives, the erroneous detection of clean files, have been referred to as the Achilles heel of the anti-virus industry. Some believe the problem false positives represent is growing. This belief is likely underpinned by the growth in anti-virus signatures, due to the exponential growth in malicious code over the past 2 years, and the corresponding impact this invariably has on false pos...

متن کامل

Automatic Extraction of Computer Virus

One way that anti-virus programs identify the presence of a virus in an executable le, a boot record, or memory is by using short identiiers called signatures, which consist of sequences of bytes in the machine code of the virus. A good signature is one that is found in every object infected by the virus, but is unlikely to be found if the virus is not present; i.e. the likelihood of both false...

متن کامل

Early Warnings of Plan Failure, Falso Positives and Envelopes: Experiments and a Model

We analyze a tradeoff between early warnings of plan failures and false positives. In general, a decision rule that provides earlier warnings will also produce more false positives. Slack time envelopes are decision rules that warn of plan failures in our Phoenix system. Until now, they have been constructed according to ad hoc criteria. In this paper we show that good performance under differe...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:
  • CoRR

دوره abs/1306.4652  شماره 

صفحات  -

تاریخ انتشار 2013