Browse Definitions :
Definition

malware testing

Malware testing is the practice of subjecting malicious programs to software testing tools and antivirus programs designed for legitimate applications. 

Malicious software developers want their products to meet a lot of the same requirements that other software should meet. It's not desirable, for example, for either type of program to crash user computers or applications. 

In the case of regular software, causing crashes indicates that the software is not functional. If malware crashes user systems, on the other hand, the larger concern is that the cause of the crash will be detected, eradicated and reported. Running smoothly without causing problems is generally the ideal for malware as much as it is for any software because anything that causes problems is likely to be investigated.

Brandon Dixon, an independent researcher, reported that two high-profile nation state hacking teams were using Google's VirusTotal website to improve their malware. VirusTotal is a free service that allows any user to submit a program for testing. The site aggregates over three dozen antivirus scanners from Symantec, Kaspersky Lab, F-Secure and others. Dixon had been tracking submissions to the site for some time. 

To test their malware, the hacking teams repeatedly submitted programs to the site attempting to ensure they can evade detection by antivirus software. When a program failed to get through antivirus, they would tweak the code and resubmit until the malware was able to pass undetected. 

This was last updated in September 2014

Continue Reading About malware testing

SearchCompliance

  • information governance

    Information governance is a holistic approach to managing corporate information by implementing processes, roles, controls and ...

  • enterprise document management (EDM)

    Enterprise document management (EDM) is a strategy for overseeing an organization's paper and electronic documents so they can be...

  • risk assessment

    Risk assessment is the identification of hazards that could negatively impact an organization's ability to conduct business.

SearchSecurity

  • honeypot (computing)

    A honeypot is a network-attached system set up as a decoy to lure cyber attackers and detect, deflect and study hacking attempts ...

  • spam trap

    A spam trap is an email address that is used to identify and monitor spam email.

  • cracker

    A cracker is someone who breaks into someone else's computer system, often on a network; bypasses passwords or licenses in ...

SearchHealthIT

SearchDisasterRecovery

  • risk mitigation

    Risk mitigation is a strategy to prepare for and lessen the effects of threats faced by a business.

  • call tree

    A call tree is a layered hierarchical communication model that is used to notify specific individuals of an event and coordinate ...

  • Disaster Recovery as a Service (DRaaS)

    Disaster recovery as a service (DRaaS) is the replication and hosting of physical or virtual servers by a third party to provide ...

SearchStorage

  • cloud testing

    Cloud testing is the process of using the cloud computing resources of a third-party service provider to test software ...

  • storage virtualization

    Storage virtualization is the pooling of physical storage from multiple storage devices into what appears to be a single storage ...

  • erasure coding

    Erasure coding (EC) is a method of data protection in which data is broken into fragments, expanded and encoded with redundant ...

Close