Christian Leka, Christoforos Ntantogian, Stylianos Karagiannis, E. Magkos, Vassilios S. Verykios
{"title":"A Comparative Analysis of VirusTotal and Desktop Antivirus Detection Capabilities","authors":"Christian Leka, Christoforos Ntantogian, Stylianos Karagiannis, E. Magkos, Vassilios S. Verykios","doi":"10.1109/IISA56318.2022.9904382","DOIUrl":null,"url":null,"abstract":"VirusTotal has been widely used and being adopted by researchers mainly for the classification of files as malicious or not. Unfortunately, it is not well understood how reliable the results from the antivirus engines on VirusTotal are, especially compared to their desktop counterparts. In this paper, we shed light on the blackbox testing functionality of VirusTotal by evaluating the detection results of VirusTotal antivirus engines and their equivalent desktop versions. Based on our results, we arrive to the conclusion that there are discrepancies between the engines on VirusTotal and the desktop engines. In general, the malware detection rate of the engines on VirusTotal is lower compared to desktop products. This is mainly attributed to the fact that VirusTotal engines do not take advantage of cloud-based detection deteriorating their performance.","PeriodicalId":217519,"journal":{"name":"2022 13th International Conference on Information, Intelligence, Systems & Applications (IISA)","volume":"297 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2022-07-18","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"6","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2022 13th International Conference on Information, Intelligence, Systems & Applications (IISA)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/IISA56318.2022.9904382","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 6
Abstract
VirusTotal has been widely used and being adopted by researchers mainly for the classification of files as malicious or not. Unfortunately, it is not well understood how reliable the results from the antivirus engines on VirusTotal are, especially compared to their desktop counterparts. In this paper, we shed light on the blackbox testing functionality of VirusTotal by evaluating the detection results of VirusTotal antivirus engines and their equivalent desktop versions. Based on our results, we arrive to the conclusion that there are discrepancies between the engines on VirusTotal and the desktop engines. In general, the malware detection rate of the engines on VirusTotal is lower compared to desktop products. This is mainly attributed to the fact that VirusTotal engines do not take advantage of cloud-based detection deteriorating their performance.