A Look into 30 Years of Malware Development from a Software Metrics Perspective

A Look into 30 Years of Malware Development from a Software Metrics Perspective
复制标题

从软件指标的角度审视 30 年的恶意软件开发

DOI:
--
复制
发表时间:
2016
期刊:
International Symposium on Recent Advances in Intrusion Detection
影响因子:
--
通讯作者:
Juan Caballero
Juan Caballero
中科院分区:
--
文献类型:
--
作者:
Alejandro Calleja;J. Tapiador;Juan Caballero

文献摘要

被引文献

相似文献

在过去的几十年中,恶意和不需要的软件(恶意软件)的问题在数量和复杂性上激增。恶意软件在当今大多数网络攻击中扮演着关键角色,并已成为地下经济中的一种商品。在这项工作中,我们从软件工程的角度分析了自20世纪80年代初至今恶意软件的演变。我们分析了151个恶意软件样本的源代码,并获得了它们的大小,代码质量和开发成本(努力,时间和人数)的估计措施。我们的研究结果表明,在规模和估计工作量等方面,每十年增加近一个数量级,代码质量指标与常规软件相似。总的来说,这支持了关于恶意软件日益复杂及其生产逐渐成为一个行业的说法。
During the last decades, the problem of malicious and unwanted software (malware) has surged in numbers and sophistication. Malware plays a key role in most of today’s cyber attacks and has consolidated as a commodity in the underground economy. In this work, we analyze the evolution of malware since the early 1980s to date from a software engineering perspective. We analyze the source code of 151 malware samples and obtain measures of their size, code quality, and estimates of the development costs (effort, time, and number of people). Our results suggest an exponential increment of nearly one order of magnitude per decade in aspects such as size and estimated effort, with code quality metrics similar to those of regular software. Overall, this supports otherwise confirmed claims about the increasing complexity of malware and its production progressively becoming an industry.