RESEARCH ABSTRACT

How Effective Are Anti-Virus Toolkits at Preventing Computer Virus Attacks?

The technical literature is filled with examples of the many methods that 
can be used to prevent computer virus attacks.  However, to date, limited 
basic research has been undertaken to quantify just how effective the 
various approaches are.  The typical anti-virus toolkit is composed of 
loosely integrated software components designed to detect and remove 
computer viruses.  These tool-kits traditionally favor a priori methods 
designed to detect known computer viruses, with some products also providing 
a posteriori methods designed to identify the symptoms of a computer virus 
attack, presumably when the a priori methods have failed.  The focus of this 
research is to establish the actual effectiveness of a random sample of 
anti- viral products when applied against a judgmental sample of constructed 
computer viruses that are representative of the current population of 
computer viruses.  Using descriptive statistics, contingency analysis, 
hypothesis testing, and Chi-Square goodness of fit tests -- the research 
will establish the measures of effectiveness for the pooled sample of 
products, determine whether there are actually any statistical differences 
in the effectiveness of today's products, evaluate whether optimizing 
anti-viral product configuration statistically effects product 
effectiveness, and determine whether the availability of virus creation 
toolkits and experimental viruses has a statistical impact on anti-viral 
product effectiveness.  Since military computer systems are by definition 
always subject to attack, and the defense budget is constantly shrinking, 
military planners must be able to evaluate the effectiveness of anti-viral 
toolkits which are very often used as the first line of defense against 
computer virus attacks.  A primary goal is to determine if the a priori 
approach of using digital signatures to identify computer viruses is an 
effective way of preventing computer virus attacks.  A secondary goal is to 
demonstrate whether integrity checking, heuristic methods of identifying 
suspected viral activity, and armoring technology that wraps executable 
files in a shell that detects modifications may hold more promise in 
preventing successful computer virus attacks on IBM-PC compatible computer 
systems.

Authors:      Captain Kevin Ziese and Captain LeRoy Pedone, US Air Force
              Graduate Students, US Air Force Institute of Technology (AFIT)
              A Master's Thesis in Software Systems Management

Advisors:     Major Maurice Riggins, Deputy Director, Comm-Computer Systems,
              Air Force Institute of Technology
              Ms Freida Stohrer, Ph. D., Professor,
              Air Force Institute of Technology

Publication:  November 1993, Defense Technical Information Center (DTIC).

Contact:      Captain Kevin Ziese, US Air Force
              1-513-667-3329 (Voice)
              1-513-667-4554 (FAX/Voice/Data Mail)
              kziese@afit.af.mil (Internet)
              70252, 2704 (CompuServe)

The information presented here is the personal view of the authors and does 
not reflect the official position of the United States Air Force.  This 
notice must be included in any reproductions, in whole or in part, of the 
data presented in this research abstract.

