Research Article

Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software

Volume: 12 Number: 4 January 7, 2025
EN

Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software

Abstract

In the age of widespread digital integration, the rise in cyber threats is evident. Cyber attackers use malicious software (malware) to compromise data and exploit system resources, employing tactics such as remote control or ransom through data encryption. Despite the common use of antivirus software with signature-based detection, this study reveals its limitations. Using a honeypot trap system on Google Cloud, suspicious files uploaded by attackers were analyzed. Results from evaluating these files with 64 antivirus programs show that relying solely on signature-based methods is insufficient. Only three programs had success rates exceeding 90\%, while the majority had success rates predominantly below 70\%. This underscores the need for diverse detection techniques alongside signature-based methods to enhance cybersecurity. The repository containing collected malicious files and the Python script is available on Github, serving as a valuable research resource for further exploration.

Keywords

References

  1. [1] G. Pitolli, G. Laurenza, L. Aniello, L. Querzoni, and R. Baldoni, “Malfamaware: automatic family identification and malware classification through online clustering,” International Journal of information security, vol. 20, pp. 371–386, 2021.
  2. [2] M. Amal and P. Venkadesh, “Review of cyber attack detection: Honeypot system,” Webology, vol. 19, no. 1, pp. 5497–5514, 2022.
  3. [3] S. COOK, “Malware statistics in 2022: Frequency, impact, cost & more,” Feb 2022. [Online]. Available: https: //www.comparitech.com/antivirus/malware-statistics-facts/
  4. [4] S. S. Chakkaravarthy, D. Sangeetha, and V. Vaidehi, “A survey on malware analysis and mitigation techniques,” Computer Science Review, vol. 32, pp. 1–23, 2019.
  5. [5] N. Pachhala, S. Jothilakshmi, and B. P. Battula, “A comprehensive survey on identification of malware types and malware classification using machine learning techniques,” in 2021 2nd International Conference on Smart Electronics and Communication (ICOSEC). IEEE, 2021, pp. 1207–1214.
  6. [6] C. Rohith and G. Kaur, “A comprehensive study on malware detection and prevention techniques used by anti-virus,” in 2021 2nd International Conference on Intelligent Engineering and Management (ICIEM). IEEE, 2021, pp. 429–434.
  7. [7] K. Oosthoek and C. Doerr, “Cyber threat intelligence: A product without a process?” International Journal of Intelligence and CounterIntelligence, vol. 34, no. 2, pp. 300–315, 2021.
  8. [8] D. Aygor and E. Aktan, “The limitations of signature-based ¨ and dynamic analysis methods in detecting malwares: A case study,” Journal of the Faculty of Engineering and Architecture of Gazi University, vol. 37, no. 1, pp. 305–315, 2022.

Details

Primary Language

English

Subjects

Software Testing, Verification and Validation

Journal Section

Research Article

Early Pub Date

January 13, 2025

Publication Date

January 7, 2025

Submission Date

July 1, 2024

Acceptance Date

November 22, 2024

Published in Issue

Year 2024 Volume: 12 Number: 4

APA
Başer, M., Güven, E. Y., & Aydın, M. A. (2025). Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software. Balkan Journal of Electrical and Computer Engineering, 12(4), 337-348. https://doi.org/10.17694/bajece.1506554
AMA
1.Başer M, Güven EY, Aydın MA. Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software. Balkan Journal of Electrical and Computer Engineering. 2025;12(4):337-348. doi:10.17694/bajece.1506554
Chicago
Başer, Melike, Ebu Yusuf Güven, and Muhammed Ali Aydın. 2025. “Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software”. Balkan Journal of Electrical and Computer Engineering 12 (4): 337-48. https://doi.org/10.17694/bajece.1506554.
EndNote
Başer M, Güven EY, Aydın MA (January 1, 2025) Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software. Balkan Journal of Electrical and Computer Engineering 12 4 337–348.
IEEE
[1]M. Başer, E. Y. Güven, and M. A. Aydın, “Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software”, Balkan Journal of Electrical and Computer Engineering, vol. 12, no. 4, pp. 337–348, Jan. 2025, doi: 10.17694/bajece.1506554.
ISNAD
Başer, Melike - Güven, Ebu Yusuf - Aydın, Muhammed Ali. “Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software”. Balkan Journal of Electrical and Computer Engineering 12/4 (January 1, 2025): 337-348. https://doi.org/10.17694/bajece.1506554.
JAMA
1.Başer M, Güven EY, Aydın MA. Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software. Balkan Journal of Electrical and Computer Engineering. 2025;12:337–348.
MLA
Başer, Melike, et al. “Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software”. Balkan Journal of Electrical and Computer Engineering, vol. 12, no. 4, Jan. 2025, pp. 337-48, doi:10.17694/bajece.1506554.
Vancouver
1.Melike Başer, Ebu Yusuf Güven, Muhammed Ali Aydın. Analysis of Malicious Files Gathering via Honeypot Trap System and Benchmark of Anti-Virus Software. Balkan Journal of Electrical and Computer Engineering. 2025 Jan. 1;12(4):337-48. doi:10.17694/bajece.1506554

All articles published by BAJECE are licensed under the Creative Commons Attribution 4.0 International License. This permits anyone to copy, redistribute, remix, transmit and adapt the work provided the original work and source is appropriately cited.Creative Commons Lisansı