Malware
Heuristic detection
Heuristic detection is flagging code by what it does or how it is built, rather than by matching a known name or hash. It can catch something nobody has seen before.
How it is measured
A heuristic engine scores traits: a script that decodes a string and evals it, a hidden iframe, a call to a host registered yesterday, or a PHP file that reads `$_POST` into `system()`. Each trait adds weight, and a total above a threshold raises an alert.
Measure it by hits on a labeled sample set. Run 100 known-bad and 100 known-good files through it and count caught, missed, and wrongly flagged.
Worked example
A scanner reviews a membership site's plugin folder. One file has no known hash and no signature match, but it combines a 6 KB base64 string, `gzinflate`, `eval`, and a write to `.htaccess`. Together they score 9 against an alert threshold of 7.
The file is a dropper from a campaign released the previous week, so no signature existed yet. A separate caching plugin gets a score of 4 for using `eval` once and is left alone.
How it differs
Heuristic detection asks whether the behavior looks bad. Signature-based detection asks whether the file matches a known bad one. Signatures are exact and cheap but blind to new samples. Heuristics reach new samples but raise more false positives. A sandbox goes further by running the code and watching what happens.
Common errors
Setting the threshold once and never revisiting it. Treating a high score as proof. Treating a low score as proof of safety. Using one trait, like `eval`, as a trigger by itself. Skipping the review of what got flagged and cleared.
In practice
Pair heuristics with signatures. When a heuristic flags a file, read it before deleting, and note the verdict. Adjust the threshold using your own cleared list so noise falls over time without opening blind spots.