Malware

Signature-based detection

Signature-based detection is flagging a file or request because it matches a pattern known from earlier malware: a hash, a string, a byte sequence. It is fast and precise on old threats and blind to new ones.

How it is measured

A detector holds a signature set, such as file hashes, regex on content, or rules like those in ClamAV or YARA, and checks each scanned object against it. Measure it by detection on a known-sample set and by false positives on clean files. The signature database date matters as much as the scanner version.

Check coverage with a harmless test string like EICAR and by seeing how a one-byte change or re-encoding affects the match. An exact hash match breaks with any change; a string or rule can survive small edits.

Worked example

A host scans a shared server and flags 14 files as 'PHP.Shell.WSO'. A client's cleaned copy of the same shell, re-encoded with a base64 layer and a different variable name, passes the scan. The scanner's signature file is from March; it is now October.

A new rule on a stable string inside the decoded shell catches both versions. The first batch of 14 was found because the shell was already catalogued; the re-encoded copy was the attacker's second try.

How it differs

Heuristic detection scores behavior or traits, like many eval calls or odd entropy, and can catch unseen samples at the cost of more false alarms. Signature-based detection only matches what has been catalogued. One finds the known family; the other guesses about the unknown.

Common errors

Trusting a clean scan as a clean site. Letting the signature database go months without an update. Using exact hashes for code that mutates per request. Writing broad strings that flag legitimate libraries. Ignoring files the scanner could not read.

In practice

Update signatures automatically and note the database date in each scan report. Pair signature scans with file-integrity checks against clean core files, because anything not in the catalogue only shows up as a change. Tune new rules against a set of known-good files before enabling them.

See also

Heuristic detection, YARA

Sources

Count this on a real site.

Watch my website