Recently, malware has been rapidly evolving in both diversity and distribution channels, becoming increasingly sophisticated. As a result, questions are growing about the real-world effectiveness of traditional defense mechanisms such as antivirus solutions. To address this, our research team conducts long-term, controlled, and repeatable experiments rather than one-time evaluations to quantitatively analyze antivirus performance. In this series of posts, we systematically present the evolution of antivirus detection capabilities based on a realistic testbed and a wide range of malware types. In particular, this article analyzes data collected from Q3 2024 to Q4 2025, comparing download-time and real-time detection performance, and examining performance gaps between products as well as the limitations of current detection technologies to assess the practical effectiveness of modern antivirus solutions.
[글쓴이:] 이 정호
KAIST 사이버보안연구센터 사이버위협분석팀 연구원으로 데이터 수집 및 분석, 소프트웨어 테스팅 연구를 주로 수행하고 있다.
최근 악성코드는 다양한 유형과 유포 경로를 통해 빠르게 확산되며 점점 더 정교해지고 있고, 이에 따라 전통적인 방어 수단인 안티바이러스의 실제 대응 성능에 대한 의문도 커지고 있습니다. 저희 연구팀은 이러한 문제를 정량적으로 분석하기 위해 단발성 평가가 아닌 장기간·동일 조건 기반의 반복 실험을 수행하고 있으며, 시리즈로 기획된 이번 포스팅에서는 실제 환경을 모사한 테스트베드와 다양한 악성코드 유형을 기반으로 안티바이러스 탐지 성능 변화를 체계적으로 정리해 소개합니다. 특히 본 글에서는 2024년 3분기부터 2025년 4분기까지의 데이터를 바탕으로 다운로드 탐지와 실시간 탐지 성능을 비교 분석하고, 제품 간 성능 편차와 탐지 기술의 한계를 중심으로 현재 안티바이러스의 실질적인 대응 수준을 살펴보고자 합니다.
모바일 안티바이러스의 중요성 및 6개의 시나리오를 바탕으로 한 14개의 성능 부분과 36개의 기능 부분에 대한 평가 기준 수립에 대해 기술하였으며 수립된 평가 기준을 바탕으로 다양한 악성앱에 대한 10종의 모바일 안티바이러스의 성능에 대한 실험을 진행하였습니다. 공정한 실험이 되도록 자체적으로 테스트 도구를 개발하여 실험을 진행하였으며 각각의 모바일 안티바이러스의 실험에 대한 평가 결과와 그에 따른 분석 내용에 대해 소개해 드리겠습니다.

