In recent years, malicious software (malware) has become one of the most insidious threats in computer security. However, this is arguably not the result of increased sophistication in malware design or attack strategies, but rather of the increased presence of computers and computer networks within every aspect of society. In this paper, we address and defend the commonly shared point of view that the worst is very much yet to come. We introduce an aim-oriented performance theory for malware and malware attacks, within which we identify some of the performance criteria for measuring their “goodness” with respect to some of the typical objectives for which they are currently used. We also use the OODA loop model, a well-known paradigm of command and control borrowed from military doctrine, as a tool for organising and reasoning about the behavioural characteristics of malware and orchestrated attacks using it. We then identify and discuss particular areas of malware design and dep...
José M. Fernandez, Pierre-Marc Bureau