Angelo Porcella, Zachary Wadhams, Clemente Izurieta, Jonathan Crussell, Ann Marie Reinhold
2026 Intermountain Engineering, Technology and Computing (IETC)
Abstract
“Sophisticated” is widely used to describe malware, yet it lacks a consistent definition within academic literature. While existing software quality and complexity metrics offer some insight into malware structure, they do not capture the broader adversarial and operational traits that contribute to real-world threat potential. This paper presents a systematization of existing approaches for assessing malware quality using static binary analysis. We define malware sophistication through a quality-focused lens by reinterpreting select characteristics from the ISO/IEC 25010 software quality standard, including reliability, maintainability, flexibility, and security, and evaluating their applicability to malware binaries. We identify which characteristics are both relevant to malware and measurable through static analysis, forming the basis for future frameworks that consistently assess malware sophistication when source code is unavailable or dynamic execution is infeasible.
Citation
@inproceedings{porcella2026characterizing,
author={Porcella, Angelo and Wadhams, Zachary and Izurieta, Clemente and Crussell, Jonathan and Reinhold, Ann Marie},
booktitle={2026 Intermountain Engineering, Technology and Computing (IETC)},
title={Characterizing and Codifying Malware Sophistication},
year={2026},
volume={},
number={},
pages={1-6},
keywords={Malware;Manuals;Modeling;Codes;Measurement;Software;Security;Terminology;Complexity theory;Software quality;malware;quality;sophistication;software;threat analysis;static analysis},
doi={10.1109/IETC69527.2026.11568673}
}
Links: