ARCHIVES
Nation Guard Antivirus: A Hybrid Multi-Stage Detection System for Nation-State Malware and Advanced Persistent Threats
¹ ² ³ ⁴ Department of Computer Science and Engineering (Cyber Security), United Institute of Technology, Coimbatore, Tamil Nadu, India. ⁵ Assistant Professor, Department of Computer Science and Engineering, United Institute of Technology, Coimbatore, Tamil Nadu, India.
Published Online: May-August 2026
Pages: 72-80
Cite this article
↗ https://www.doi.org/10.59256/indjcst.20260502008Nation Guard Antivirus is a hybrid cybersecurity system engineered to detect nation-state sponsored malware and Advanced Persistent Threats (APTs) that systematically evade conventional antivirus tools. This paper presents the complete architecture, methodology, implementation, and evaluation of Nation Guard, integrating three complementary detection methodologies: static analysis, dynamic sandbox-based analysis, and real-time behavioral monitoring. The system employs a layered, five-stage pipeline that progressively escalates suspicious files through increasingly resource-intensive analysis stages. Static analysis using YARA rules, hash verification, PE header inspection, and entropy analysis achieved a detection rate exceeding 87% for known APT signatures in controlled evaluation. The dynamic sandbox, built on QEMU/KVM virtualization, captures file system activity, registry modifications, network communications, and process behavior across configurable execution windows. The behavioral monitoring engine, implemented as a kernel-level driver, provides continuous system-wide surveillance capable of detecting fileless malware, living-off-the-land (LotL) attacks, and sophisticated persistence mechanisms. All five development phases have been completed, yielding a fully integrated detection engine capable of generating composite threat scores and triggering automated response actions. Future enhancements include machine learning classifiers, MITRE ATT&CK framework mapping, and SOAR platform integration. Nation Guard represents a significant advancement toward enterprise-grade, adaptive defense against state- sponsored cyber intrusions.
Related Articles
2026
Artificial Intelligence in Learning and Teaching
2026
Admin Assist: An AI – Driven Configuration and Orchestration for Enterprise Application
2026
Enhancing Blood Group Identification using pigeon inspired optimization: An Innovative Approach
2026
Eco-Genius: Power Up Smart, Power Down Waste
2026
Crowd-Sourced Disaster Response and Rescue Assistant
2026
Unveiling Deepfake Detection Using Vision Transformers: A Survey and Experimental Study
2026
A Novel Stateful Orchestration Pattern for Data Affinity and Transactional Integrity in Sharded Backend Architectures
2026
Legal Challenges of Agentic AI Systems in Education and Employment Decision-Making
2026
New-Hybrid Soft Computing Model for Stock Market Predictions
2026
Human Emotion Distribution Learning from Face Images Using CNN


