Comments on: Is an antivirus gap looming?
Security researcher Jose Nazario says the concept of antivirus as the last line of defense has been thrown out the window. What should replace it?
Security researcher Jose Nazario says the concept of antivirus as the last line of defense has been thrown out the window. What should replace it?
December 28, 2009 11:34 AM PST
December 28, 2009 11:14 AM PST
December 28, 2009 9:50 AM PST
Add headlines from CNET News to your homepage or feedreader.
More feeds available in our RSS feed index.
Related quotes
His first point has some basis in the mass-market anti-malware products, but many smaller, more innovative companies already imbrogliate threat research, detection, and removal efforts. When a product's techniques for detecting and blocking exploits are co-developed by the threat analysts, rules rather than simple signatures are used to ID threats with polymorphic unpackers and virtual machines. This is a two-way process that advances the detection technology as new threat analysis uncovers new transmission and camouflage mechanisms.
The second point reflects the widespread lack of effective zero-day detection methods in most anti-malware products that rely primarily on conventional signatures. With the explosion of variations in camouflage and packing for even common exploits, no efficient methods exist for scanning files against databases of signatures no longer in the hundreds-of-thousands of entries, but rapidly approaching millions of entries. The handwriting was on the wall several years ago, but only a few progressive products embraced advanced detection methods to avoid this tar pit.
An finally, he is correct that just scanning with most of the market-leading antivirus products is increasingly ineffective. This can be seen in the best independent analysis of anti-malware products that I know about, namely the work at http://www.av-comparatives.org/
There you can see comparisons of the best products and the market-leading products, performed twice each year in two categories. First, the products are tested to see how well they can detect an independent set of in-the-wild malware. A few months later, the products are retested with the original set of "signatures" to see how well they detect new exploits in a (admittedly artificial) test of their zero-day abilities.
The really good products, without updating their databases, catch an amazing number of zero-day exploits that appear. The not-so-good ones show the problems you are pointing out -- namely that there is a delay from the appearance of an exploit until a signature update allows the scanning tool to detect the exploit.
A couple of other points about your perspective article. You use the term AntiVirus, although I'm sure you know that rootkits, keyloggers, etc. are not viruses; blended threats are using the important DNA of each of these types of malcode to make the term AntiVirus less useful. At some point, we need to be using terms like Anti-Malware to describe the coming generations of threats. Also, it is not necessary to wait for a new set of tools to attack the problem -- we just have to look to companies other than the big market leaders.
(Disclosure: I used to work for one of the "big" anti-spyware companies, but currently have no financial or functional association with any anti-malware company.)
The irony with Windows is because all of the security issues they've had, there's a strong framework of tools out there (from third parties & from Microsoft) to *manage* security.
These same tools don't exist on other environments. One of my clients has 30,000 employees... imagine running 30,000 Mac or Linux desktops, it would be completely unmanageable. Plus we'd *still* have to run Anti-Virus, etc., on each box (even on the Mac/Linux), and it would have to be rolled out "by hand."
That's why corporations all stay with Windows. It's not about security in isolation, it's about the balance of knowing your risks and being able to manage it (that is, deploy so called "mitigation controls".)
Many departments in the US Federal Government tried to convert to Linux / Macs but the end results have not shown improvements in overall security. Maybe the exception is in some parts of the intelligence community.
Anyways, on first look it looked pretty sleek, almost like Windows XP, I used Firefox and Openoffice :(, but soon I realized a fact I had ignored till now: there are hardly any programs available to run on this OS.
Later that day, I went to Yahoo website to download Yahoo Messenger. After digging thru their website, I actually found it. Believe it or not, these are the instructions on Yahoo website:
"Save the file to your machine.
Log in as root and type: dpkg -i ymessenger_1.0.4_1_i386.deb to install the application.
Run /usr/bin/ymessenger from X Window to launch the application."
Wow! That's almost like DOS... I guess I need to be a geek or study Computer Science in college to use it. After tinkering with it for another 4 hours, I found out how to login as root. By then I had lost all my patience and I was cursing myself for loosing the Windows CD. I really wanted to go back to the "Double Click to Install" OS
I called HP right away and paid ten bucks for a replacement CD
Yes, there are hardly any viruses for Linux, but so are the apps. Sorry Ubuntu... maybe in my next life, I'll give you another try.
As unfortunate as this fact may be, and it is, it may also be time to stop "laughing" at other users.
I know security, and I've made Windows XP invincible. Watch for this info on the web...you'll be hearing about it before too long.
increasing levels of pesticide. Diversity is the solution. Get a
Macintosh, load Solaris, plant a different crop. And follow
standards for information exchange and reject anything that smells
of monopoly. Free market, level playing field - engage the anti-
trust laws!
You could download and patch-in updated definitions every five minutes (with the A/V supplier supplying them at that rate), and it does exactly bupkis to protect the typical Windows user.
I won't say that other OSes are invulnerable to viruses, but with OSX having zero (so far) successful viruses in the wild, and Linux' last wild virus --anything worth worrying about, anyway-- occurring about five years ago? Couple that now with the intrinsic malware-resistant structuring inherent in Linux and OSX/BSD (or any flavor of *nix for that matter)?
Sure, as markets shift, so will the focus of malware writing, but seriously - the hardened nature of *nix coupled with a heterogeneous OS environment will make it much harder to exploit, dropping the majority of script kiddies out of contention entirely.
Now compare that to the swiss-cheese mickey-mouse security that Windows has (which honestly is not an OS designed for such).
Sure, the astroturfers and fanboys will come a'screaming about how [i]they[/i] never got bit, etc etc. Problem is, the Internet is full of examples that show them to be full of something else entirely when it comes to the basic premise that 'doze is dangerous for the data you may hold precious.
In short, the smart money is on getting the hell away from Windows post-haste.
/P
If you get away from Windows and go to OSX, the virus writers will shift too. People want to go after what has the highest chance of success. And that means what the majority of people use.
The smart money is on not counting on obscurity to keep you safe at night.
Every so many lines of code will have a bug, the question is also how much damage can that bug/design flaw cause.
Microsoft has gotten better, implementing the 40 year old concept of users and administrator a few years back.
However, they are still plagued with reliability issues, like I did a update last weekend on solid hardware. If I used Firefox the system was stable, when I used Internet Exploder.. The system crashed for every patch. Fortunately, on my real computers and work computers I use Linux.
(But a Mac would be great also).
Mark
The technology has now been around for some time. Go in and FDISK your drive, boom no drive, power cycle and there is your stuff just like you left it. That was about 10 years ago so I figure it is pretty solid by now.
Of course I haven't implemented it in my environment yet but it looks promising, hey my computer is freaking out, OK press the power button until it turns off, now turn it back on. Done.
We have been researching alternative approaches to mitigate zero-day attacks that malware poses on Windows systems. This area has received a lot of focus from researchers in the past, specifically in terms of locking-down systems in order to protect them. However, these approaches usually adversely affect the user-experience and maintainability of end-user systems.
We have been prototyping an approach that addresses common internet threats, including zero-day attacks, while attempting to minimize the impact on system usability and maintainability.
Interested in finding out more? http://alphaworks.ibm.com/tech/axe
What I find, though aren't new vulnerabilities. Its the same old stuff. A fully patched system isn't affected by the variants that manage to get past the antivirus software.
As it was said in the article, antivirus is the first line of defense. The new virus variants use new tricks to get through the line, to evade antivirus detection.
Don't listen to those Penguinistas, Linux is virus-proof because it is based on an OS/2 codebase.
--------------------------------------
Your point? Your point?
Nobody uses OS/2 except for the dreamlike technoid geeks living in computer labs circa 1992.
However Linux does have a user base that OS/2 will probably never have because a lot of the third-party code that's in OS/2 is still owned by Microsoft. Given Microsoft's hand in it, it is doubtful they will ever make OS/2 fully open-sourced.
Nice try, though. Feel free to correct the Wiki if I'm wrong.
http://en.wikipedia.org/wiki/OS/2
If the open source community ever manages to focus their work on a single distro to get it half-way ready for Prime Time, they still won't have any real security solutions setup. Their library is infinitely small, because there's no demand.
If any one distro of Linux ever saw the heat that Windows sees, there would be a retaliatory explosion of third-party security products. People still think Mac OS is secure, while researcher Dino Dai Zovi has proven otherwise. In fact, he said in an interview with Computerworld that the Mac operating system is in fact less secure than Windows Vista.
The point? Obscurity is no substitute for security. The advantage of using the OS that is the biggest target is learning where the vulnerabilities are and what to do about it. Since learning how to ace PC Security Test 2007 with Windows XP and IE6, I have discovered that all one needs to make Windows invincible is an ordinary SPI firewall, and blocked write-access to browser settings, system registry, and the kernel. You'll learn more when my new site is up...you'll be hearing about it.
By the way, if there is an operating system out there that's virus-proof, it's OpenBSD, not Linux. OpenBSD has gone four years and running without the discovery of a single vulnerability.
os2 is REALLY a virus-proof
Actually we do. It's called a Mac. :)
From theregister.co.uk:
File of the Week for Mac OS X
NetNewsWire 2.0
Top Picks for Mac
QuickTime
Tiger Cache Cleaner
Firefox
HandBrake
http://downloads.theregister.co.uk/Mac/
File of the Week for Windows
CleanMyPC Registry Cleaner
Top Picks for Windows
Datacatch Librarian
Handy Recovery
Cucusoft Ultimate DVD and Video Converter Suite
Webroot Spy Sweeper
Registry Mechanic
Spyware Doctor
http://downloads.theregister.co.uk/Windows/
They must all be combined, but even then, most of them are signature based.
There has been talk time and again and actual products which claim to offer Heuteristic scanning, but for the number of years that it's been supposedly offered using various methods by numerous vendors... there still seems to be no final "THIS IS THE WAY" Heuteristic scanning method.
Thus a new Heuteristic method... even after all these years has yet to truely come about. And for the ones already out, many if not most of them have false-positive problems which continue to plague each method.
Thus some NEW type of "Hybridistic" rather than "Heuteristic" method needs to come out which can adapt to the constantly changing variants.
But such a "Hybridistic" method needs to look NOT AT a "Signature Base" but AT A "Source Code Base" sort of mentality to discovery which code is save and which code is is malignant by looking at signatures.
However, the signatures I'm referring to are not Virus/Malware/Spyware/Trojan/Worm based signatures, but authentication signatures found in good code which would not be found in malignant code.
That will be the future wave of pre-vention rather than post-vention which current signature based anti-virus and anti-trojan/worm sofware currently offers.
Thus it's going to require a combined effort by Operating System manufacturers as well as application to offer validatable (non-spoofable) signature-based programs to be able to weed out the malware from the good-ware!
Walt
- Antivirus software
- by scottgator July 22, 2007 4:21 AM PDT
- Of all the Antivirus software products that Microsoft (Windows XP is my OS) suggests using, which one has the highest likelihood to detect recent viruses, malware, etc.?
- Like this Reply to this comment
-
(81 Comments)