Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Counting the Bullets on the (Malware) Front
July 25, 2008 11:25



    
How much malware is your antivirus solution detecting? A million, ten million, even "worse", less than a million? Does it really matter? No, it doesn't. What's marketable can also be irrelevant if you are to consider that today's malware is no longer coded, but generated efficiently and obfuscated on the fly. Sophos's recent statistics :

"It is estimated that the total number of unique malware samples in existence now exceeds 11 million, with Sophos currently receiving approximately 20,000 new samples of suspicious software every single day - one every four seconds."

F-Secure's comments according to which they're "lacking behind" Sophos with ten million malware samples :

"Our AVP database reached one million detection records last night. Dr. Evil would be so impressed…"

McAfee's recent comments as well, which seem to detect less malware samples than F-Secure, depending on how you count them of course :

"It demonstrates that it is possible to announce that we detected, at the end of 2007, “between 357,820 (DAT-5196) and 8,600,000 pieces of malware”. And I predict we will detect at the end of 2008 between 450,000 and 22,000,000 malware”. OK, I joke a bit, but I also want to demonstrate there are many manners to count malware and you must not judge a product only by the announced number of detections."

You have an antivirus software that's detecting 10 million malware samples, in reality, while it's protecting you from 10 million malware samples it wouldn't protect you from the just coded for hire malware bot that's about to get used in a targeted attack. The number of malware samples detected by any antivirus vendor is up to how they actually count them, do they take into consideration malware families, do they actually distinguish them, or are they in fact perceiving each and every malware as as seperate "bachelor".

Given the speed in which malware authors are lauching a DDoS attack against AV vendors by crunching out dozens of malware variants parts of a single family, their actions could start directly driving the data storage market, and if they continue maintaining the same rhythm, soon you'll be partitioning a separate GB for the signatures files. Then again, the number of malware samples detected by an antivirus solution isn't the single most important benchmark for its actual usability in a real-life situation, keep that in mind.

Where's the Count when you need him most? Well, he's somewhere out there counting.

All news for March 11, 2010
  20:26  Schneier on Security: Wikibooks Cryptography Textbook
  14:17  Schneier on Security: Wanted: Trust Detector

All news for March 10, 2010
  21:47  Schneier on Security: Nose Biometrics
  15:09  Schneier on Security: The Limits of Identity Cards
  06:11  Martin McKeay: The Network Security Podcast, Episode 188
  01:11  Jeff Jones Security Blog: Ubuntu CVE Tracker

All news for March 9, 2010
  20:36  Schneier on Security: Marc Rotenberg on Google's Italian Privacy Case
  20:02  MSRC: March 2010 Security Bulletin Release
  18:28  MSRC: Security Advisory 981374 Released
  14:59  Schneier on Security: Guide to Microsoft Police Forensic Services
  05:19  Martin McKeay: RSAC2010: Sourcefire

All news for March 8, 2010
  22:24  Schneier on Security: Google in The Onion
  19:00  Schneier on Security: Eating a Flash Drive
  16:33  Martin McKeay: RSAC2010: ISC2
  14:13  Schneier on Security: De-Anonymizing Social Network Users
  03:46  Martin McKeay: RSAC2010: Kaspersky Lab
Keywords: counting, the, bullets, on, the, malware, front

All news for March, 2010


All news for 2008


All news for 2009


All news for 2010