Technologies that
Bring Peace of Mind
Online
technical Help
and Support
Status live support chat
Live support
Have a question?
Call us Toll-Free at:
1-877-ANTISPY
1-877-2684779
+44-207-099-2078
More contacts


Subscribe to our
RSS feed
Subscribe to our RSS feed
In focus
Counting the Bullets on the (Malware) Front
July 25, 2008 11:25



    
How much malware is your antivirus solution detecting? A million, ten million, even "worse", less than a million? Does it really matter? No, it doesn't. What's marketable can also be irrelevant if you are to consider that today's malware is no longer coded, but generated efficiently and obfuscated on the fly. Sophos's recent statistics :

"It is estimated that the total number of unique malware samples in existence now exceeds 11 million, with Sophos currently receiving approximately 20,000 new samples of suspicious software every single day - one every four seconds."

F-Secure's comments according to which they're "lacking behind" Sophos with ten million malware samples :

"Our AVP database reached one million detection records last night. Dr. Evil would be so impressed…"

McAfee's recent comments as well, which seem to detect less malware samples than F-Secure, depending on how you count them of course :

"It demonstrates that it is possible to announce that we detected, at the end of 2007, “between 357,820 (DAT-5196) and 8,600,000 pieces of malware”. And I predict we will detect at the end of 2008 between 450,000 and 22,000,000 malware”. OK, I joke a bit, but I also want to demonstrate there are many manners to count malware and you must not judge a product only by the announced number of detections."

You have an antivirus software that's detecting 10 million malware samples, in reality, while it's protecting you from 10 million malware samples it wouldn't protect you from the just coded for hire malware bot that's about to get used in a targeted attack. The number of malware samples detected by any antivirus vendor is up to how they actually count them, do they take into consideration malware families, do they actually distinguish them, or are they in fact perceiving each and every malware as as seperate "bachelor".

Given the speed in which malware authors are lauching a DDoS attack against AV vendors by crunching out dozens of malware variants parts of a single family, their actions could start directly driving the data storage market, and if they continue maintaining the same rhythm, soon you'll be partitioning a separate GB for the signatures files. Then again, the number of malware samples detected by an antivirus solution isn't the single most important benchmark for its actual usability in a real-life situation, keep that in mind.

Where's the Count when you need him most? Well, he's somewhere out there counting.

All news for July 4, 2009
  00:31  Schneier on Security: Friday Squid Blogging: Office Squid

All news for July 3, 2009
  21:42  Schneier on Security: The Pros and Cons of Password Masking
  15:18  Schneier on Security: The Insecurity of Secrecy

All news for July 2, 2009
  20:09  Schneier on Security: Information Leakage from Keypads
  14:11  Schneier on Security: More Security Countermeasures from the Natural World

All news for July 1, 2009
  22:27  Schneier on Security: MD6 Withdrawn from SHA-3 Competition
  19:49  Schneier on Security: New Attack on AES
  14:51  Schneier on Security: Security, Group Size, and the Human Brain
  03:18  Martin McKeay: The Network Security Podcast, Episode 156

All news for June 30, 2009
  21:36  Schneier on Security: Cryptography Spam
  14:32  Schneier on Security: Growth of the CSE
  05:32  Martin McKeay: FIRST 2009: Dr. Suguru Yamaguchi
Keywords: counting, the, bullets, on, the, malware, front

All news for July, 2009


All news for 2008


All news for 2009