The future of antivirus
Is there a way out of the arms race?
April 14, 2008 12:00 PM ETCSO - Antivirus software makes Greg Shipley so mad he has to laugh. "The relationship between signature-based antivirus companies and the virus writers is almost comical. One releases something and then the other reacts, and they go back and forth. It's a silly little arms race that has no end."
Shipley, chief technology officer at Neohapsis, a security consultancy in Chicago, says the worst part is that the arms race isn't helpful either to him or his clients. "I want to get off of signature-based antivirus as rapidly as possible. I think it's a broken model, and I think it's an incredible CPU hog."
The question is, where should he go? Antivirus as an industry has modeled itself on the human immune system, which slaps a label on things like viruses so it knows to attack them when it sees that same label, or signature, again. Signature-based antivirus has moved well beyond that simple type of signature usage (though at the beginning, it did look for specific lines of code). In its current, more sophisticated form, it dominates the market for security software, despite some obvious limitations: You don't use it to stop data leakage, for instance, though many kinds of malware are designed to siphon data out of companies. The number of malware signatures tracked by security software company F-Secure doubled in 2007, and while you might cynically expect such a company to say there's more malware out there, 2007's total doubled the number of signatures F-Secure had built up over the previous 20 years.
Even before 2007, there were plenty of people besides Shipley arguing that antivirus was an industry in trouble. In fact, in 2006, Robin Bloor, an analyst at Hurwitz & Associates, penned a report titled "Anti-virus is dead." He argued that malware exists only because antivirus software exists, and said that antivirus software was doomed to be replaced by new forms of software, which he calls application control, or software authentication tools. Such tools whitelist the software we use and won't run anything else without the user's explicit permission.
Antivirus firms think their death is greatly exaggerated, thank you very much -- even those that aren't overly reliant on signatures, like BitDefender, which says that signature-based techniques account for only 20% of the malware it catches.
"Signatures aren't dead -- you need them," says Bogdan Dumitru, CTO at the Romanian firm, which uses behavioral targeting techniques to stop the remainder of attacks. Its main research focus is to develop an "undo" feature that will let users hit by malware reverse its effects. BitDefender hopes to release this feature in 2008.
Reprinted with permission from
Story Copyright CXO Media Inc., 2006. All rights reserved.
antivirus software
Additional Resources



White Papers & Webcasts
Death to PST Files
Download Now
The Tangled Web: Silent Threats & Invisible Enemies
Download Now
Tape Killed the IT Guy
Watch Now
Forrester Consulting Mobility Study: Taking Control of Enterprise Mobile Device Diversity
Download Now
BRM: What You Can Do To Reduce Risk In Challenging Times
Watch this webcast now!
What IT Must Do to Support Employee-Owned BlackBerry, iPhone and Android Mobile Devices
Download Now
Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".
eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...

