The future of antivirus
Is there a way out of the arms race?
April 14, 2008 12:00 PM ETCSO - Antivirus software makes Greg Shipley so mad he has to laugh. "The relationship between signature-based antivirus companies and the virus writers is almost comical. One releases something and then the other reacts, and they go back and forth. It's a silly little arms race that has no end."
Shipley, chief technology officer at Neohapsis, a security consultancy in Chicago, says the worst part is that the arms race isn't helpful either to him or his clients. "I want to get off of signature-based antivirus as rapidly as possible. I think it's a broken model, and I think it's an incredible CPU hog."
The question is, where should he go? Antivirus as an industry has modeled itself on the human immune system, which slaps a label on things like viruses so it knows to attack them when it sees that same label, or signature, again. Signature-based antivirus has moved well beyond that simple type of signature usage (though at the beginning, it did look for specific lines of code). In its current, more sophisticated form, it dominates the market for security software, despite some obvious limitations: You don't use it to stop data leakage, for instance, though many kinds of malware are designed to siphon data out of companies. The number of malware signatures tracked by security software company F-Secure doubled in 2007, and while you might cynically expect such a company to say there's more malware out there, 2007's total doubled the number of signatures F-Secure had built up over the previous 20 years.
Even before 2007, there were plenty of people besides Shipley arguing that antivirus was an industry in trouble. In fact, in 2006, Robin Bloor, an analyst at Hurwitz & Associates, penned a report titled "Anti-virus is dead." He argued that malware exists only because antivirus software exists, and said that antivirus software was doomed to be replaced by new forms of software, which he calls application control, or software authentication tools. Such tools whitelist the software we use and won't run anything else without the user's explicit permission.
Antivirus firms think their death is greatly exaggerated, thank you very much -- even those that aren't overly reliant on signatures, like BitDefender, which says that signature-based techniques account for only 20% of the malware it catches.
"Signatures aren't dead -- you need them," says Bogdan Dumitru, CTO at the Romanian firm, which uses behavioral targeting techniques to stop the remainder of attacks. Its main research focus is to develop an "undo" feature that will let users hit by malware reverse its effects. BitDefender hopes to release this feature in 2008.
Reprinted with permission from
Story Copyright CXO Media Inc., 2006. All rights reserved.
antivirus software
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
