Anti-Virus Effectiveness Down from Last Year
juct sends us Heise Security's summary of an article detailing the abilities of 17 current anti-virus solutions. German computer magazine c't has found that, compared to last year, the virus scanners are having a more difficult time recognizing malware. Quoting Heise:
"For real protection, however, in view of the flood of new malware, the way these programs cope with new and completely unfamiliar attacks is more important. And that's where almost all of the products performed significantly worse than just a year ago. The typical recognition rates of their heuristics fell from approximately 40-50 per cent in the last test - at the beginning of 2007 - to a pitiful 20-30 per cent."
I've had a lot of people bring me infected PC's with smitFraud, that the big AV's have not even recognised or been able to properly remove, they have been pretty angry that the $90 or so they paid for a complete Internet Security product was not able to protect them.
It causes windows to pretty much choak and die as it just consumes so many resources and provides so much irritation, but major products like Trend or Symantec have not been able to successfully protect or remove them, I have had to use custom written tools that you get off the net for free. They really dropped the ball with that one.
I think the real problem with malware is that by the time an antivirus/antispyware program is needed IT IS TOO LATE. you have already been infected, antivirus software is for after the fact, cleaning up the files that were installed or warning you of their presence in a file atatchment etc.. The real defense here is preventing this from happening in the first place. That is, educating users not to click haphazerdly at anything that they feel like and that is a heck of a challenge. most users do not understand what can happen and many likely do not really care, they just want their new screensaver or whatever to work [bundled with spyware of course] and when their bad habits finally catch up with them when their computer slows to a virtual crawl, they go out and buy a new one thinking computers decay over time or something.
Sigs are too short to say anything truly profound so read the above post instead.
I always assume an antivirus is only as good as its current signatures. Heuristics are good but nowadays, I could literally count with my fingers the number of times it did the job. The best defense is still knowing what you are running with or without an antivirus. Most of the annoyances I see are done by the local script / virus kiddies, their work rarely make it outside the country so the signatures against those are not a priority. (Although what I hate is that most of this local scripts/virii are just copycats of popular ones, yet popular AV's rarely detects them...)
Considering how few viruses run on Linux, it's not as big a deal for Linux users. However, Linux machines that deliver content to Windows users (mail servers, usenet servers, bulletin boards, etc.) are a useful application for Linux virus scanners that detect viruses for other platforms. And the big names do function in this role: Kaspersky and AVG both have products for doing just this. And there's the free ClamAV as well, of course. The Linux versions of the big name products are probably no more or less effective than the Windows versions.
No one company has the resources to be aware of every virus. The standard advice is to run more than one.
In Windows, if you wanna run more than one, you can only have the real time protection of a single anti-virus enabled or you get conflicts.
Meaning you rely on the on-demand protection of every other anti-virus and have to manually run them regularly OR set up schedules. What kind of user will do that?
Slashdot needs Geekcode | Can anyone recommend any good SCIFI? My tastes: Foundation, Startide Rising, CITY, Ringworld,
Just don't have AV's installed at all. Not having AV installed on my system keeps me from even thinking of trying anything stupid. every month or so I download a free trial of a Non Norton / Non Mcaffee AV program, update it and run a full scan. Then I do the same with a different one. Then I repeat with Spyware/malware programs. All that has ever been found is a few cookies. Safety through not doing stupid shit.
Why is it so hard to only have politicians for a few years, then have them go away?
Yeah, now that world + dog uses a NAT router for their broadband and the lack of kazaa, virus' and worms are a dieing breed. We swapped them for intrusive spyware and identity theft-ware that is much harder to get rid of and, thanks to the wonders of social engineering, much harder to stop joe-sixpack from getting :/
...
You make an excellent point.
Pro Linux, as I am, I still do not feel that we can afford to be complacent about the malware issue. The reason that Linux is largely unaffected is that it is not very widely used, especially by the sort of numpties that get tempted by exciting new screensavers baring trojans.
If/when we succeed in bringing Linux to the masses, this layer of protection will be torn away. I hope and believe that Linux is more secure by design and the same is probably true of many of the apps that are popular in Linux distros - you won't find ActiveX cheerfully opeing the door to anyone. However nobody should be ignoring malware with the excuse that Linux is immune.
Why are we still talking about this in late 2007. What have the supreme innovators being doing the past decade. Ranum laid out the solution here:
"if I were to simply track the 30 pieces of Goodness on my machine, and allow nothing else to run, I would have simultaneously solved the following problems":
* Spyware
* Viruses
* Remote Control Trojans
* Exploits that involve executing pre-installed code that you don't use regularly
davecb5620@gmail.com
"The reason that Linux is largely unaffected is that it is not very widely used .. If/when we succeed in bringing Linux to the masses, this layer of protection will be torn away"
If that were true, where are all the Linux server exploits being actively being used it the wild. A Linux desktop logged in as standard user is safe from the numpties and is still usable. The dangers of screensavers wouldn't even apply here; even if a user managed to run some malware script it would most probably be confined to the users home dir, the core system would remain immune.
Re:yeah, but.. (Score:5, Interesting)
davecb5620@gmail.com
I disagree. I think the reason there are fewer pieces of malware floating around for Linux is because of the kind of roles Linux machines typically serve in. Most Linux machines are servers or enterprise workstations. In the case of a server, there will be a system administrator who is responsible for configuring the server, locking it down, and keeping it up. Chances are, they'll notice malware pretty quickly, and do something about it. Enterprise workstations aren't an attractive target, either: they're usually either a shared machine that's locked down hard, and under the eye of a sysadmin, or they're the pet of a tech-savvy user who wants his box in top condition so s/he can get stuff done.
/. geeks) looked at the files that this "codec" was installing, we would see that it couldn't be a real codec at all, and we could cancel the install; but an uninformed user won't know to look at file listings, and won't know what looks right, and what doesn't. It wasn't a failing of the OS: it was a valid installer package that prompted for authorisation to run; it was all about users who don't know how to administer a system.
Malware is all about money these days, whether it's herding bots so you can sell spamming services, or getting paid to DDoS someone's competitor, sniffing credit card numbers to buy stuff, or sniffing personal details for identity theft. Remember that your attack isn't 100% reliable, so you want as many potential targets as possible, and you want to attack weak targets so as to get the highest possible success rate. All so you can make as much money as possible, of course.
And what's the best target? Home Windows PCs, of course. No vigilant sysadmin monitoring the system; average Joe user doesn't grasp the concept of locking his box down, let alone have the m4d skillz to do it; Joe doesn't install patches regularly because he sees the downloads and restarts as nothing more than an annoyance; Joe doesn't really understand his computer, so he doesn't know how to look for the telltale signs of malware; Joe doesn't understand that he has to keep his virus scanner's definitions up to date, and turned off the annoying prompts; Joe doesn't understand a firewall, so he just clicks "Allow" to get rid of the warning message; the list goes on forever...
Now that MacOSX is becoming more popular, we're seeing a bit of malware for it, too. Example, that thing that claimed to be a video codec, but was really a DNS redirector. Now this one is a very good example of how malware authors target uninformed users: in the standard OSX installer program, there is an option to show the files that will be installed; if you or I (as
Until Linux is popular in the hands of inexperienced, non-tech-savvy home users (as opposed to enterprise), it won't be an attractive target for malware authors, and we won't see its security put to the test. When it does become popular, I expect we will see Linux malware, and I expect it will be like OSX malware, in that it relies on failings of the user, rather than the system itself.
For the record, I use OSX and Solaris at home, and develop for whatever I'm paid to develop for at work (which was, until recently, Windows, Linux, Solaris and OSX - looks like it will be just Solaris soon).
Antivirus has always been useless. It's not proper security.
Imagine having a door man that has a list of everyone you hate and everyone on that list is not allowed in your house. An enemy is prevented access but a stranger can still walk away with your TV. Wouldn't it be better to give the door man a list of all your friends instead.
Blacklisting is a really bad way to prevent unwanted activity. Whitelisting is much better.
...and that is all I have to say about that.
http://jessta.id.au
And it will fall still further.
Time was a virus would either just pop up an annoying message or delete random data or reformat your PC. Effectively viruses and virus writers were hunters and once they had got the target they had no further interest.
Virus writers have now become 'civilised' farmers. They now get paid for their efforts.
The writers have a tame herd (of infected PCs). They will spend their time trying to make sure the AV software will not interfere (to them these things are the infection). They spend their time tending their herd and catching 'wild' examples - other peoples virii (?) so they cross-breed.
One consquence of this (if correct) is that viruses may well start to remove other infections, and generally tune up your PC. After all, if your PC is working just fine, why would you bother keeping the AV scanner up to date?
He's right. He's just right.
True story:
A customer call. Quite irate person, yelling and screaming at our poor techie, telling him in no uncertain terms that he finally uninstalled our piece of junk and installed $competitor_software, because our piece of electron crap kept popping up and nagging him with some "virus found" junk and cutting into his productivity while $competitor_software doesn't.
So. Now question for 500: What the heck do you tell him?
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.
You can't hope to really fix bad behavior with technology. This is why instead of giving dad a false sense of security with cpu/disk thrashing AV software, I took the time to show him the nastiness that can go on, especially with email attachments, and downloading and running software he doesn't know anything about. I also set him up with firefox with the adblock plus extension. On his own (even though I didn't feel it was necessary), he manually runs adware detecting software to make sure nothing has been slipping by. Three years, and he has yet to be infected with anything (manual AV scan with latest signatures when I was there the other day confirms).
Tools and their uses:
- Firewalls: block stuff you shouldn't be listening for anyway, also help to mitigate against attacks against stuff you do listen for.
- Service Lockdown (difficult on windoze, see "Firewalls" above): You can't exploit something that's not there
- Proper configuration of what you do need listening: default stuff on that linksys router, for example
- Patches: Deal with worms (not viruses)
- AV software: tries to correct user stupidity. Not exactly a winning battle, as can be seen by the existence of this article.
- IDS: Never for an end user. How are they to know how to tune it, and what the messages mean, etc?
My experience has been that AV software gets in the way, causes system instability, and provides a false sense of security. None of this provides a significant benefit for a user who already practices good hygiene on their computer.
It was prone to happen. Actually I'm amazed it's considered news.
...
The malware-antimalware war ain't a static one. Both sides are engaging in a quite impressive arms race. They start creating morphing trojans, we create ways to detect them, they create global trojan floods, we employ detection networks to catch them, they switch from mail distribution to infected webpages, we start sending out spiders, they start using targeted spam, we create fake personalities to be "interesting" for them, they
It's just the same with the detection and elimination routines. They use certain API calls, we start listening to those calls carefully, they switch the calls, we follow, they start using executable packers, we develop exec unpackers, we discover that malware PE headers have a certain format, they change the format and create "filler" sections to look normal...
It's just a chapter in that arms race. Give us 2 months and we're back on par.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.