Slashdot Mirror


Game Theory, Antivirus Improvements Explain Rise In Mac Malware

Sparrowvsrevolution writes "Four years ago, security researcher Adam J. O'Donnell used game theory to predict in a paper for IEEE Security and Privacy when malware authors would start targeting Macs. Based on some rough assumptions and a little algebra, he found that it would only become profitable to target Apple's population of users when they reached 16% market share. So why are we now seeing mass attacks on Macs like the Flashback trojan when Apple only has 11% market share? O'Donnell says it turns out he may have underestimated the effectiveness of the antivirus used by most Windows users, which now makes overconfident Mac users a relatively vulnerable and much more appealing target. Based on current antivirus detection rates, O'Donnell's equations now show that victimizing Macs becomes a profitable alternative to PCs at just 6.5% market share."

22 of 319 comments (clear)

  1. Hey Apple Users... by pwnyxpress · · Score: 4, Funny

    How it security by obscurity treating you now?

    1. Re:Hey Apple Users... by Samalie · · Score: 4, Insightful

      Stupid people doing stupid shit with technology and getting viris outbreaks?

      Yeah, that's confined to ANY particular OS.

      Sorry, but if Linux had enough market share, they'd be targeted too. Computing is by definition insecure, because you'll always have stupid people doing stupid shit.

      --
      09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0
    2. Re:Hey Apple Users... by Luckyo · · Score: 4, Interesting

      Pretty much this. In most cases the weakest link is between keyboard and chair and chain is as strong as its weakest link.

    3. Re:Hey Apple Users... by WrongSizeGlass · · Score: 5, Insightful

      How it security by obscurity treating you now?

      Security by obscurity was not the problem. Complacency was the problem.

    4. Re:Hey Apple Users... by cpu6502 · · Score: 4, Funny

      So does Ubuntu Linux have 6.5% share yet?

      --
      My AC stalker: " I personally agree with your posts most of the time, but that won't keep me from modding you troll"
    5. Re:Hey Apple Users... by SJHillman · · Score: 4, Informative

      Linux does have significant marketshare in the server and smartphone arenas. Servers are generally more secure than desktop machines (not to mention better maintained), so there's naturally fewer points of vulnerability - this holds true for Windows servers as well. As for smartphones, I've seen a lot of articles about Android malware recently although I haven't personally encountered any.

    6. Re:Hey Apple Users... by Drinking+Bleach · · Score: 4, Informative

      Generally more secure, but Linux servers are still vulnerable, especially when they are neglected from being looked after. I have signed onto a company that kept a mail server running for years with no updates -- turns out that exim had a security vulnerability and there was a rootkit living on the system for at least a couple years. If the machine was being properly monitored, the chances of infection would be very low (keep on top of updates!), and it would have been detected rather quickly even if it did happen despite that first point.

      I still don't know what the attacker gained but apparently it pays off enough to pry on mismanaged Linux servers.

    7. Re:Hey Apple Users... by betterunixthanunix · · Score: 4, Interesting

      Sorry, but if Linux had enough market share, they'd be targeted too.

      "Linux" is not one operating system. There are very secure distributions, and then there are distributions that are not so secure, and then there are distributions that can be secure if you stick to best practices.

      --
      Palm trees and 8
    8. Re:Hey Apple Users... by davester666 · · Score: 5, Insightful

      What's funny is that NONE of the anti-virus products blocked it, indicating just how useless their products are.

      --
      Sleep your way to a whiter smile...date a dentist!
    9. Re:Hey Apple Users... by msobkow · · Score: 4, Insightful

      Servers are more secure than desktops in the Linux arena primarily because there is no idiot user sitting in front of the keyboard to click "Ok" when malware tries to install itself. Also, servers aren't typically used for surfing and downloading, so the malware doesn't get a chance to try to install itself.

      Only once since I started programming in the late '70s have I seen a machine that was infected without the intervention of a user disabling the anti-virus or installing pirated/downloaded software. Once.

      --
      I do not fail; I succeed at finding out what does not work.
    10. Re:Hey Apple Users... by Charliemopps · · Score: 5, Funny

      as stupid as windows user are... and I'll grant you they ARE stupid... Absolutely nothing compares to the apple market. There's a price to be paid for making your OS so easy to use that you don't even need to be smart enough to tie your own shoes to use it... namely, that your OS will attract all of the people not smart enough to tie their own shoes.

      Now, I know all you apple "power users" are going to get all mad and scream "You're calling me dumb! I'm not dumb!" I'm not saying you're dumb... I'm saying all your friends are dumb... and you make bad technology choices... I'm sure you made a very smart, well informed decision when you chose the wrong operating system.

    11. Re:Hey Apple Users... by Tharsman · · Score: 4, Informative

      I'm sorry; I love my Macs BUT this last Flasback virus would easily get into your computer without doing anything. All you had to do was visit a page with the virulent java applet for your computer to be infected. Once infected it may attempt to ask a password off you to dive further into your system, but even ignoring it did nothing, the virus was fully active in your system.

      Some tech geeks love to think "I'm too smart for me to be infected", and blame anyone with a virus of being stupid. Ironically, those tech geeks" tend to be some of the most vulnerable users for real virus infections, since they refuse to use any anti-virus solution because it will "slow down their system" or patch their systems with latest updates because "it's working fine and I know what I'm doing."

      That’s how viruses actually work. Everything that requires you to do something to accept it is qualified as a Trojan. No amount of tech savvinnes makes anyone less likely to get virus infections (unless you are savvy enough to update asap and run some form of antivirus.)

      THAT being said:
      0.7% flashback victims were Linux machines
      0.6% flashback victims were Windows 7 or Windows 8 PCs
      0.3% flashback victims were FreeBSD
      0.5% flashback victims were machines running an unidentified OS.

      How on Earth does Linux got more Flashback infections than Windows??? Hint: I said why above. At least Macs have the excuse of Apple negligence at patching the vulnerability.

    12. Re:Hey Apple Users... by Tharsman · · Score: 4, Informative

      To add (thanks for the edit button, slashdot!)

      Source of the numbers

    13. Re:Hey Apple Users... by Ihmhi · · Score: 4, Interesting

      This just in, Antivirus products can't block shit they haven't seen before!

      Film at 11.

    14. Re:Hey Apple Users... by mcgrew · · Score: 4, Funny

      Well, hey, then Mac AV will work a lot faster than Windows AV since there's only one virus in the definition database!

  2. One factor frequently left out by MikeRT · · Score: 5, Insightful

    In all of the fights between Windows and Mac users over the disparity in viruses for both platforms, I've never seen a Windows user point out the fact that Windows is often used on infrastructure that is valuable to compromise. No major business runs their corporate infrastructure on Macs. No major sites with valuable data I know of are hosted on Apple hardware. What has changed with the marketshare is that now Macs are used by the upper-middle and upper classes extensively at work and at home. So even at 6.5% of the market, you're far more likely now to compromise a Mac with valuable data or access to it now.

    Compromise a Mac today and you might get access to a corporate network, a richer man/woman's bank information, etc. That wasn't true 10 years ago.

    1. Re:One factor frequently left out by SJHillman · · Score: 4, Insightful

      So what you're saying is the fact that Apple overcharges for Macs is actually a factor in the increase in Mac malware? Oddly enough, makes sense.

  3. "Vastly oversimplified" by ledow · · Score: 5, Insightful

    He says himself that the equation is vastly oversimplified, and a small change in antivirus detection range changes the answer from 16 to 6%. That means the equation is all-but useless and pointless to try to "predict" anything except, apparently, in hindsight.

    I could have plucked any number I liked out of the air and wrote a (reasonable) equation to make it come out with whatever answer I wanted, even basing it on "game theory" (which has very, very, very little relevance here, actually) - I could have done that even before I graduated in mathematics (including Game Theory) over a decade ago.

    When enough Mac's exist to make it viable (and market share has little to do with it compared to "number of computers active on the Internet" of that particular model), viruses will target them. Guess what, same for every other platform on the planet. If someone miraculously sells a popular device based on MINIX that millions start buying, eventually someone will write a virus for that platform.

    Seriously - don't give it the press.

  4. Winning formula by chepati · · Score: 4, Insightful

    Let's see what our wise men can come up with:

    1) Write a "scientific" paper, make assumptions, use some "algorithm", predict event A
    2) Wait
    3) Observe empirical evidence
    4) Revise initial paper
    5) Bask in peer admiration

    Did I miss anything?

  5. Nay! by Anonymous Coward · · Score: 5, Funny

    Tis a feature, allowed by the Almighty Jobs as a test thy faith in Apple .. so only mayest the True Believers be granted the next iDevice.

  6. Urge to deny "overconfident" by Loopy · · Score: 5, Insightful

    While I realize there may be some outrage over the "overconfident" label, it does make sense in terms of learned behavior. More specifically, Windows users have known malware has been rampant for so long that:

    A) they're used to having to use antivirus, firewalls and other "security" type apps

    B) Windows has steadily improved its built-in firewall and anti-trojan features to combat real and perceived vulnerability

    C) Windows-based PC OEMs and system builders install anti-virus by default and have for quite some time now.

    I can't say whether Macs get a/v software by default but despite our joking about macs not being susceptible to malware, that view is held by far too many mac users. While it might be true statistically speaking relative to Windows, it is unhelpful in being a rightfully vigilant denizen of this wretched hive of scum and villainy we call the Internet.

  7. Re:Correct by Anonymous Coward · · Score: 5, Informative
    Actually, here is what Apple says:

    http://www.apple.com/why-mac/better-os/#viruses

    A Mac isn’t susceptible to the thousands of viruses plaguing Windows-based computers. That’s thanks to built-in defenses in Mac OS X that keep you safe, without any work on your part.

    Is this true? Yes, but only because the malware they are talking about was written specifically for Windows. It has nothing to do with the "built-in defenses in Mac OS X that keep you safe". It is at best disingenuous because the average user reads that to mean "Macs can't get malware".