About Us

The Immunet Blog is maintained by the Immunet team as a forum for discussing news and issues related to AntiVirus, security and cloud technology.

Search
« Computer Viruses Make for Gripping (Often Real) Urban Legends | Main | The State of the Net 2010 is Sobering: Why Protecting Your Lifeboat Matters More Than Ever »
Saturday
May082010

The desktop security battle is just beginning

Jeremiah Grossman from Whitehat Security posted an interesting Blog on Thursday entitled ‘Ceding the desktop security battle, almost the war’ which was followed by an article from Dennis Fisher on ThreatPost, ‘Have We Lost the Desktop Security Battle?’.

Both posts draw the same conclusion (with Dennis really hitting it home) – AntiVirus vendors have lost and virus authors have won.  Since this debate has been percolating in the security space for well over a decade now, let’s look at some real facts on how well today’s leading AntiVirus vendors are doing.

To do this, let’s look at one of the few impartial industry reviews that actually measures how well we are all doing.  The best measure for this is AV Comparatives, run by Andreas Clementi in Germany.  His review, the Proactive / restrospective test is designed to measure a product’s detection rate on new, previously unseen threats.  AntiVirus vendors all do very well on known threats, regularly achieving over 99% detection.  Known viruses, however, are shared by vendors across the industry and everyone has them, including the reviewers; so these numbers come as no surprise.  It is how well vendors do on unseen threats that REALLY matters and ultimately dictates how protected Consumers are as they browse the Internet each day.  This is what the retrospective test measures.

Andreas’ last retrospective review was released in November of 2009 and can be obtained here (PDF document).  Note that Immunet has not participated in the review (our product is still in beta as we improve our own detection capabilities).  The below picture pretty much sums it up:



As we can see, average proactive detection rates hover at 50% or less, including those of the two market leaders.  There is a caveat to this test – products that use execution based detection (such as emulation or behavioral monitoring) are not able to benefit from them in this test. 

This is a stark reminder as to what a typical Consumer should expect from their AntiVirus product:

A less than 50% chance of being protected when they encounter a new threat

As a result, Financial Institutions (as Jeremiah discusses) are more than justified in assuming that all Consumers are compromised, and in accepting transactions despite this.

Despite these numbers, I would argue that the AntiVirus industry has not ceded the battle, nor has it lost it, but it is struggling to maintain high efficacy rates in the face of a growing number of threats.  The traditional approaches to this problem are not working.  We need game changing technologies to make a dent in this problem, since the status quo just won’t do. 

I remain convinced that by using the latest technologies in cloud computing, collective intelligence, data mining and machine learning, we can make a big leap forward from where we are today and turn the table on these threats.  The AntiVirus problem has turned into a data management and timing problem.  It is about how much temporal data about files you can collect, and how quickly you can process that data in order to make a basic decision on its disposition; ultimately a YES or NO decision.  These concepts are exactly what we are working on here at Immunet and we have certainly not given up.  

Rather than seeing the war as being lost, we at Immunet believe that the battle is just beginning.  We are just starting to see the benefits from these game changing technologies.  We are building technologies that will have the ability to be far more effective than what has been built before us, and we are all devoting our lives to this fight in the here and now.

 

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (10)

Do we need a SPU (Security Processing Unit) together with a CPU & GPU?

May 8, 2010 | Unregistered Commentersrw

Helpful Stuff! Though I don't understand much but I know this is useful!

Automatic Gate

May 11, 2010 | Unregistered CommenterJulie Johnson

If only more than 64 people would hear about this..

May 28, 2010 | Unregistered CommenterJanine Hampton

If only more people could hear about this!

May 29, 2010 | Unregistered CommenterVictor Madrid

You've done it once more! Superb post!

May 31, 2010 | Unregistered CommenterEmanuel Payne

Hehe I'm literally the first comment to this incredible read?!?

May 31, 2010 | Unregistered CommenterTracey Bruno

This just proves that once again relying on anti-virus alone is not going to block viruses. I encourage everyone to look at my articles on windowssecurity.com which describe least privilege. You need all users (employees and IT staff) running least privilege. With a solution like BeyondTrust PowerBroker for desktops (www.beyondtrust.com), you can acheive this with EASE!

Derek Melber, MVP

October 30, 2010 | Unregistered CommenterDerek Melber, MVP

When it comes to NBA, there are a lot of people, especially, the young people will be excited. When the events begin, hundreds of millions of fans watch the matches through the night with the NBA jersey. The lovejerseys.com supplies all kinds of NBA jerseys at cheap price. As the event is coming, do not hesitate to have one of Cheap basketball jerseys.

December 15, 2010 | Unregistered CommenterCheap basketball jerseys

Ralph Lauren Ralph Lauren Polo Ralph Lauren Polo Ralph Lauren Ralph Lauren Polo Ralph Lauren Polo Cheap Ralph Lauren Polo Cheap Ralph Lauren Polo Ralph Lauren Polo Outlet Ralph Lauren Polo Outlet Ralph Lauren Outlet Store Ralph Lauren Outlet Store Ralph Lauren Polos Ralph Lauren Polos Ralph Lauren Clothing Ralph Lauren Clothing Discount Ralph Lauren Women S Polo Shirts Discount Ralph Lauren Women Polo Ralph Lauren Classic Fit Stripe Sport Shirt Polo Ralph Lauren Classic Mens Ralph Lauren Custom Fit Polo Mens Ralph Lauren Custom Ralph Lauren Black Watch Polo Ralph Lauren Black Watch Big And Tall Ralph Lauren Polo Shirts Big And Tall Ralph Lauren Colorful Polo Ralph Lauren Shirts Colorful Polo Ralph Lauren Ladies Polo Ralph Lauren Shirts Ladies Polo Ralph Lauren Polo Ralph Lauren Models Polo Ralph Lauren Models Big Pony Polo 5x Ralph Lauren Big Pony Polo True Religion True Religion True Religion Jeans True Religion Jeans Cheap True Religion Jeans Cheap True Religion Jeans Discount True Religion Jeans Discount True Religion Jeans Herve Leger Herve Leger Herve Leger Dress Herve Leger Dress Herve Leger Skirt Herve Leger Skirt Herve Leger Outlet Herve Leger Outlet Herve Leger Bandage Herve Leger Bandage Herve Leger Dresses Herve Leger Dresses

January 10, 2011 | Unregistered Commenterxixiwyhes
Comments for this entry have been disabled. Additional comments may not be added to this entry at this time.