Anti-Virus is dying...
Anti-Virus, we knew you well...(hurry up and die!)
Why is Anti-Virus dying?
First, it's not really alive, so it can't be dying. What I'm saying here is that the technology isn't working anymore. The detection rate is astoundingly low. Why? Because as of 2013 there were 5.5 million new malware signature generated per month. That is a 50% increase year over year from 2012. That and the best in breed Anti-Virus catches only 30% of known malware under 30 days old. All this is according to the well-respected source of Virustotal.com
To generate a new signature all that is required is to modify the last few bits of a malware stub. This activity is known as flipping a bit, and is completely automated by free, readily available, malware crypters, packers, and binders.
Those serious about making money off of infecting systems and selling their services as bot nets, will automate the generation of thousands of variants per second to make sure that they remain undetected.
Also, malware is a matter of time. No seriously, it's about time. Sophisticated malware has learned that in order to obfuscate the source of the infection they simply need to incorporate a function that simply waits a predefined duration before executing its payload. Existing signature based Anti-Virus technology does not account for this.
Why would we want it to hurry up and die?
As with many things sometimes doing things "the way we have always done it" can get in the way of real progress.
With the proliferation of new malware signatures it’s time to take a fresh approach. As a security community I know a growing level of descent is prevalent. I imagine that it will only be a matter of time before the consumer segment reaches a tipping point where "enough is enough."
Why does it make sense to continue to pump money into companies that charge a premium for Anti-Virus solutions when they are having about the same success rate as free options?
Where do we go from here? What's next?
2 words: Threat Emulation
There currently are new technologies that are capable of detecting malware without using traditional signature technology. They creating instantaneous environments that then can manipulate their internal clocks and detonate suspected payloads. They then analyze changes to virtual system and if deemed malicious based upon heuristics (read behavior) they can create rules to help secure the environment in the future.
One final note:
I do think there is still value in traditional Anti-Virus. There is no reason why we should become vulnerable to knownpopular malware. I'm just saying that I believe that it should not give us a false sense of security, nor should it require a significant of capital to maintain.
Questions? Comments? Agree? Disagree? Let me know in the comments below!
This was an awesome read!! I remember you talking about this in CyberPatriot when I was in high school and it just blew my mind. Now that I am diving deeper into this profession I am seeing that cybersecurity costs corporations a lot of money, so a lot of companies just do the bare minimum.
Good read, man!
Excellent post.
Excellent article.
Great article. The inmates have been running the prison for a while now.