Another year, another debate over whether anti-virus’ demise is imminent. This time, a surprising voice joined the anti-AV crew: Symantec, one of the world’s biggest anti-virus sellers. It said that whilst the technology still had a place in stopping some threats, it wasn’t going to be a money maker anymore (despite the fact 40 percent of Symantec’s revenue comes from anti-virus).
Others soon gleefully waded in to declare that AV has indeed been dying for some time and is very nearly a goner. One of them was FireEye, one of the fastest-growing security companies around that has been bashing the “AV is dead” drum since it was founded.
Steer told us over email that it works “approximately 15 percent of the time”. So even the most rudimentary AV does work to some extent, even according to one of the technology’s chief detractors.
Many so-called “advanced threat detection” firms likely use some kind of signature-based anti-virus tools, says Simon Edwards, technical director of Dennis Technology Labs, an independent testing facility. “And why not? We’ve seen a file appear on Fred’s PC and we can take a signature of that and search the other files on the network for other copies. That makes a lot of sense and does not sound like dead or obsolete,” he adds.
The likes of FireEye are laying into this signature approach as it only finds malicious kit after the fact. But no respectable AV firm is using solely signature-based detection anyway. That includes Symantec, McAfee, Kaspersky, the whole anti-virus crew.
“Anti-malware products that use only signatures of known malicious files are very limited and that’s why no decent AV product works that way. They all have additional protection layers to support this most basic function,” adds Edwards.
“It would be rather remiss to omit the signature system (you’d risk ignoring well-known malicious files, which seems rather silly), but to rely on it is clearly a bad idea.
“That’s what the ‘AV is dead’ line always comes down to. It should really be: ‘AV products that rely solely on signatures are relatively useless in isolation’.”
Anti-virus seems to stop rather a lot of malware anyway, says Edwards. Whilst few products are 100 percent effective, the best products stop in excess of 90 percent of threats, according to Dennis Technology Labs tests. “Again, that does not sound like dead or obsolete.”
And what of consumers? What else can they rely on to protect them from nasty threats like ransomware? Anti-virus appears to be the only viable option.
“Have you ever tried even the most basic parental control software? It’s very labour-intensive to use in the real world,” Edwards adds.
“So anti-malware-based products are clearly one of the few options available for consumers and, as long as those products are not entirely signature-based, they should do a reasonable job of protecting people. They will be better than nothing, at least, which, again, does not sound like dead or obsolete.”
Anti-virus is very much alive then. It’s just not as good at its job as users would like it to be.
Are you a security pro? Try our quiz!
Fourth quarter results beat Wall Street expectations, as overall sales rise 6 percent, but EU…
Hate speech non-profit that defeated Elon Musk's lawsuit, warns X's Community Notes is failing to…
Good luck. Russia demands Google pay a fine worth more than the world's total GDP,…
Google Cloud signs up Spotify, Paramount Global as early customers of its first ARM-based cloud…
Facebook parent Meta warns of 'significant acceleration' in expenditures on AI infrastructure as revenue, profits…
Microsoft says Azure cloud revenues up 33 percent for September quarter as capital expenditures surge…