Follow Us

Anti-virus software too inconsistent

Needs to improve

Anti-virus technologies are inconsistent when it comes to identifying attacks such as worms, phishing and botnets.

That's according to a report from the University of Michigan's Electrical Engineering and Computer Science Department and network security company Arbor Networks, anti-virus products are inconsistent at best when it comes to identifying attacks such as worms, phishing and botnets.

The report, Automated Classification and Analysis of Internet Malware, said that "Using a large, recent collection of malware that spans a variety of attack vectors (e.g., spyware, worms, spam), we show that different AV products characterise malware in ways that are inconsistent across AV products, incomplete across malware, and that fail to be concise in their semantics."

It goes on to show that host-based anti-virus techniques failed to "detect or provide labels for between 20 and 62 percent of the malware samples."

The researchers argue that a new classification technique is required that "describes malware behaviour in terms of system state changes (eg files written, processes created) rather than in sequences or patterns of system calls. To address the sheer volume of malware and diversity of its behaviour, we provide a method for automatically categorising these profiles of malware into groups that reflect similar classes of behaviours and demonstrate how behaviour-based clustering provides a more direct and effective way of classifying and analysing Internet malware."

The researchers demonstrated the usefulness of this approach during a six-month period on 3,700 malware samples.

Traditional, signature-based anti-virus methods for detecting and squelching the growing volumes and variety of viruses and other malware have been termed dead by some industry watchers.

Companies such as McAfee, Symantec and Trend Micro have in fact started to reveal plans to move their security products to the next level through whitelisting and other approaches.






Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

State of software security report volume 4

If your business has anything worth protecting, be it money, intellectual property or a trusted...

Download Whitepaper

New threats demand innovative responses

Financial institutions in the UK remain susceptible to further systemic problems, as challenging...

Download Whitepaper

Delivering a competitive advantage through IT

IT organisations share a common mission; to optimise investments and streamline operations to...

Download Whitepaper

6 tips to mobilise your existing ERP

Enterprise mobile users throughout the global business community will number 1.19 billion by...

Download Whitepaper

Techworld UK - Technology - Business

Techworld Awards

Techworld Awards Winners 2011


Learn who the winners of this year's Techworld Awards are. Video footage coming soon...

Find out more
Techworld Mobile Site

Access Techworld's content on the move

Get the latest news, product reviews and downloads on your mobile device with Techworld's mobile site.

Find out more...

Site Map

* *