Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


April 02, 2008

Anti-Malware Performance and Evolution

RSS
Subscribe to Windows IT Pro | See More Antivirus Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

As more malware is detected, anti-malware signature databases grow. The size of such databases and how up-to-date they are affect detection rates (and overall system performance). As the stress to meet performance demand increases, the need for anti-malware product evolution becomes more apparent.

To give you an idea of the sheer volume of malicious programs, Andreas Marx of AV-Test.org recently wrote that his organization received nearly 5.5 million unique malware samples in 2007 (at the URL below). That's quite a lot. Marx also wrote that his organization's in-house testing platform (which handles 45 different anti-malware solutions) downloaded a total of 148,869 unique updates in 2007 for a total of 1.6TB of data. I did some quick math and found that that's an average of 9 updates per day for each of the 45 products. http://www.av-test.org/down/papers/2008-02_vb_comment.pdf

So how does increased malware volume affect detection rates? AV-Test.org recently released a report that compares the performance of 30 anti-malware solutions in multiple tests. The tests included on-demand signature-based tests, adware and spyware detection, false-positive rates, retrospective and proactive detection, rootkit detection, new outbreak response times, and malware cleanup. Retrospective and proactive detection tests the capabilities of a tool that hasn't been updated for one week combined with any built-in heuristic and behavior-based defenses the tool might have.

The on-demand tests used 1.1 million Trojans, backdoors, bots, worms, and viruses collected in January and February. The adware and spyware tests used 80,000 samples that are no longer active. To determine false positive rates, 100,000 known clean files were run through each scanner. Thirty-five hundred samples were used for the retrospective tests, and 20 active samples were used to conduct proactive tests. In addition, the rootkit detection tests used 12 active rootkits, and cleanup was tested against 20 active malware samples. The cleanup test checked whether a solution could remove the malware and repair any damage, such as changes to the registry or modifications to the system's "hosts" file. To gauge response times to new outbreaks, the tests monitored update turnaround time for 55 outbreaks in 2007 and 3 outbreaks in 2008.

Avira, Sophos, and Trend Micro all ranked at the top overall, with each having a strong point as compared with the competition. For example, Trend Micro's rootkit detection is superior, Sophos's proactive detection is superior, and Avira has the best overall scan speed and response time for issuing updates after a new outbreak (clocked at less than 2 hours on average).

If you look at the results from a narrower perspective that takes into consideration only detection rates for malware along with those for adware/spyware, then Webwasher and G Data are the clear winners. The companies each achieved 99.9 percent detection rates in both categories. Right behind them was TrustPort, with a 99.6 percent detection rate for malware and 99.8 percent detection for adware/spyware, followed by Avira with 99.3 and 99.1 percent detection rates. You can view the full results at Virus Bulletin's site at the URL below: http://www.virusbtn.com/news/2008/03_13a.xml

It seems obvious that the evolution of anti-malware defense needs to move toward better behavior-based detection. Otherwise, we'll all wind up with gigantic signature databases, which of course would translate to performance problems in terms of raw system resource requirements as well as bandwidth use. Stronger gateway products could be another solution because they could offload a megaton of burden from desktops; however, those solutions don't address malware that doesn't transit through a gateway, as is the case with desktop-to-desktop or desktop-to-server transfers.

Marx outlined some of his ideas for better behavioral testing in a recent presentation given at the AVAR 2007 Conference in Seoul, South Korea. The presentation is detailed in a paper available (in PDF format) at the AV-Test.org site, at the URL below--if you're interested in how anti-malware technology might evolve. http://www.av-test.org/down/papers/2007-11_avar_2007_dynamic.zip

If you're curious about other anti-malware performance-related reports, check the data available from VirusTotal (at the first URL below), AV-comparatives.org (second URL below), and Okie Island Trading Company (third URL below). http://www.virustotal.com/estadisticas.html http://www.av-comparatives.org/ http://winnow.oitc.com/malewarestats.php

End of Article



Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
A Simple File Transfer Solution

My small business clients thought FTP was the answer to their file transfer problems, but I surprised them with an even better solution for their data delivery needs. ...

The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

WinInfo Short Takes: 080808 Special Edition

An often irreverent look at some of the week's other news, including a surprising side-trip to Northern Ireland, the 2008 Summer Olympics, Microsoft vs. VMWare, Samsung's lousy SSDs, IBM and Lenovo sitting in a Microsoft-free tree, and much, much more ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 through Aug 29th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



Entrust Unified Communications Certs
Secure Exchange 2007 and save 20%. Now through Sept. 2008.

When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing