19 Jul 2007
Signature-based malware detection techniques are becoming less effective in the face of so-called 'malware 2.0' threats, a security firm claimed today.
"The security space is changing rapidly. We are witnessing a major shift in the anti-malware marketplace moving into a new era of malware 2.0," said Kurt Baumgartner, chief threat officer at PC Tools.
"We are now dealing with zero-minute, rather than just zero-day, exploits that have the potential to further evade signature detections."
PC Tools said that malware variants are now released at "immense rates", driving up sample volumes and making it almost impossible for researchers to keep on top of updates using manual analysis.
These threats are taking advantage of the non-detection sweet spot where they can freely propagate and infect before anti-malware companies can respond.
PC Tools argues that new compilers and other techniques are being used to make threats more difficult, if not impossible, to detect with traditional signature-based systems.
Rather than the broad sweeping attacks seen in the past, attacks are now focusing on smaller groups of PCs making it less likely to attract the attention of security vendors. As a result, malware is spreading in "epic proportions".
"The real challenge for security vendors is in identifying new ways to detect the behaviour of malware. Signature identification alone is ineffective in protecting consumers," said Baumgartner.
Fran Howarth, a partner at analyst firm Hurwitz and Associates, agreed with the research.
"Signature-based detection is dead, be it for antivirus, intrusion detection or any other security measures," she told vnunet.com, adding that security companies are currently just "playing a constant game of catch up".
The spyware industry is worth billions of dollars, and there are significant incentives for malware authors to develop techniques to avoid detection.
The researchers estimate that one in five users with major antivirus products already installed on their computers are still vulnerable to these new and emerging threats.
Latest stories from Security
Related articles
Related jobs
Poll
What is the most important IT priority for your company this year?
Connect with V3.co.uk
This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes
Why good data management at all levels is essential in the modern business (video, 6mins)
We have been given the privilege of recruiting for a...
My client is a proprietary, electronic trading firm and...
Our client is looking for a Senior Project Manager (Telecoms...
Business Analysts are being sought by my leading financial...
Keep up to date with the latest products, services and technologies from the world's leading IT companies. IThound.com brings you over 2,000 white papers, case studies and analyst reports.
Do you agree?
Shameful...
"Malware 2.0" and "zero-minute" - that's scary stuff... Until, of course, "Malware 3.0" and "zero-second"
Posted by: anonymous 19 Jul 2007