Computer virus
Security firms are warning of a new era of malware 2.0
R E L A T E D   C O N T E N T
ADVERTISEMENT

'Malware 2.0' raises its ugly head

Signature-based security unable to cope with 'zero-minute' threats

Ian Williams, vnunet.com 19 Jul 2007
ADVERTISEMENT

Signature-based malware detection techniques are becoming less effective in the face of so-called 'malware 2.0' threats, a security firm claimed today.

"The security space is changing rapidly. We are witnessing a major shift in the anti-malware marketplace moving into a new era of malware 2.0," said Kurt Baumgartner, chief threat officer at PC Tools

"We are now dealing with zero-minute, rather than just zero-day, exploits that have the potential to further evade signature detections."

PC Tools said that malware variants are now released at "immense rates", driving up sample volumes and making it almost impossible for researchers to keep on top of updates using manual analysis.

These threats are taking advantage of the non-detection sweet spot where they can freely propagate and infect before anti-malware companies can respond.

PC Tools argues that new compilers and other techniques are being used to make threats more difficult, if not impossible, to detect with traditional signature-based systems.

Rather than the broad sweeping attacks seen in the past, attacks are now focusing on smaller groups of PCs making it less likely to attract the attention of security vendors. As a result, malware is spreading in "epic proportions".

"The real challenge for security vendors is in identifying new ways to detect the behaviour of malware. Signature identification alone is ineffective in protecting consumers," said Baumgartner.

Fran Howarth, a partner at analyst firm Hurwitz and Associates, agreed with the research. 

"Signature-based detection is dead, be it for antivirus, intrusion detection or any other security measures," she told vnunet.com, adding that security companies are currently just "playing a constant game of catch up".

The spyware industry is worth billions of dollars, and there are significant incentives for malware authors to develop techniques to avoid detection.

The researchers estimate that one in five users with major antivirus products already installed on their computers are still vulnerable to these new and emerging threats.

See also:

Apple wormAnonymous hacker boasts of attack that can penetrate fully-patched Macs  18 Jul 2007
Apple iPhoneSafe for now, but uncertain future  11 Jul 2007
Swiss laboratory launches marketplace for security research  05 Jul 2007
HackingNew targeted attacks also on the rise  03 Jul 2007
Phishing114,013 new sites found last week, most using commercially available toolkits  20 Jun 2007

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Greythorn IT
Leading Mobile Network vendore is currently seeking a Process consultant for a positions based either in the Middle east or Africa. We are looking for around 10 years experience with at least 5 years business ... more >
| Greythorn IT
Tier 1 Network solutions provider is currently seeking an experienced Telecommunications sales manager to work in their Abu Dhabi office. There is a brilliant benefits package as well as an attractive salary available for the ... more >
| Greythorn IT
Leading network solutions provider in Egypt is currently seeking and experienced Egyptian Network Operation /Supervision Engineer. There are competitive packages and attractive benefits package on offer for the right candidate. You will be responsible to ... more >
| Greythorn IT
A leading network Solutions vendor is currently seeking an Egyptian national to act as a Service Assurance manager out of their Egyptian office. Ideally we are looking for someone with Vendor based experience however other ... more >
More job opportunities