Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Anti Malware is Not Dead, But it is Futile
News & Analysis

Anti Malware is Not Dead, But it is Futile

ISBuzz TeamBy ISBuzz TeamJune 11, 2013Updated:November 28, 20137 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
malware
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The IT security market remains dominated by anti-malware vendors whose business model is based on the detection of new malware and selling subscription-based updates that block new malware as it is released. Two of the world’s biggest security companies, McAfee and Symantec – while both have diversified into services –  still focus much of their global marketing effort on anti-malware and being seen to be on the offensive against the malware creators. And to the general public, cyber security IS anti-malware.

At the same time, despite coming up with new product categories that supposedly meet new types of threats as they appear, many parts of the IT security vendor community continue to license those core anti-malware products from the major manufacturers, and neatly package them into a wide variety of tin boxes in categories such as anti-malware gateways, anti-malware management, UTM and content filtering.

While it is true that security technology has improved in the last ten years, with a move to more intelligence and risk-based tools such as SIEM and vulnerability assessment products, too much effort is being placed on trying to defeat what is now increasingly clear to be undefeatable: the continuous tide of malware and zero-day vulnerabilities.

This unwinnable war on malware continues to be good business. In 2011, Gartner reported that (US) consumers spent $4.5 billion on antivirus while enterprises spent $2.9 billion, a total of $7.4 billion or more than a third of the total of $17.7 billion spent on security software.

In its marketing efforts, the anti-malware industry focuses on its valiant efforts to defeat malware. We are increasingly told how malware and, by extension, its authors have never been more “sophisticated” or the volume more eye popping.

“Today’s security threats are more sophisticated and targeted than ever, and they’re growing at an unprecedented rate. Malicious URLs, viruses, and malware have grown almost six-fold in the last two years, and last year saw more new viruses and malware than all prior years combined.” reports McAfee Labs.

Not to be outdone, F-Secure claims that, “Cybercriminals are following the money. They are authoring ever more sophisticated, difficult-to-detect malware”. And just to complete the picture here’s Sourcefire:  “Today, malware is more sophisticated and evolving more quickly than ever before. Many customers find it impossible to keep up.”

The security press does its bit too. In the United States, SC Magazine says that malware remains an emerging area of concern “because it is always changing”.

“We used to worry about zero-day threats. Now it can be zero-hour. Malware is proliferating at a ferocious rate.” it added in the foreword to one of its group tests, failing to see the irony in describing malware as an emerging area of concern.

So we know for sure that malware has never been more sophisticated or that there is a lot of it about. And yet for all their efforts, the anti-malware lobby do not seem to be doing a very good job of managing the threat. Efficacy is a problem. A report by Israeli cloud security company Imperva collected and analysed 82 previously non-catalogued viruses against more than 40 anti-virus solutions, and it found that less than five per cent of anti-virus solutions were able to initially detect previously non-catalogued viruses. It also found that some freeware AV solutions performed better than those from the major brands.

At this point, I should say that I am not trying to blame any company for the anti-malware conundrum. McAfee, Symantec, Kaspersky and the rest all do valuable work for the industry in many different ways.

We still need anti-malware, just like we need PCs but I am sure that deep within the citadels of those businesses is the realisation that anti-malware as it exists now is not working and we need to be moving on from the anti-malware era.

The vendors that matter, I am sure, are giving this matter serious consideration. They are spending billions of dollars trying to defeat an entity that simply won’t go away and passing the cost onto their customers in a cycle of diminishing returns. The more we spend, the less the impact.

I am not cynical enough to believe that the anti-malware industry would prefer this negative status quo in order to maintain profits. This war on malware has led to the stasis of containment which is not good for the industry, its customer base or the economy. We have got there together.

So what’s the answer? That’s the problem. At the moment there isn’t a clear one. We can’t abandon anti-malware immediately but what we can do is shift resources away from the “war on malware” because it is evident that it is an unwinnable war.

The producers of malware by the very nature of the attack and defence mode that we find ourselves in, will always be ahead. We are always playing catch up and by its very nature anti-malware can only neutralise known threats.

We can begin a process of reengineering our approach to malware. We need instead to move to a model of active intelligence. By watching malware rather than trying to kill it. Most importantly analyse what attackers do with malware – it is after all only a means to an end whether that is data theft or financial gain.

Blocking a known malicious activity or quarantining a part of the network that is affected may be a smarter move than throwing endless bits of anti-malware across the enterprise, trying to stop it coming in.

By letting the “clever” stuff in, the well-written software (malware) that “does bad things”, we can learn how to defend the systems rather than finding a patch. After all, many of those “sophisticated” new viruses and zero day attacks are not entirely unique, they are based on the DNA of previous malware but tweaked ever so slightly to slip though the previous set of signatures. We know this so why can’t we build on this intelligence and develop architectures that can identify and isolate malware using an heuristic approach. Does this sound like fantasy or beyond the imagination of the R&D department of the major vendors?

The war on malware is beginning to look much like the war on drugs: billions spent and a drug trade bigger than ever. It’s time to divert funds and research into new technology that manages malware rather than the futile goal of killing it.

About the Author:

is17Paul Fisher | @Pfanda | Pfanda.co.uk

Paul Fisher has worked in the technology media and communications business for the last 22 years. In that time he has worked for some of the world’s best technology media companies, including Dennis Publishing, IDG and VNU.

He edited two of the biggest-selling PC magazines during the PC boom of the 1990s; Personal Computer World and PC Advisor. He has also acted as a communications adviser to IBM in Paris and was the Editor-in-chief of DirectGov.co.uk (now Gov.uk) and technology editor at AOL UK.

In 2006 he became the editor of SC Magazine in the UK and successfully repositioned its focus on information security as a business enabler. In June 2012 he founded pfanda as a dedicated marketing agency for the information security industry  – with a focus on content creation, customer relationship management and social media.

His heroes include David Ogilvy, Ludwig Mies van der Rohe, Ken Garland, William Bernbach, Andy Warhol, Richard Branson, Charles & Ray Eames, Steve Jobs and Paul Rand. And George Best. He comes from Watford but he thinks he comes from Manchester. If you came from Watford, you would too.
As an impulsive adopter of new technologies and an inability to stick to one ecosystem, he can be spotted around London’s finest WiFi hotspots variously sporting a Chromebook Pixel, an old Blackberry, Nexus 7 and a Nokia 920. He also has a Mac and an Xbox at home.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Tenable warns AI adoption is outpacing governance as cloud exposure risks surge

May 15, 20264 Mins Read

Cloud Security Controls Explained: A Definitive Guide

March 19, 20269 Mins Read

From VPS to Phishing: Darktrace Exposes SaaS Hijacks through Virtual Infrastructure Abuse

August 22, 20255 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}