Anti-virus fix touted by researchers

Opinion
Jun 7, 20072 mins

Anti-virus technologies might not be on their last legs, but they could use a second wind, according to security researchers.

According to a report published recently by researchers at the University of Michigan’s Electrical Engineering and Computer Science Department and network security company Arbor Networks, anti-virus products are inconsistent at best when it comes to identifying attacks such as worms, phishing and botnets. The report is called “Automated Classification and Analysis of Internet Malware.” http://www.eecs.umich.edu/techreports/cse/2007/CSE-TR-530-07.pdf

“Using a large, recent collection of malware that spans a variety of attack vectors (e.g., spyware, worms, spam), we show that different AV products characterize malware in ways that are inconsistent across AV products, incomplete across malware, and that fail to be concise in their semantics,” the report reads.

The report shows that host-based anti-virus techniques failed to “detect or provide labels for between 20 and 62 percent of the malware samples.”

The researchers argue that a new classification technique is required that “describes malware behavior in terms of system state changes (e.g., files written, processes created) rather than in sequences or patterns of system calls. To address

the sheer volume of malware and diversity of its behavior, we provide a method for automatically categorizing these profiles of malware into groups that reflect similar classes of behaviors and demonstrate how behavior-based clustering provides a more direct and effective way of classifying and analyzing Internet malware.”

The researchers demonstrated the usefulness of this approach during a six-month period on 3,700 malware samples.

Traditional signature-based antivirus methods for detecting and squelching the growing volumes and variety of viruses and other malware have been called dead by some industry watchers. http://www.networkworld.com/news/2007/040507-desktop-antivirus-dead.html

Companies such as McAfee, Symantec and Trend Micro have in fact started to reveal plans to move their security products to the next level through whitelisting and other approaches

http://www.networkworld.com/news/2007/042507-malware-detection.html