Feeds

Virus writers outpace traditional AV

One in ten 'protected' users still get the pox

  • alert
  • submit to reddit

Securing Web Applications Made Simple and Scalable

Email viruses infecting 10 per cent of users and are costing business millions of pounds each year - even though AV software is used by 95 per cent of companies

That's the main finding of a study by analysts Hurwitz Group, sponsored by managed security outfit MessageLabs. This concludes that traditional anti-virus software development is failing to keep pace with email-borne infections. Managed services from ISPs which scan email for viruses offer lower total cost of ownership for AV protection, the Hurwitz report concludes.

Clearly there's a vested interest here, but Hurwitz / MessageLabs claims are consistent with reports of infections that readers send us after every major email virus outbreak - and what the AV software vendors say among themselves.

Every time a new virus is released it takes time to spot it, time for AV vendors to develop an antidote and time to distribute this antidote (virus signature definition file). At the industry's annual get together, Virus Bulletin, in Prague last year, concerns were expressed that this approach is in danger of becoming obsolete.

Improvements in the speed of antivirus analysis and management tools are continuing but can only go so far. Meanwhile virus writing s'kiddiots are taking full advantage of the Internet to spread their wares; and every indication is the problems caused by SirCam, BadTrans-B, Klez-H et al is getting progressively worse.

This means a small number of virus writing s'kiddiots can tie up, or even potentially exhaust, the resources of the industry.

Mark Sunner, Chief Technology Officer at MessageLabs, said: "most anti-virus software was developed in a pre-Internet age when the sharing of an infected floppy disk was as dangerous as things got, now over 90 per cent of viruses are email-borne, spreading across the globe in a matter of minutes."

"For many companies downloading virus patches amounts to no more than closing the gate after the horse has bolted."

MessageLabs argues that the problem needs to be tackled at source and that the first line of virus defence should be positioned at the Internet level, not at the gateway or desktop.

Scanning at the Internet level means more aggressive heuristic scanning (automatic detection) can be used, so emails can be blocked if they have suspicious attachments.

The same approach at the desktop would lead to numerous false positives, and although managed services for virus scanning are not without issues (companies have to trust a third party and scanning encrypted email being two) we reckon they are the way forward.

It's either that or wait for the mythical Warhol worm to floor us all in 15 minutes... ®

Related stories

AV vendors sell 'blunt razor blades'
Rise in viruses within emails outpacing growth of email
2001: vintage year for virus infections
Hybrid viruses set to become bigger threat
Undead virus infects the dim-witted
BadTrans virus bites Windows users hard
SirCam virus hogs connections with spam
Firms hit in Nimda mutant outbreak
Nimda worm tails off
Users haven't learned any lessons from the Love Bug

Mobile application security vulnerability report

More from The Register

next story
HIDDEN packet sniffer spy tech in MILLIONS of iPhones, iPads – expert
Don't panic though – Apple's backdoor is not wide open to all, guru tells us
LibreSSL RNG bug fix: What's all the forking fuss about, ask devs
Blow to bit-spitter 'tis but a flesh wound, claim team
Manic malware Mayhem spreads through Linux, FreeBSD web servers
And how Google could cripple infection rate in a second
NUDE SNAPS AGENCY: NSA bods love 'showing off your saucy selfies'
Swapping other people's sexts is a fringe benefit, says Snowden
Own a Cisco modem or wireless gateway? It might be owned by someone else, too
Remote code exec in HTTP server hands kit to bad guys
British data cops: We need greater powers and more money
You want data butt kicking, we need bigger boots - ICO
Crooks fling banking Trojan at Japanese smut site fans
Wait - they're doing online banking with an unpatched Windows PC?
NIST told to grow a pair and kick NSA to the curb
Lrn2crypto, oversight panel tells US govt's algorithm bods
prev story

Whitepapers

Reducing security risks from open source software
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Consolidation: The Foundation for IT Business Transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.
Application security programs and practises
Follow a few strategies and your organization can gain the full benefits of open source and the cloud without compromising the security of your applications.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Consolidation: the foundation for IT and business transformation
In this whitepaper learn how effective consolidation of IT and business resources can enable multiple, meaningful business benefits.