Feeds

Virus writers outpace traditional AV

One in ten 'protected' users still get the pox

  • alert
  • submit to reddit

Intelligent flash storage arrays

Email viruses infecting 10 per cent of users and are costing business millions of pounds each year - even though AV software is used by 95 per cent of companies

That's the main finding of a study by analysts Hurwitz Group, sponsored by managed security outfit MessageLabs. This concludes that traditional anti-virus software development is failing to keep pace with email-borne infections. Managed services from ISPs which scan email for viruses offer lower total cost of ownership for AV protection, the Hurwitz report concludes.

Clearly there's a vested interest here, but Hurwitz / MessageLabs claims are consistent with reports of infections that readers send us after every major email virus outbreak - and what the AV software vendors say among themselves.

Every time a new virus is released it takes time to spot it, time for AV vendors to develop an antidote and time to distribute this antidote (virus signature definition file). At the industry's annual get together, Virus Bulletin, in Prague last year, concerns were expressed that this approach is in danger of becoming obsolete.

Improvements in the speed of antivirus analysis and management tools are continuing but can only go so far. Meanwhile virus writing s'kiddiots are taking full advantage of the Internet to spread their wares; and every indication is the problems caused by SirCam, BadTrans-B, Klez-H et al is getting progressively worse.

This means a small number of virus writing s'kiddiots can tie up, or even potentially exhaust, the resources of the industry.

Mark Sunner, Chief Technology Officer at MessageLabs, said: "most anti-virus software was developed in a pre-Internet age when the sharing of an infected floppy disk was as dangerous as things got, now over 90 per cent of viruses are email-borne, spreading across the globe in a matter of minutes."

"For many companies downloading virus patches amounts to no more than closing the gate after the horse has bolted."

MessageLabs argues that the problem needs to be tackled at source and that the first line of virus defence should be positioned at the Internet level, not at the gateway or desktop.

Scanning at the Internet level means more aggressive heuristic scanning (automatic detection) can be used, so emails can be blocked if they have suspicious attachments.

The same approach at the desktop would lead to numerous false positives, and although managed services for virus scanning are not without issues (companies have to trust a third party and scanning encrypted email being two) we reckon they are the way forward.

It's either that or wait for the mythical Warhol worm to floor us all in 15 minutes... ®

Related stories

AV vendors sell 'blunt razor blades'
Rise in viruses within emails outpacing growth of email
2001: vintage year for virus infections
Hybrid viruses set to become bigger threat
Undead virus infects the dim-witted
BadTrans virus bites Windows users hard
SirCam virus hogs connections with spam
Firms hit in Nimda mutant outbreak
Nimda worm tails off
Users haven't learned any lessons from the Love Bug

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.