Can antimalware suites remain effective if they are sandboxed ?
Seems to me that the "system police", as it were, needs access to the system it is policing.
Seems to me that the "system police", as it were, needs access to the system it is policing.
I agree with your sentiment that sandboxing will require more complex interactions between sandboxes for antimalware suites to act on pre-existing threats (and minimizing the required privileges for the 'SYSTEM'-level process that must act on those threats.)
[1]: https://www.engadget.com/2016/06/29/google-symantec-antiviru... [2]: https://www.engadget.com/2016/01/13/trend-micro-security-pas...