So should malware authors all figure out what Flame (or other more advanced malware) is doing, and how to do it themselves, eventually current day AV _will_ be useless.
No?
So should malware authors all figure out what Flame (or other more advanced malware) is doing, and how to do it themselves, eventually current day AV _will_ be useless.
No?
It's probably more helpful to think of these classes of malware as being "obscure" or "wide-spread" than "smart" or "stupid" (I apologize for my previous analogy.) "Advanced persistent threats" don't really exist on a higher plane than common, boring malware (although these have included some impressive payloads), they're just tailored toward something specific in most cases.
I think it's a logical impossibility that all malware should suddenly become as obscure as these were. The payload can certainly be shuffled around, but nothing stops AV from recognizing and stopping whatever mechanism decrypts and runs them. That doesn't, in any way, make AV a panacea--but that's the way it's always been.
I guess we'll have to wait and see!