Antivirus Makers Struggle to Adapt
nytimes.com
nytimes.com
They can and they have in Windows 8: http://www.lifehacker.com.au/2012/11/ask-lh-does-microsoft-s...
They've renamed it to Windows Defender (confusing, since this was a different product in earlier versions) but the interface is virtually identical to Security Essentials.
What is that better software?
Some people might have weird definitions of "better", so it might also be handy to say why that software is better.
With dynamic languages like JS and ActionScript, their approach is to fingerprint 10 different strains of the same threat. Then the 11th strain can be generated in a few seconds with new obfuscation.
So the A/V only starts working if/when eventually a native code payload reaches the target.
a pretty standard tool in detection evasions bag of tricks is to write a custom virtual machine that generates code on the fly, which makes static, signature based analysis of payloads totally useless.
The remainder of the article provides similar enlightenment.
Aside: this reminded me of PG's article "The Suit is Back": http://www.paulgraham.com/submarine.html That, at least, is well worth a read.
So I guess Imperva might be a company to watch - at least we now know they have a good PR firm :)
In Unixes, it's still "open an xterm and chmod a+x executable". There's still a huge difference.
That along with the horrible architecture of Windows systems that just about invites malware. Vista failed miserably in both architecture and privileges and in an attempt to fix that in Windows 7, the privilege of accounts is nullified as it was in XP.
Speaking of XP, it's still the target of most malware and probably will be for some time as most Windows computers still run it (as opposed to 7/Vista/8).
The fact that third-party software tops malware charts and absence of Blaster, Sobig, Nimda, etc. kind of pandemics doesn't back up your claim.
On the other hand, it is true that anti-virus software became a lot more popular as Windows gained market-share. The reason is simple: as we all know, for a long time Microsoft did not take security very seriously. They essentially followed what seems to be Adobe's current philosophy, which is "release first, secure later." Remember that it was only relatively recently that they started to rigorously plug holes on a very short turnaround (mostly weekly if not shorter). So it is not difficult to conceive of a perspective where anti-virus software existed (and still does) mostly to overcome some of the shortcomings of the OS.
It is easier to whitelist than blacklist. It is stupidly easy to embed a cipher in a binary, encrypt the actual payload, and have the execution context decode it back into its viral form. If you do that, you can tweak a knob, get an entirely different looking binary, and keep shipping out the same virus over and over.
The computer would reboot in to a maintenance mode where it would boot in to a check mode. Hopefully off the network or some other source that couldn't be altered by a virus/malware.
The check mode would checksum all executable content and update its database, reporting all changed and added files. It could also check for known out of date executable files. All files would be checked against a A/V database too. If nothing fails the computer reboots back to the OS, else it is halted until repaired.
This still has two risks I can see, one is the BIOS is altered and subverted there. The other is non-executable content runs transient programs that do not survive reboot.
I understand that anti-viruses (AVs) maintain signatures of viruses (which as I understand are byte patterns present in that virus not present in non-infected software code). They also look for executables modifying others.
Questions:
1. If AVs have to match byte patterns for a very large number of known viruses (millions??), would this not make scanning each executable very slow? This seems to be O[e*v] operation where e is the number of executables and v is the number of viruses. Since it does not seen as slow intuitively, what is going on?
2. I presume AVs would also track check-sums of known executables so that these can be safe guarded against new viruses for which signatures are not yet available. Is this right?
The algorithm that is used is probably a variation of the Aho-Corasick algorithm. This is a string matching algorithm that can match k patterns in O(kn+m).
This is basically linear and doable.
Two your second question I can only point to a flaw in some virus scanner a couple years ago where it detected a false positive in an essential Windows file, removed the file and left Windows in an unbootable state. I do hope that there was some learned lesson.
Go back to Windows, I say!
No worries, downvoting, upvoting, I couldn't give a shit one way or the other. It's just a silly number.
What you or others may attach to it doesn't matter.
What is attached to popular karma is an over-optimistic, unrealistic viewpoint of rewards based on action. The world doesn't work that way, but a lot of people, especially in the western world think it does and think this is a valid concept. It's not. It's a sequitur.
That is all that I was stating. I do not wish to attach anything more to the concept than has already been attached.
Karma is simply that: action. Physical actions are just like how we accept Newton's Laws of motion as science (in Cartesian, non-relatavistic, non-high-gravity). It can be tested to a high degree of certainty, and therefore requires heavy proof to overcome.
However the distinction with karma is application of Newton's laws to also human behavior. That includes equal and opposite reactions to emotions, thoughts, and efforts. Those who followed Hinduism accepted this idea as Karma. Wiccans know this as the Wiccan Rede and the threefold rule. LaVeyan Satanism's "Rules of the Earth" have some sembelance of 'do no harm to innocents'. Even Jews discuss this very topic with the positive form in Leviticus 19:18, whilst not discussing the basis for it (it's usual for Abrahamic religions to give commandments).
I think every religion has developed a wording of the same principal of Karma, but with slightly different wordings due to language and culture.
Most seem to get the idea of inertia. People tend to go the direction they were already headed towards, even if it is ruin. I've seen this time and again with people. It doesn't matter if you tell them: something with as much force has to get in their way. And most people get reciprocity, or "you get what you put out". Seems awfully similar to "For Every Action, there is an equal and opposite Reaction".