Advertisement
Promo

Security threats Toolkit

Sunbelt: Small antivirus companies are overwhelmed

Tom Espiner ZDNet.co.uk

Published: 25 Jan 2008 17:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Small antivirus and anti-spyware companies are being overwhelmed by the amount of malware being produced, according to security researcher Alex Eckelberry.

Eckelberry, president and chief executive of antivirus company Sunbelt Software, said on Thursday that the huge amount of malware in existence makes it difficult for small compnaies to tackle the problem.

"No longer can a company compete with a few folks in the lab and a group of good programmers," wrote Eckelberry in a blog post. "They're out there: little companies with small teams working an anti-spyware or antivirus product, but it's hopeless. A small platoon won't win this war. You need a brigade."

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Eckelberry quoted AV-Test.org statistics that he said showed "a good representation of the staggering load of malware that anti-malware folks are under". According to Eckelberry, the number of unique samples of malware, with variants, rose from 564 in 1986 to 5,490,960 in 2007. At the beginning of 2006, the number of unique samples of malware was still under a million, but this number had quintupled by the end of 2007.

While anti-malware processes can be automated, said Eckelberry, it is the non-automated processes that are being overwhelmed. For example, hunting down new malware, tracking IP addresses and the locations of potential malware users, reverse-engineering specialised code, creating signatures for difficult malware, and coding to deal with rootkits, all require some form of human interaction, said Eckelberry.

Mikko Hypponen, chief research officer for antivirus company F-Secure, agreed that the amount of malware is rising rapidly.

"The numbers are going through the roof," said Hypponen on Friday. "We're getting 17,000 samples [of malware] a day, and our database uses 30TB of hard-drive space. The job is getting harder and harder. Small companies will be overwhelmed unless they get really clever."

Hypponen said that small antivirus companies need to invest in automated technology that is capable of identifying individual cases of malware, as well as technologies that identify malware based on its behaviour.

"[Antivirus companies] still need virus-specific detection, combined with generic [behaviour-based] detection," said Hypponen. "F-Secure can handle that because we made a major investment in our backend systems three years ago."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
16 out of 16 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters