Advertisement
Promo

Security threats Toolkit

Sunbelt: Small antivirus companies are overwhelmed

Tom Espiner ZDNet.co.uk

Published: 25 Jan 2008 17:35 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Small antivirus and anti-spyware companies are being overwhelmed by the amount of malware being produced, according to security researcher Alex Eckelberry.

Eckelberry, president and chief executive of antivirus company Sunbelt Software, said on Thursday that the huge amount of malware in existence makes it difficult for small compnaies to tackle the problem.

"No longer can a company compete with a few folks in the lab and a group of good programmers," wrote Eckelberry in a blog post. "They're out there: little companies with small teams working an anti-spyware or antivirus product, but it's hopeless. A small platoon won't win this war. You need a brigade."

Sentry Posts Blog

Sentry Posts Blog
Guarding the network

What you need to know — and what you and your peers have to tell us — about security management in our new community group blog

Read more +

Eckelberry quoted AV-Test.org statistics that he said showed "a good representation of the staggering load of malware that anti-malware folks are under". According to Eckelberry, the number of unique samples of malware, with variants, rose from 564 in 1986 to 5,490,960 in 2007. At the beginning of 2006, the number of unique samples of malware was still under a million, but this number had quintupled by the end of 2007.

While anti-malware processes can be automated, said Eckelberry, it is the non-automated processes that are being overwhelmed. For example, hunting down new malware, tracking IP addresses and the locations of potential malware users, reverse-engineering specialised code, creating signatures for difficult malware, and coding to deal with rootkits, all require some form of human interaction, said Eckelberry.

Mikko Hypponen, chief research officer for antivirus company F-Secure, agreed that the amount of malware is rising rapidly.

"The numbers are going through the roof," said Hypponen on Friday. "We're getting 17,000 samples [of malware] a day, and our database uses 30TB of hard-drive space. The job is getting harder and harder. Small companies will be overwhelmed unless they get really clever."

Hypponen said that small antivirus companies need to invest in automated technology that is capable of identifying individual cases of malware, as well as technologies that identify malware based on its behaviour.

"[Antivirus companies] still need virus-specific detection, combined with generic [behaviour-based] detection," said Hypponen. "F-Secure can handle that because we made a major investment in our backend systems three years ago."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
18 out of 18 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment

Campaigners criticise '£10bn NHS IT ov...

The National Health Service's flagship IT project has been criticised by a tax campaign group for running billions of pounds over budget. The NHS National Programme for IT (NPfIT)... More

2 comments


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters