Wilders Security Forums  

Go Back   Wilders Security Forums > Security Products > other anti-virus software
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old June 3rd, 2009, 05:02 PM
Derek0027 Derek0027 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 3
Default Real-time Protection

Hello,

Does anyone know why new (undetected) malware is able to slip by most anti-virus real-time protection?
  #2  
Old June 3rd, 2009, 08:46 PM
larryb52's Avatar
larryb52 larryb52 is offline
Very Frequent Poster
 
Join Date: Feb 2006
Posts: 1,109
Default Re: Real-time Protection

because they do & can, nothing is 100% perfect...
__________________
Larry
  #3  
Old June 3rd, 2009, 09:20 PM
Peter2150's Avatar
Peter2150 Peter2150 is offline
Global Moderator
 
Join Date: Sep 2003
Posts: 11,844
Default Re: Real-time Protection

Quote:
Originally Posted by Derek0027
Hello,

Does anyone know why new (undetected) malware is able to slip by most anti-virus real-time protection?

Because until the AV companies get it and add signature, they can't detect it.
  #4  
Old June 3rd, 2009, 10:06 PM
Derek0027 Derek0027 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 3
Default Re: Real-time Protection

Quote:
Because until the AV companies get it and add signature, they can't detect it.
So the protection modules don't have the ability to recognize unknown malware files by themselves? That seems very risky. How can I protect my system if the AV can't analyze an unknown malicious file?
  #5  
Old June 4th, 2009, 12:31 AM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: Real-time Protection

Quote:
Originally Posted by Derek0027
So the protection modules don't have the ability to recognize unknown malware files by themselves? That seems very risky. How can I protect my system if the AV can't analyze an unknown malicious file?
Most AVs have heuristics, which enable them to detect many (not all) of the malwares for which they do not yet have signatures.

In addition to using AVs, some users (myself included) also use HIPS applications, such as Mamutu (a behavior blocker) and Malware Defender (a "classical"), which can further alert users to malware which gets by their AV.

However, IMO the "ultimate protection" is to periodically image your system drive.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #7  
Old June 4th, 2009, 08:14 AM
andyman35 andyman35 is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 2,288
Default Re: Real-time Protection

Quote:
Originally Posted by Derek0027
So the protection modules don't have the ability to recognize unknown malware files by themselves? That seems very risky. How can I protect my system if the AV can't analyze an unknown malicious file?
That's why many users here adopt a default deny policy based on whitelisting,whereby only known good executables are allowed to run and everything else is treated with suspicion.
  #8  
Old June 4th, 2009, 09:02 AM
twl845's Avatar
twl845 twl845 is offline
Massive Poster
 
Join Date: Apr 2005
Location: USA
Posts: 3,402
Default Re: Real-time Protection

This is why apps like Returnil and Shadow Defender, not to forget Sandboxie are superior for prevention.
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Macrium Reflect Standard, AX64 Time Machine
  #9  
Old June 4th, 2009, 10:18 AM
Derek0027 Derek0027 is offline
Infrequent Poster
 
Join Date: Jun 2009
Posts: 3
Default Re: Real-time Protection

Based on your comments, it sounds like an AV is not enough anymore by itself no matter what brand it is. I wonder why it is still the dominent method in determining if a file is rogue. For example, there are many virus upload sites like VirusTotal that use several name brand AV programs that scan the file(s) for recognition. Sometimes you'll see 2 or 3 that detect, other times more, other times zero. It seems that this is still the security model being used to find out if a file is bad.
  #10  
Old June 4th, 2009, 10:31 AM
TonyW TonyW is offline
Very Frequent Poster
 
Join Date: Oct 2005
Location: UK
Posts: 2,309
Default Re: Real-time Protection

Quote:
Originally Posted by Derek0027
It seems that this is still the security model being used to find out if a file is bad.
It's not the only method, but you have to remember scanning sites like virustotal often use older scanning engines and cannot be compared to having the actual product installed on your system which will use newer scanning engines and incorporate other technologies too.
  #11  
Old June 4th, 2009, 07:19 PM
Fly Fly is offline
Very Frequent Poster
 
Join Date: Nov 2007
Posts: 1,876
Default Re: Real-time Protection

Quote:
Originally Posted by Derek0027
Hello,

Does anyone know why new (undetected) malware is able to slip by most anti-virus real-time protection?

Maybe this will give you some insight ?

http://www.eset.com/download/whitepa...c_Analysis.pdf
 

Wilders Security Forums > Security Products > other anti-virus software « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 12:55 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums