Hackers winning cat-and-mouse game with antivirus programmers

CoreTrace WhiteSpace

The Application Whitelisting and Security Weblog

Hackers winning cat-and-mouse game with antivirus programmers

Ever since malware writers swapped worldwide infamy for hefty profits, they’ve become a larger problem to deal with. And as the game of cat-and-mouse with antivirus software programmers continues, hackers remain one step ahead of their chief nemesis.

In the article, “‘Viruses Are Winning’: Malware Threat Outpaces Antivirus Software,” not only has malware gotten stealthier, it’s multiplied in variety and volume at an unmanageable rate. According to Sean-Paul Correll, a threat researcher at Panda Security, in 2006 the growth in malware samples were doubling year-after-year. By 2009, that number jumped to 25 million new strains, more than the previous 20 years combined. Through July 2010, the number has grown to 46.6 million malware samples, nearly 100% growth over last year, with 5 months remaining.

While antivirus security companies have responded with new technologies to detect more sophisticated attacks, security experts such as Golden Richard III, a professor of computer science at the University of New Orleans, say antivirus software programmers are losing the battle.

“The viruses are winning because the defenses don’t work very well. It’s much harder to be on defense. And the offensive guys are really smart, they’ve got a lot of resources. It’s a bleak situation.”

Modern malware uses many different ways to conceal itself from the most advanced antivirus software, which only detects 40-70% of infections, said Danny Quist, a malware specialist at Offensive Computing, LLC. The most recent example is the latest incarnation of the Stuxnet worm, which uses techniques to evade antivirus detection and install itself on Windows systems to access SCADA environments. The good news for networks protected by CoreTrace’s BOUNCER application whitelisting solution, they don’t have to play the cat-and-mouse game with enhanced malware specifically designed to defeat virus scanners.

If you would like to read an independant view on our new version, BOUNCER 6.0, check out what Enterprise Management Associates (EMA had to say about the enhancements in their Impact Brief,“Taking Adaptive Application Whitelisting to the Next Level: CoreTrace Introduces BOUNCER 6.0.”

If you enjoyed this article, subscribe to the WhiteSpace RSS feed or to receive new content via email.