- Markus Breitenbach - http://blog.markus-breitenbach.com -
ISC on the Future of Anti-Virus Protection
Posted By Markus On August 1, 2008 10:25 pm @ 10:25 pm (August 1, 2008) In Classification, Machine Learning, Artificial Intelligence (AI), Security | 2 Comments
An article on the [1] Internet Storm Center discusses wether Anti-Virus software in the current state is a dead end. In my opinion it has been dead for quite a while now. Apart from the absolutely un-usable state that anti-virus software is in, I think it’s protecting the wrong things. Most attacks (trojans, spyware) nowadays come through web-browser exploits and maybe instant-messenger (see reports on ISC). So instead of scanning incoming emails, how about a behavior blocker for the web-browser and the instant messenger? There are a couple of freeware programs (e.g. [2] IEController [German]) out there that successfully put Internet Explorer, etc. into a sandbox; whatever Javascript exploit - known or unknown - the browser won’t be able to execute arbitrary files or write outside its cache-directory. Why is there nothing like that in the commercial AV packages?
However, a few possibilities suggested in the article might be worth exploring. For example, they suggest Bayesian heuristics to identify threats. Using machine learning techniques might be a direction worth exploring. IBM AntiVirus (maybe not the current version anymore) has been using Neural Networks with 4Byte sequences (n-grams) for bootsector virus detection.
A couple things to keep in mind, though:
Article printed from Markus Breitenbach: http://blog.markus-breitenbach.com
URL to article: http://blog.markus-breitenbach.com/2008/08/01/isc-on-the-future-of-anti-virus-protection/
URLs in this post:
[1] Internet Storm Center discusses wether Anti-Virus software: http://isc.sans.org/diary.html?storyid=4808
[2] IEController: http://www.heise.de/ct/projekte/iecontroller/
[3] Mimedefang: http://www.mimedefang.org/
[4] impsec: http://impsec.org/email-tools/procmail-security.html
Click here to print.