{"id":4022,"date":"2016-07-14T21:32:18","date_gmt":"2016-07-14T21:32:18","guid":{"rendered":"https:\/\/really.zonky.org\/?p=4022"},"modified":"2016-07-14T21:32:18","modified_gmt":"2016-07-14T21:32:18","slug":"anti-virus-is-dead-long-live-behavioural-analysis","status":"publish","type":"post","link":"https:\/\/really.zonky.org\/?p=4022","title":{"rendered":"Anti-Virus Is Dead. Long-Live Behavioural Analysis &#8230;"},"content":{"rendered":"<p>One of the throw-away statistics I tripped over recently was that there are 5 new malware releases <em>every second<\/em>.\u00a0 Now many of those new releases are variations on a theme &#8211; there are pieces of software designed to distort a piece of malware into a new piece of malware with the same functionality. This is done deliberately to evade anti-virus software.<\/p>\n<p>And it works. Every so often I feed some strange mail attachments into <a href=\"https:\/\/www.virustotal.com\/\">virustotal<\/a> to find out how widely it is recognised. It is not uncommon to find that only 2-3 will recognise it as malware out of 50-odd virus checkers on that site. So if you happen to be dumb enough to download and activate the attachment, your anti-virus checker has a roughly 5% chance of protecting you.<\/p>\n<p>Not exactly what you should expect.<\/p>\n<p>I recently sat through a sales pitch for a not-so-new corporate product that does anti-malware protection very differently. Of course it is also insanely expensive, so I will not mention the actual product, but it does offer something new. Protection against malware by checking and blocking\u00a0<em>behaviour<\/em>.<\/p>\n<p>Whilst they add all sorts of clever data analysis tricks, fundamentally anti-virus products recognise malware because they recognise the data that makes up the malware. If they don&#8217;t recognise the signature of the malware, then they do not know it is malware; so they have an incredibly difficult time recognising new malware releases.<\/p>\n<p>But recognising malware based on behaviour is far more likely to successfully recognise malware &#8211; for example by recognising an attempt to make itself persistent in a way that an ordinary application does not do, and blocking it. Which is a far more practicable method of blocking malware (if it works!).<\/p>\n<p>It is also something that should probably be built into operating systems, which to a certain extent <a href=\"https:\/\/en.wikipedia.org\/wiki\/AppArmor\">already has been<\/a>.<\/p>\n<div id=\"attachment_4157\" style=\"width: 650px\" class=\"wp-caption aligncenter\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-4157\" class=\"size-full wp-image-4157\" src=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2016-04-02-the-new-defence-s..jpg?resize=640%2C427&#038;ssl=1\" alt=\"The New Defence\" width=\"640\" height=\"427\" srcset=\"https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2016-04-02-the-new-defence-s..jpg?w=640&amp;ssl=1 640w, https:\/\/i0.wp.com\/really.zonky.org\/wp-content\/uploads\/2016-04-02-the-new-defence-s..jpg?resize=300%2C200&amp;ssl=1 300w\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" \/><p id=\"caption-attachment-4157\" class=\"wp-caption-text\">The New Defence<\/p><\/div>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of the throw-away statistics I tripped over recently was that there are 5 new malware releases every second.\u00a0 Now many of those new releases are variations on a theme &#8211; there are pieces of software designed to distort a piece of malware into a new piece of malware with the same functionality. This is <a href='https:\/\/really.zonky.org\/?p=4022' class='excerpt-more'>[&#8230;]<\/a><\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false,"_share_on_mastodon":"0"},"categories":[4,489],"tags":[869,1430,817],"class_list":["post-4022","post","type-post","status-publish","format-standard","hentry","category-it","category-security","tag-anti-virus","tag-apparmor","tag-malware","category-4-id","category-489-id","post-seq-1","post-parity-odd","meta-position-corners","fix"],"share_on_mastodon":{"url":"","error":""},"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p1f2KI-12S","_links":{"self":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/4022","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4022"}],"version-history":[{"count":4,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/4022\/revisions"}],"predecessor-version":[{"id":4207,"href":"https:\/\/really.zonky.org\/index.php?rest_route=\/wp\/v2\/posts\/4022\/revisions\/4207"}],"wp:attachment":[{"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4022"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4022"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/really.zonky.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4022"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}