Eighty percent of new malware defeats antivirus

Found on ZDNet on Friday, 21 July 2006
Browse Computer

At a security breakfast hosted by e-mail security firm Messagelabs in Sydney on Wednesday, the general manager of the Australian Computer Emergency Response Team (AusCERT), Graham Ingram, told the audience that popular desktop antivirus applications "don't work".

"At the point we see it as a CERT, which is very early on -- the most popular brands of antivirus on the market … have an 80 percent miss rate. That is not a detection rate that is a miss rate."

"I am not suggesting that there is a difference in the quality of the antivirus products themselves. What is happening is that the bad guys, the criminals, are testing their malicious code against the antivirus products to make sure they are undetectable. This is not a representation of the software," said Ingram.

According to Gartner, the top three are Symantec, McAfee and Trend Micro with a total market share of more than 86%. Relying on those obviously doesn't protect you at all. With a 90% hit rate, Kaspersky on the other hand is one of the weapons of choice. So you better rely on two smaller scanners instead of trusting the market leaders. Why Symantec is the most used application is strange enough; on every system I saw it running, it caused problems and ate more resources than a simple scanner should.