On TechRepublic: Windows 7: Slower to boot than Vista?
BNET Business Network:
BNET
TechRepublic
ZDNet

July 14th, 2009

Does free antivirus offer a false feeling of security?

Posted by Dancho Danchev @ 2:08 am

Categories: Anti Virus, Botnets, Browsers, Hackers, Malware, Symantec

Tags: Antivirus, Antivirus Scanner, Viruses And Worms, Security, Dancho Danchev

Earlier this month, Symantec’s product manager David Hall dismissed free security software as equal alternative to the paid versions, and also described  Microsoft’s free “Microsoft Security Essentials” as “a stripped down version of the OneCare product Microsoft pulled from retail shelves“.

Needless to  say that such statements from a competing vendor often come as a direct frontal attack against the alternative solution, however, they also fuel the debate on whether or not free antivirus offers a false feeling of security.

The answer? Let the data, and a bit of a common sense speak for itself.

Antivirus software is not the solution, antivirus software is part of the (defense in-depth) solution

Consider the results from the latest Anti-Virus comparative review for May 2009 against new malware, indicating that Microsoft’s OneCare achieved an Advanced+ rating (60% detection), putting it on the second position, with Symantec achieving a mere 35% detection rate — ironically a huge percentage of AV-Comparative’s visitors are running free antivirus software according to their voting poll.

Moreover, similar results can be seen in Virus Bulletin’s comparative review for April, 2009 (subscribers only), where OneCare once again outperforms Symantec.

Does this mean that free antivirus is in fact outperforming commercial applications? Given the dynamic nature of today’s threats, what’s true for a particular moment in time can become totally irrelevant at a future date. For instance, some real-time time statistics on antivirus rankings have the potential to offer an entirely different comparative view — free antivirus scanners again rank pretty well — which shouldn’t be considered as the primary benchmark when attempting to answer whether or not free antivirus offers a false feeling of security.

Both, commercial and free stand-alone antivirus scanners suffer from a similar weakness - they’re over-positioned in the mind of the average Internet user. This over-positioning results in higher expectations which on the other hand results in lack of security awareness on what an antivirus scanner can, and cannot protect against (Secunia: popular security suites failing to block exploits).

Cybercriminals have been tricking signature based scanning engines for years, and their quality assurance practices are becoming even more professional and automated through the user of underground versions of popular community services such as VirusTotal, or by using multiple offline virus scanning engines before a campaign is launched. Similar services attempting to verify whether or not their malware sample will bypass popular personal firewalls are also known to be available on demand.

Therefore, fighting the battle on the signature scanning front isn’t exactly the wisest choice. This is where the stand-alone antivirus, a free or commercial version of it, becomes part of the defense in-depth solution.

Through a combination of a fully patched operating system running the latest versions of the software installed (Secunia: Average insecure program per PC rate remains high), least privilege accounts (Report: 92% of critical Microsoft vulnerabilities mitigated by Least Privilege accounts) and a well-configured personal firewall (Matousec’s Proactive Security Challenge), a huge percentage of the malware pushed through client-side exploits may in fact never reach the antivirus scanner.

That’s of course only if you exclude the fact that “there’s no patch for human stupidity” in the sense that social engineering in the form of fake codecs/videos and poisoned search results continue tricking users into on purposely disabling the security solutions that they had at the first place.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 55 Talkback(s)
I'd bet your long experience...
taught you to use Avast's real time protection, and AVG's non-resident scanner.

I imagine folks don't know they can have more than one AV on board as long as only one is resident.(real-time protection enabled - for any newbies who happen to be reading this)... (Read the rest)
Posted by: JCitizen Posted on: 11/25/09 You are currently: a Guest | | Terms of Use
No it does not...  NoThomas | 07/14/09
No it does not...  neverhome | 07/15/09
I've even been able to run...  JCitizen | 11/07/09
ALL AV offers a false sense of security  ejhonda | 07/14/09
Most definitely... *NEW*  JCitizen | 11/25/09
That list looks familiar. *NEW*  ye | 07/14/09
RE: Does free antivirus offer a false feeling of security? *NEW*  GameOvR | 07/14/09
Remember this comes from Symantec... *NEW*  Joe_Raby | 07/14/09
That really chaps my... *NEW*  JCitizen | 11/25/09
RE: Does free antivirus offer a false feeling of security? *NEW*  tealcat | 07/14/09
To Who(m)? *NEW*  vermonter | 11/06/09
RE: Does free antivirus offer a false feeling of security? *NEW*  phatkat | 07/14/09
You should read recent reviews *NEW*  Joe_Raby | 07/14/09
OneCare helped topple resource hungry, expensive AV *NEW*  Patanjali | 07/15/09
Agreed *NEW*  Joe_Raby | 07/15/09
Very true!.... *NEW*  JCitizen | 08/01/09
I run a computer service shop, and... *NEW*  cryptikonline | 07/14/09
Infected MP3's *NEW*  Joe_Raby | 07/14/09
More than 20 to 30,000 legitimate web sites... *NEW*  JCitizen | 07/21/09
On Firewalls *NEW*  voska1 | 11/13/09
Actually on topic.. *NEW*  JCitizen | 11/25/09
One more thing I forgot... *NEW*  cryptikonline | 07/14/09
RE: Does free antivirus offer a false feeling of security? *NEW*  Smoothtopper | 07/15/09
I totally agree... *NEW*  JCitizen | 07/22/09
RE: Does free antivirus offer a false feeling of security? *NEW*  cryptikonline | 07/15/09
RE: Does free antivirus offer a false feeling of security? *NEW*  az22nz@... | 07/15/09
I'd bet your long experience... *NEW*  JCitizen | 11/25/09
Normal use vs Security *NEW*  Tom6 | 07/16/09
Offer rejected *NEW*  Tom6 | 07/16/09
What BLATANT misinformation!! *NEW*  kaninelupus | 07/16/09
Counter measures against antivirus lol *NEW*  Tom6 | 07/16/09
Not blatant!... *NEW*  JCitizen | 07/22/09
RE: Does free antivirus offer a false feeling of security? *NEW*  bonnielou432 | 07/16/09
First, post your specs.. *NEW*  JCitizen | 07/22/09
RE: Does free antivirus offer a false feeling of security? *NEW*  bgfores | 07/16/09
Using ONLY free anti-virus is dangerous.. *NEW*  JCitizen | 07/21/09
No more free solutions for me.. *NEW*  janiesmiling | 07/28/09
Free Solutions Fine for Me *NEW*  blegs38552@... | 07/30/09
I didn't trust NIS 2009 at first... *NEW*  JCitizen | 08/01/09
BitDefender is pretty good... *NEW*  JCitizen | 08/01/09
Symantec Products are Compromised Regularly *NEW*  pc_techs_ct@... | 08/04/09
Sounds good to me.. *NEW*  JCitizen | 08/05/09
All A/V software leads to a false sense of security. *NEW*  ye | 11/05/09
This includes not so free AV.. *NEW*  JCitizen | 11/06/09
every AV offer a false sense of security *NEW*  ljenux-23043766007667558234416105604265 | 11/06/09
No one antivirus catches all malware *NEW*  Pyrotech_z | 11/06/09
MSE is an anti-virus solution.. *NEW*  JCitizen | 11/07/09
That is why we use 3 different types *NEW*  voska1 | 11/13/09
RE: Does free antivirus offer a false feeling of security? *NEW*  The Admiral | 11/06/09
That's what I ask my clients!... *NEW*  JCitizen | 11/07/09
RE: Does free antivirus offer a false feeling of security? *NEW*  The Admiral | 11/06/09
RE: Does free antivirus offer a false feeling of security? *NEW*  brendalyn | 11/24/09
This is the use... *NEW*  JCitizen | 11/25/09
RE: Does free antivirus offer a false feeling of security? *NEW*  brendalyn | 11/24/09
Only if it is not implemented properly... *NEW*  JCitizen | 11/25/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here