HomeSecurityAntivirus programs are slow to find real threats

Antivirus programs are slow to find real threats

Antivirus

Detecting malware with classic programs is probably a less than adequate approach to the issue, especially in corporate environments, since antivirus software takes months to adopt the necessary routines to identify some of the most complex threats.

A study by Damballa, a security company that provides solutions against the most advanced cyber threats, revealed that malware could exist on a system for six months before being detected, if the system uses a signature-based detection method.

In a period of nine months, the researchers analyzed a set of samples from thousands of files they took from corporate clients and ran them for detection with four of the most popular antivirus protection products currently on the market.

The company found that in the first hour, only 30% of the malicious software data could be identified by the products as a threat. After one day, the detection rate increased to 66% and the improvement continued after a week, when 72% of the malicious data indicators had now been recognized as a threat.

The researchers systematically re-scanned the files to see the time it takes for antivirus developers to add the correct data to the database

One month later, 93% of the samples were identified as malicious. The longer the malware remains in a system, the higher the chances that the attackers managed to reach sensitive areas of the system. According to Damballa, 100% of the detection was achieved after six months.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS