McAfee CEO: Adware is killing antivirus blacklisting

By Liam Tung, ZDNet Australia
Monday, June 16, 2008 10:47 AM

Traditional security products--which employ signature-based blacklisting technology--are no longer effective because of a massive increase in malware, according to the CEO of McAfee, Dave De Walt.

Blacklisting--where vendors compile lists of known malware--has become technically unfeasible, said De Walt.

"When you're doubling the amount of malware you're getting on a daily basis, eventually a blacklisting model ultimately could run out of architectural scalability," he said at a press briefing today.

In 2007, McAfee received 370 new malware samples per day, and according to De Walt, that figure is likely to reach 750 per day by end of this year. "The current trend six months into [2008] is we're seeing a doubling of the malware we receive into our labs," he said.

The gloomy predictions are consistent with other security vendors. Symantec this year sid that 65 percent of the 54,609 Windows-based applications that have been released to the public in the past six months were malicious.

Chia Wing Fei, a security response team manager at F-Secure, told ZDNet Asia's sister site ZDNet Australia that in 2007, the company detected more than 500,000 pieces of malware. He expects that figure to double this year--for the second year running.

Late last year, antivirus testing company, AV-Test produced statistics showing the staggering growth of malware in the past year.

"This is a good representation of the staggering load of malware that anti-malware folks are under," said Alex Eckelberry, a security researcher for security vendor, Sunbelt Software in response to the statistics. "Like most companies, weÂ’re processing gigabytes of malware daily."

McAfee's De Walt said he was shocked by the pace of growth.

"This was a shocker to me to see at McAfee just what we face in the world. In 2007, 40 percent of all malware was written that year," he said.

However, De Walt blames online marketing companies for much of the escalation.

"A lot of it's coming from the growing adware market, which is a legitimate market... Literally billions of dollars are being put into figuring out ways to market more intelligently to you...in a more personalized way. That's driven malware development.

"Marketing companies often contract companies to figure out ingenious ways to put a brand on your device, and that same ingenious way to put a brand on your device is what potentially the bad guys and gals can do to exploit your computer--either through data theft, data loss, identity theft or some sort of phishing attack," he said.

As blacklisting becomes increasingly difficult, De Walt said whitelisting technologies hold promise.

"Whitelisting looks like it has an architectural promise that could be very strong," he said.

Whitelisting was a dominant topic at this year's AusCERT conference. Cisco's chief security officer expressed frustration at blacklisting, and said he would like to see more whitelisting. "Antivirus should be an integral part of how you clean content, and keep it safe, however as a first line of defense, I just don't see it anymore," Stewart told ZDNet Australia.

AusCERT general manager Graham Ingram backed Stewart up. "I think [whitelists] are a natural progression... I think the realization [is] that blacklisting only had a limited life and we're getting towards the end of that," said Ingram.

However, De Walt has reservations about its adoption due to cultural factors.

"The cultural adoption of it has been the challenge. Because what is whitelisting? You can only use seven products on your machine, you're not allowed to use another product on your machine. I lock down your environment, according to a whitelist and I prevent software moving onto that computer, unless I grant that access to that application," he said.

"The cultural aspects are, I'd really like to use iTunes, or the latest peer to peer music sharing product. That prevents that. It also keeps it safe, but at the same time, it's culturally inhibiting in the way people like to work with their machines."


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Common ways IT wastes money on development

Web Development

Examples include using developers as support staff and failing to calculate a project's ROI before giving it the go-ahead.


Read more »



  • Enterprise 2.0

    Vince Casarez, vice president of product management at Oracle, explains how Web 2.0 technologies, such as tags, wikis, and mash-ups, can be applied within an organization.
    Play video


  • Nehalem Architecture

    What makes next-generation Intel® Microarchitecture (Nehalem) such a superior successor?
    Play video

 
Free the untapped potential of your IT infrastructure
Reduce bottlenecks to drive the efficiency and productivity of Business IT.
» Ultimate virtualization blade
» Scalable SAN solution
» Accelerate service delivery
On demand CRM goes strategic
CRM technology has come of age, and is now able to align with your customer strategy and grow in step with your business.

» Learn more about Oracle’s CRM Solutions




Could this be the most critical budget for India?

Blog thumbnail

For business journalists in India, budget time is excitement time. It's like sports journos covering the Olympics. As a newspaper correspondent, I too had my fill of budget-time excitement. But..... by Swati Prasad

Read more »

Tags

  1. attack
  2. bank
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. u.s.
  19. viruses and worms
  20. web