<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: Antivirus Getting Dumber?</title>
	<atom:link href="http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/</link>
	<description>Bringing Fire To The Village: Your Source For Computer, Network &#38; Information Security News from Dave Lewis, Security Blogger</description>
	<pubDate>Thu, 28 Aug 2008 08:04:45 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.1</generator>
		<item>
		<title>By: Dave Lewis</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-68022</link>
		<dc:creator>Dave Lewis</dc:creator>
		<pubDate>Wed, 06 Feb 2008 17:01:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-68022</guid>
		<description>@Ilya

Sorry mate. I was up to my eyeballs. Thanks for the comment.</description>
		<content:encoded><![CDATA[<p>@Ilya</p>
<p>Sorry mate. I was up to my eyeballs. Thanks for the comment.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Rabinovich</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67974</link>
		<dc:creator>Ilya Rabinovich</dc:creator>
		<pubDate>Thu, 31 Jan 2008 15:56:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67974</guid>
		<description>Ah, silence. Lets then think it means "yep, right here, bro!".

First of all, it is very important to understand that current anti-virus scanners are working with already known malware. But, if malware module is caught, the revenue rate for "bad guys" is getting down, that is why it is very important for them to do not allow AVers to be up-to-date. There are many methods to do that- constant module updation, rootkits, DDOS of the anti-virus labs with the thousands of the samples per day. Heuristic mechanisms are working good for already known bypass methods of it, but a new one comes every single day. That is why you think that scanners are getting dumber. It is more and more obvious that those blacklisting technologies are out-to-date, they are more and more useless.

Behavioural technologies can't cure malware in common case (yes, there are some blacklisting HIPS like AntiBot, but I see no difference if some tool is using code or behavioural signatures- false positives and false negatives is their destiny), but may gives you a really high, honest 90-95% of malware prevention against any kind of it, known and unknown, with no misses. So, why to loose couple of hours with HijackThis, AVZ and anti-rootkit tools if malware prevention is much more obvious and simple thing? Yes, right now it is "out of box", not something you used to use, but its time is coming... Resistance is useless, join people who already lives with only behavioural protections and never being infected!</description>
		<content:encoded><![CDATA[<p>Ah, silence. Lets then think it means &#8220;yep, right here, bro!&#8221;.</p>
<p>First of all, it is very important to understand that current anti-virus scanners are working with already known malware. But, if malware module is caught, the revenue rate for &#8220;bad guys&#8221; is getting down, that is why it is very important for them to do not allow AVers to be up-to-date. There are many methods to do that- constant module updation, rootkits, DDOS of the anti-virus labs with the thousands of the samples per day. Heuristic mechanisms are working good for already known bypass methods of it, but a new one comes every single day. That is why you think that scanners are getting dumber. It is more and more obvious that those blacklisting technologies are out-to-date, they are more and more useless.</p>
<p>Behavioural technologies can&#8217;t cure malware in common case (yes, there are some blacklisting HIPS like AntiBot, but I see no difference if some tool is using code or behavioural signatures- false positives and false negatives is their destiny), but may gives you a really high, honest 90-95% of malware prevention against any kind of it, known and unknown, with no misses. So, why to loose couple of hours with HijackThis, AVZ and anti-rootkit tools if malware prevention is much more obvious and simple thing? Yes, right now it is &#8220;out of box&#8221;, not something you used to use, but its time is coming&#8230; Resistance is useless, join people who already lives with only behavioural protections and never being infected!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Rabinovich</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67970</link>
		<dc:creator>Ilya Rabinovich</dc:creator>
		<pubDate>Wed, 30 Jan 2008 19:58:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67970</guid>
		<description>Right here, in comments?</description>
		<content:encoded><![CDATA[<p>Right here, in comments?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Lewis</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67966</link>
		<dc:creator>Dave Lewis</dc:creator>
		<pubDate>Wed, 30 Jan 2008 12:49:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67966</guid>
		<description>@Ilya

Ha! Yes, I know. As long as you add a disclaimer its all good. 

:)</description>
		<content:encoded><![CDATA[<p>@Ilya</p>
<p>Ha! Yes, I know. As long as you add a disclaimer its all good. </p>
<p> <img src='http://www.liquidmatrix.org/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Rabinovich</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67965</link>
		<dc:creator>Ilya Rabinovich</dc:creator>
		<pubDate>Wed, 30 Jan 2008 12:18:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67965</guid>
		<description>Dave, if you think it is ethical for me as a anti-malware behavioural protection developer- yes, I can. Without advertisement, naturally...</description>
		<content:encoded><![CDATA[<p>Dave, if you think it is ethical for me as a anti-malware behavioural protection developer- yes, I can. Without advertisement, naturally&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dave Lewis</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67959</link>
		<dc:creator>Dave Lewis</dc:creator>
		<pubDate>Tue, 29 Jan 2008 17:01:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67959</guid>
		<description>@Ilya

Fair point. Care to elaborate?</description>
		<content:encoded><![CDATA[<p>@Ilya</p>
<p>Fair point. Care to elaborate?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ilya Rabinovich</title>
		<link>http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67957</link>
		<dc:creator>Ilya Rabinovich</dc:creator>
		<pubDate>Tue, 29 Jan 2008 16:32:33 +0000</pubDate>
		<guid isPermaLink="false">http://www.liquidmatrix.org/blog/2008/01/28/antivirus-getting-dumber/#comment-67957</guid>
		<description>Why to use malware detection clents if malware prevention ones are much better?</description>
		<content:encoded><![CDATA[<p>Why to use malware detection clents if malware prevention ones are much better?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
