Computerworld
McAfee sees 400,000 virus definitions by 2008
McAfee now has 200,000 definitions in its antivirus database. It expects this number to double in two years.
Robert McMillan (IDG News Service)  06 July, 2006 11:46

Although widespread virus outbreaks may be a thing of the past, the total amount of malicious software being written is on the rise, according to McAfee.

On Tuesday, McAfee vendor added the 200,000th definition to its threat database, and the security vendor expects the total number of identified threats to double in another two years. McAfee's antivirus products use these definitions as digital fingerprints to determine which software should not be allowed to run on a user's PC.

After a bit of a lull in their efforts, virus writers have spent the past few years creating more of this software than ever before, said Jimmy Kuo, a research fellow with McAfee's Avert Labs.

Between 1999 and 2002, when McAfee's database held steady at around 50,000 definitions, but since then, the number of different worms and viruses being created has jumped, he said.

At the same time, the number of serious outbreaks has dropped dramatically. In 2004, McAfee counted 48 virus outbreaks of at least medium severity. In 2005, that number dropped to 12. This year there haven't been any.

These trends reflect the growth and increasing professionalization of hacker culture that no longer seeks the fame that accompanies a worldwide virus outbreak. Instead of fame, hackers want money, Kuo said.

"There are now hackers for hire in spamming and phishing campaigns and they're in it to work," he said. "When you create a big incident... the police react and they go searching for you," he added. "So the bad guys don't create these incidents anymore."

McAfee may be bragging that it has discovered a large number of virus definitions, but there's a down side to all of this good work: sluggish computers.

There are now more antivirus signatures than there are files on a typical PC, according to Andrew Jaquith, a senior analyst at the Yankee Group. "Collectively the industry is creaking under the load of all of it," he said.

With its 200,000 definitions, McAfee's software is going to cause some trouble on some PCs, Kuo admitted. "For those companies that still have really old machines, they basically stop updating their dat [virus definition] files after a while," he said. "If you run it on a 1998-style machine, it's not going to run very well at all."

But even if newer "behavior-based" antivirus techniques begin to take a front seat in identifying viruses, definitions will not go away because they serve an important role in cleaning up systems that have already been compromised, Kuo said. "In terms of preventing you might lean more upon behavior-based [techniques]" he said. "But after you've been hit by something you're going to want to go to definitions."

Kuo's blog posting on the 200,000th virus definition can be found here: http://www.avertlabs.com/research/blog/?p=49

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Keeping your SQL Server Going 24x7

The SQL Server is the vital link between corporate data and enterprise applications. With compliance and regulatory implications, as well as business disruption, keeping data up-to-date and flowing 24x7 has to be the goal. Keep your SQL server going - read more now.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.