12.07.2015 Views

Antivirus Myths and Facts - Commtouch

Antivirus Myths and Facts - Commtouch

Antivirus Myths and Facts - Commtouch

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Antivirus</strong> <strong>Myths</strong> <strong>and</strong> <strong>Facts</strong>\Myth: If an antivirus has flagged or blocked a file, this file isdefinitely malwareFact: While the goal of antivirus engines is of course to block files that contain malware, the reality isthat other types of files may be mistakenly blocked, even if they do not contain viruses or other threateningcode. A few incorrectly blocked files (aka “false positives”) are not necessarily a major cause for concern, butshould be taken into account when comparing antivirus engines (in addition to detection comparisons).Another type of non-malware file that may also trigger a malware indicationis “pseudo-malware.” This consists of “corrupted” malware, “garbage” files<strong>and</strong> “intended malware.”Garbage <strong>and</strong> corrupted files are generally the product of changes made tomalware code over the years due to h<strong>and</strong>ling by antivirus engines, incorrectfile replication, or other types of file manipulation. After decades of malwareh<strong>and</strong>ling, a vast number of files are distributed across the Internet containingparts of original malware. These modified files are generally inert <strong>and</strong> not ableto replicate or cause any damage, yet may trigger an antivirus which wouldthen flag it as malware.Intended malware files are those that may be released by malware authorsbefore they have been fully tested, <strong>and</strong> contain bugs which prevent themfrom “working” as they were intended.Pseudo-malware may appear during testing of antivirus solutions sincemany sites that maintain malware collections also contain these files.For this reason, many antivirus companies detect these files asmalware. On the other h<strong>and</strong>, some antivirus engines do not identifythese types of files as malware, since after all, there is no riskassociated with them.Since many vendors detect <strong>and</strong> flag pseudo-malware, there are oftensignificant differences of detection levels between various antivirusproducts. For example, in comparing two antivirus engines, one mayappear to detect many more viruses than another, but upon closeranalysis of the samples used in the test, it may become clear that the“viruses” the other engine “missed” were not actually harmful at all.Pseudo-malwarecan skew testresults dependingon the policies ofthe antivirusvendor.In other words, pseudo-malware can have an adverse effect on detection test results, causing a competentantivirus engine to perform badly, or a deficient antivirus engine to show very good test results, (withoutproviding very good real-world protection). For this reason it is not enough to simply compare the number ofviruses detected between antivirus engines.Page| 4blog.commtouch.comwww.commtouch.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!