{"id":10137,"date":"2017-10-27T06:10:03","date_gmt":"2017-10-27T14:10:03","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/10\/27\/news-3910\/"},"modified":"2017-10-27T06:10:03","modified_gmt":"2017-10-27T14:10:03","slug":"news-3910","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/10\/27\/news-3910\/","title":{"rendered":"Traditional AV solutions shown ineffective in real-time global heat map"},"content":{"rendered":"<p><strong>Credit to Author: Marcin Kleczynski| Date: Fri, 27 Oct 2017 07:01:46 +0000<\/strong><\/p>\n<p>It&#8217;s no secret that antivirus technology (AV) has faced increased scrutiny in the tech industry for quite some time. With signature-based detection methods, <a href=\"https:\/\/press.malwarebytes.com\/2017\/10\/26\/new-research-traditional-antivirus-failed-protect-nearly-40-percent-users-using-two-av-solutions-malware-attacks\/?utm_source=blog&amp;utm_medium=social\" target=\"_blank\" rel=\"noopener\">traditional AV solutions are simply weak<\/a> against unknown malware and other malicious content. Meanwhile, consumers and businesses continue to trust AV solutions to protect their devices. So, how ineffective are they and what\u2019s the risk to users?<\/p>\n<p>\u201cTesting\u201d of AV platforms has become increasingly popular as a multitude of solutions, based on the same core technologies, have flooded the market. Those that perform well under these parameters tout the results as a stamp of approval. However, the true value of these tests is yet to be determined, as malware in the wild behaves in a manner significantly different from laboratory samples \u2013 even recently captured samples apprehended in security honeypots.<\/p>\n<p>However, one way to truly gauge the effectiveness of today\u2019s traditional AV solutions is by analyzing <strong>real-world data<\/strong>. So, <a href=\"http:\/\/www.malwarebytes.com\/remediationmap\" target=\"_blank\" rel=\"noopener\">we did just that<\/a>.<\/p>\n<p>To better understand the inherent flaws with traditional AV technology and to cast an eye onto the problem globally, we pulled data from <a href=\"http:\/\/www.malwarebytes.com\/remediationmap\" target=\"_blank\" rel=\"noopener\">real-world scans<\/a> running one or more traditional AV tools registered on Windows\u00ae Security Center. We looked at instances where Malwarebytes was used solely for remediation and excluded data where Malwarebytes proactively blocked threats. This data excluded PUPs (potentially unwanted programs).<\/p>\n<p>We found that in the US, nearly 40 percent of all malware attacks cleaned by Malwarebytes on endpoints with an AV installed occurred on endpoints that had two or more of these traditional AV solutions registered.<\/p>\n<p>What does this mean from a global perspective? We learned that AV is not necessarily the silver bullet. A combination of remediation and protection is sorely needed. What we found might surprise you. In just the month of October, there were <strong>about <em>4 million<\/em> instances where traditional AV was ineffective against today\u2019s threats. <\/strong><\/p>\n<p style=\"text-align: center\"><strong>Screenshot from real-time heat map showing global detections in October<\/strong><\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Mapping-AV-Failures-Screen-Shot-10-25-17-DA2.png\" data-rel=\"lightbox-0\" title=\"\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-20307 size-full\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Mapping-AV-Failures-Screen-Shot-10-25-17-DA2.png\" alt=\"Mapping AV Failures Screen Shot 10-25-17 DA2\" width=\"750\" height=\"874\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Mapping-AV-Failures-Screen-Shot-10-25-17-DA2.png 750w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Mapping-AV-Failures-Screen-Shot-10-25-17-DA2-257x300.png 257w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Mapping-AV-Failures-Screen-Shot-10-25-17-DA2-515x600.png 515w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>We also created a real-time heat map looking at global malware detections around the globe as they happen, <a href=\"http:\/\/www.malwarebytes.com\/remediationmap\" target=\"_blank\" rel=\"noopener\">www.malwarebytes.com\/remediationmap<\/a>.<\/p>\n<p>For a dot to appear on the real-time maps, three things must happen:<\/p>\n<ol>\n<li>A device has a third-party antivirus registered on Windows\u00ae Security Center.<\/li>\n<li>A Malwarebytes remediation scan is run.<\/li>\n<li>The scan must detect malware.<\/li>\n<\/ol>\n<p>Malwarebytes then adds a numerical count for each detection next to the respective vendor\u2019s name. These elements represent Malwarebytes real-time global view of the threats detected by the remediation scans. Each dot represents a detection and there can be multiple detections for each dot.<\/p>\n<p>The results of our global analysis show the ineffectiveness of today\u2019s traditional AV solutions. The worst part is that many businesses and users have no idea that their traditional AV programs aren\u2019t doing their job. This can have devastating consequences at work and at home. Trusting traditional AV alone is a losing proposition for individuals and businesses looking to protect their data from today\u2019s modern threats. The path to a stronger solution for users must be a combination of both remediation and protection.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/ceo-announcements\/2017\/10\/traditional-av-solutions-shown-ineffective-real-time-global-heat-map\/\">Traditional AV solutions shown ineffective in real-time global heat map<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/ceo-announcements\/2017\/10\/traditional-av-solutions-shown-ineffective-real-time-global-heat-map\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Marcin Kleczynski| Date: Fri, 27 Oct 2017 07:01:46 +0000<\/strong><\/p>\n<table cellpadding='10'>\n<tr>\n<td valign='top' align='center'><a href='https:\/\/blog.malwarebytes.com\/malwarebytes-news\/ceo-announcements\/2017\/10\/traditional-av-solutions-shown-ineffective-real-time-global-heat-map\/' title='Traditional AV solutions shown ineffective in real-time global heat map'><img src='https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2017\/10\/Threat-Map-October.png' border='0'  width='300px'  \/><\/a><\/td>\n<\/tr>\n<tr>\n<td valign='top' align='left'>It&#8217;s no secret that antivirus technology (AV) has faced increased scrutiny in the tech industry for quite some time. One way to truly gauge the effectiveness of today\u2019s traditional AV solutions is by analyzing real-world data. So, we did just that.<\/p>\n<p>Categories: <\/p>\n<ul class=\"post-categories\">\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/malwarebytes-news\/ceo-announcements\/\" rel=\"category tag\">CEO announcements<\/a><\/li>\n<li><a href=\"https:\/\/blog.malwarebytes.com\/category\/malwarebytes-news\/\" rel=\"category tag\">Malwarebytes news<\/a><\/li>\n<\/ul>\n<p>Tags: <a href=\"https:\/\/blog.malwarebytes.com\/tag\/antivirus\/\" rel=\"tag\">antivirus<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/heat-map\/\" rel=\"tag\">heat map<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/marcin-kleczynski\/\" rel=\"tag\">marcin kleczynski<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/remediation\/\" rel=\"tag\">remediation<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/remediation-map\/\" rel=\"tag\">remediation map<\/a><a href=\"https:\/\/blog.malwarebytes.com\/tag\/traditional-antivirush\/\" rel=\"tag\">traditional antivirush<\/a><\/p>\n<table width='100%'>\n<tr>\n<td align=right>\n<p><b>(<a href='https:\/\/blog.malwarebytes.com\/malwarebytes-news\/ceo-announcements\/2017\/10\/traditional-av-solutions-shown-ineffective-real-time-global-heat-map\/' title='Traditional AV solutions shown ineffective in real-time global heat map'>Read more&#8230;<\/a>)<\/b><\/p>\n<\/td>\n<\/tr>\n<\/table>\n<\/td>\n<\/tr>\n<\/table>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/malwarebytes-news\/ceo-announcements\/2017\/10\/traditional-av-solutions-shown-ineffective-real-time-global-heat-map\/\">Traditional AV solutions shown ineffective in real-time global heat map<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[10453,12655,16171,10546,12626,14718,16172,16173],"class_list":["post-10137","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-antivirus","tag-ceo-announcements","tag-heat-map","tag-malwarebytes-news","tag-marcin-kleczynski","tag-remediation","tag-remediation-map","tag-traditional-antivirush"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=10137"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/10137\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=10137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=10137"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=10137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}