{"id":6881,"date":"2017-03-07T07:50:21","date_gmt":"2017-03-07T15:50:21","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2017\/03\/07\/news-672\/"},"modified":"2017-03-07T07:50:21","modified_gmt":"2017-03-07T15:50:21","slug":"news-672","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2017\/03\/07\/news-672\/","title":{"rendered":"Anti-malware is imperfect but still necessary. Here\u2019s why"},"content":{"rendered":"<p><strong>Credit to Author: Bill Brenner| Date: Tue, 07 Mar 2017 14:53:27 +0000<\/strong><\/p>\n<p><img decoding=\"async\" data-attachment-id=\"26996\" data-permalink=\"https:\/\/blogs.sophos.com\/2014\/08\/18\/sophos-mobile-security-for-android-version-4-0-is-coming-sign-up-for-the-beta-to-win-a-prize\/sophos-free-antivirus-mobile-security-android-2\/#main\" data-orig-file=\"https:\/\/sophos.files.wordpress.com\/2014\/08\/sophos-free-antivirus-mobile-security-android1.png?w=640\" data-orig-size=\"150,150\" data-comments-opened=\"1\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"sophos-free-antivirus-mobile-security-android\" data-image-description=\"\" data-medium-file=\"https:\/\/sophos.files.wordpress.com\/2014\/08\/sophos-free-antivirus-mobile-security-android1.png?w=640?w=150\" data-large-file=\"https:\/\/sophos.files.wordpress.com\/2014\/08\/sophos-free-antivirus-mobile-security-android1.png?w=640?w=150\" src=\"https:\/\/sophos.files.wordpress.com\/2014\/08\/sophos-free-antivirus-mobile-security-android1.png?w=640\" alt=\"\"   class=\"alignleft size-full wp-image-26996\" \/>Doctors sometimes make\u00a0mistakes that harm\u00a0the patient. Police often fail to protect and serve. When that happens, people rightly demand the\u00a0failures be analyzed and fixed. But no one ever calls for the elimination of all doctors and police.<\/p>\n<p>Why then, do some call for the end of antivirus and anti-malware when failures happen? It&#8217;s a question that has vexed us for a long time.<\/p>\n<p>Researchers uncover vulnerabilities in security products on a regular basis. A recent example is Trend Micro, which faced scrutiny in January after researchers reported some <a href=\"https:\/\/www.forbes.com\/sites\/thomasbrewster\/2017\/01\/25\/trend-micro-security-exposed-200-flaws-hacked\/#2730a7322678\">223 vulnerabilities <\/a>across 11 of the vendor\u2019s products. Tavis Ormandy, a prolific and gifted Google Project Zero researcher who most recently <a href=\"https:\/\/nakedsecurity.sophos.com\/2017\/02\/27\/cloudbleeds-silver-lining-the-response-system-worked\/\">discovered Cloudbleed<\/a>, regularly targets security products, including those produced by Sophos and such vendors as Kaspersky and Symantec.<\/p>\n<p>Along the way, someone either declares it the end of antivirus, anti-malware and endpoint protection, or calls for its demise. Last year, during another disclosure of Trend Micro vulnerabilities, security experts even declared antivirus <a href=\"http:\/\/www.csoonline.com\/article\/3020459\/security\/antivirus-software-could-make-your-company-more-vulnerable.html\">a threat to security<\/a>.<\/p>\n<p>Can we all do better? Absolutely. Like all technology created since the dawn of time, antivirus sometimes falls short of its mission. As an industry, we need to continue to find weaknesses and fix them as quickly as possible.<\/p>\n<p>Does doing better mean we set aside antivirus and anti-malware, just as some believe vaccines should be shelved? Hardly.<\/p>\n<p>To help frame the issue, I sat down with Sophos CTO Joe Levy.<\/p>\n<p><strong>Iatrogenesis happens, followed by schadenfreude<\/strong><br \/> \u201cIn responding to the occasional question about the claims of harm from endpoint security products, it occurred to me how strikingly similar such a belief system is to the anti-vaxxer movement. Both mean well, but unfortunately have the potential to do more harm than those they indict. Nonetheless, those who point out problems with antivirus make valid points,\u201d Levy said. \u201cAll software has flaws.\u201d<\/p>\n<p>Levy offers two other observations:<\/p>\n<ol>\n<li>This is a case of yelling \u2018<a href=\"https:\/\/en.wikipedia.org\/wiki\/Iatrogenesis\">iatrogenesis<\/a><u>\u2019<\/u> (harm caused by the healer) in a crowded theater. It is particularly sensational because of the irony, and in many cases, a source of <a href=\"https:\/\/en.wikipedia.org\/wiki\/Schadenfreude\">schadenfreude<\/a> (pleasure derived from the misfortune of others).<\/li>\n<li>The attack surface of security software is often enlarged by the level of privilege needed to operate efficiently (i.e. in the kernel) and to do the kind of work that it needs to (file\/network interception, process termination, system cleanup, etc.)<\/li>\n<\/ol>\n<p>Just as patients sometimes develop complications after surgery, security technology sometimes fails, creating unintended harm for the user, Levy said. When that happens, detractors love to swoop in and bludgeon the offender.<\/p>\n<p>Levy noted that when medical care goes wrong, we don\u2019t see the masses calling for the end of doctors and hospitals. Sometimes police make mistakes and do harm in the line of duty. When that happens there\u2019s public outrage, but no one calls for the end of police.<\/p>\n<p>Like modern medicine and law enforcement, the security industry has a very high obligation to protect their users from harm. That means not only demonstrating effectiveness against attacks targeting operating systems and applications, but also against attacks targeting themselves. Despite this awareness, prevalent security software, like all other software with a large enough install base, is still sometimes found to be far from ironclad.<\/p>\n<p>But just as we still need hospitals and police officers, we still need those security tools, Levy said. While Microsoft continues to make great strides in the security of their operating systems and applications year over year, a look at the number of Microsoft vulnerabilities per year illustrates the continuing need for additional protections. Microsoft security holes between 2009 and 2016, as catalogued on the <a href=\"http:\/\/www.cvedetails.com\/microsoft-bulletins.php\">Common Vulnerabilities and Exposures (CVE) website<\/a>, are as follows:<\/p>\n<ul>\n<li><strong>2009: <\/strong>74<\/li>\n<li><strong>2010: <\/strong>106<\/li>\n<li><strong>2011: <\/strong>103<\/li>\n<li><strong>2012: <\/strong>83<\/li>\n<li><strong>2013: <\/strong>106<\/li>\n<li><strong>2014: <\/strong>85<\/li>\n<li><strong>2015: <\/strong>135<\/li>\n<li><strong>2016: <\/strong>155<\/li>\n<\/ul>\n<p>In five of the last eight years, Microsoft released more than 100 security bulletins in a 12-month period. The number of bulletins each year haven\u2019t fallen below 75 since 2009. Antivirus remains the first line of defense when attackers work to exploit vulnerabilities in either software or the software\u2019s human operators.<\/p>\n<p>\u201cWe take our obligation to protect very seriously, and we make continuous investments in the tools and programs to improve the security of our products, from our SDLC (secure development lifecycle), to static\/dynamic\/runtime security tools, to our <a href=\"https:\/\/bugcrowd.com\/sophos\">bug bounty program<\/a>, to name a few,\u201d Levy said. \u201cWe are genuinely grateful to those security researchers who practice responsible disclosure. All of us in the security industry, whether software vendors or researchers, seek to make information systems more secure.\u201d<\/p>\n<p>He added: \u201cWe should all take a sort of Hippocratic Oath to do no harm, and that means both holding ourselves to a higher standard for building secure software, as well as putting end users before glory or sensationalism. Failure at either is a form of negligence, but calls for extermination are silly and irresponsible. The focus should not be on kicking the other when they\u2019re down, but on making each other better.&#8221;<\/p>\n<p>Filed under: <a href='https:\/\/blogs.sophos.com\/category\/corporate\/'>Corporate<\/a> Tagged: <a href='https:\/\/blogs.sophos.com\/tag\/anti-malware\/'>anti-malware<\/a>, <a href='https:\/\/blogs.sophos.com\/tag\/antivirus\/'>Antivirus<\/a>, <a href='https:\/\/blogs.sophos.com\/tag\/joe-levy\/'>Joe Levy<\/a> <br \/><a href=\"http:\/\/feedproxy.google.com\/~r\/sophos\/dgdY\/~3\/Z6KUEARkgdI\/\" target=\"bwo\" >http:\/\/feeds.feedburner.com\/sophos\/dgdY<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Bill Brenner| Date: Tue, 07 Mar 2017 14:53:27 +0000<\/strong><\/p>\n<p>Doctors sometimes make\u00a0mistakes that harm\u00a0the patient. Police often fail to protect and serve. When that happens, people rightly demand the\u00a0failures be analyzed and fixed. But no one ever calls for the elimination of all doctors and police. Why then, do some call for the end of antivirus and anti-malware when failures happen? It&#8217;s a question [&#8230;]<img loading=\"lazy\" decoding=\"async\" alt=\"\" border=\"0\" src=\"https:\/\/pixel.wp.com\/b.gif?host=blogs.sophos.com&#038;blog=834173&#038;post=33089&#038;subd=sophos&#038;ref=&#038;feed=1\" width=\"1\" height=\"1\" \/><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10377],"tags":[11013,10453,10379,11537],"class_list":["post-6881","post","type-post","status-publish","format-standard","hentry","category-security","category-sophos","tag-anti-malware","tag-antivirus","tag-corporate","tag-joe-levy"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6881","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=6881"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/6881\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=6881"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=6881"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=6881"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}