Latest news
They found that less than 5% of anti-virus solutions in the study were able to initially detect previously non-cataloged viruses and that many solutions took up to a month or longer following the initial scan to update their signatures.

“Enterprise security has drawn an imaginary line with its antivirus solutions, but the reality is that every single newly created virus may subvert these solutions,” said Amichai Shulman, CTO, Imperva. “We do not believe that enterprises are achieving the value of the investment of billions of dollars in anti-virus solutions, especially when certain freeware solutions in our study outperformed paid solutions.”
Imperva utilized various methods for collecting more than 80 viruses. These 82 unreported viruses were tested in a virtual execution environment that ensured that they displayed behavior indicative of viruses and that limited the vulnerability to computing resources.
The key findings and implications of the report include:
Antivirus solutions have a difficult time detecting newly created viruses - While antivirus vendors may constantly work to update their detection mechanisms, the initial rate of detection of new viruses by antivirus solutions in the study was less than 5%.
Antivirus solutions in the study were unable to provide complete protection since they are unable to keep up with virus propagation on the Internet.
Antivirus solutions lag in updating signatures - In some cases in the study, it took anti-virus solutions up to four weeks following the initial scan to detect a virus.
Investment in antivirus is misaligned - In 2011, Gartner reported that consumers spent $4.5 billion on antivirus while enterprises spent $2.9 billion, a total of $7.4 billion or more than a third of the total of $17.7 billion spent on security software. In addition, certain freeware solutions in the study proved equally or more effective than paid solutions.
While Imperva did not find a single antivirus product that provided complete protection, the solutions that had the best detection rates included two freeware anti-virus products.
Despite the inadequacy of antivirus solutions, Imperva does not recommend completely eliminating them from an effective security posture. Instead, security teams should focus on detecting abnormal behavior, such as unusually fast access speeds or large volume of downloads, and adjust their security spend on modern solutions to address today’s threats.
The complete report is available here.


Spotlight

Is it time to professionalize information security?
Posted on 23 May 2013. | The issue of whether or not information security professionals should be licensed to practice has already been the topic of many a passionate debate.

Review: Logging and Log Management
Posted on 22 May 2013. | Every security practitioner should be aware of the overwhelming advantages of logging and perusing logs for discovering system intrusions. But logging and log management comes with its own set of difficulties.

Experts highlight top data breach vulnerabilities
Posted on 22 May 2013. | Hidden vulnerabilities lie in everyday activities that can expose personal information and lead to data breach, including buying gas with a credit card or wearing a pacemaker.

A closer look at Mega cloud storage
Posted on 21 May 2013. | Once a novelty, nowadays many cloud storage services are fighting for their piece of the market in the virtual world. Mega offers 50GB of free space with great pricing on Pro accounts.

The CSO perspective on healthcare security and compliance
Posted on 20 May 2013. | Randall Gamby is the CSO of the Medicaid Information Service Center of New York. In this interview he discusses healthcare security and compliance challenges and offers a variety of tips.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.





