📜 ⬆️ ⬇️

How to catch what is not. Part sad: what is an antivirus?

Quite often, when coming to customers, in one form or another I have to ask the question: why do you need an antivirus? As a rule, they look at me like an idiot - everyone knows that! But in most cases, further discussion shows that the overwhelming majority of customers do not know the answer to the children's question. To be precise, over the past year they answered correctly in just two (two!) Companies. And by the way, according to statistics, this is not only Russia's misfortune - the situation abroad is similar.

This part was not originally planned, but apparently urgently needed. A number of comments to previous articles show that even IT professionals do not understand the difference between the concepts of "antivirus" and "antivirus protection system." This is quite clearly manifested in the comments, when instead of an antivirus in the form of a call it is suggested to use other software - as a rule, systems of restriction of rights, access, etc.

Therefore, I propose to return to what was said earlier. Let's determine if anyone has any objections to replacing the antivirus with alternative solutions and whether the antivirus is different from the antivirus security system.
')
Antivirus, given to us in the definitions

In the first part of our cycle, we realized that at the moment there is no definition of a malicious program in the world - regulators, in general, do not know what to protect against. Let's turn to the opposite side and see what an antivirus is from the point of view of the regulators of our country and the world:


Thus, it is clear that at least the definitions do not define the moment when the protection system should detect a malicious program, or include outdated definitions of protection measures (modification).

Do we catch fleas? By no means. Despite the fact that in previous articles it was quite clearly stated that the main task of the antivirus is the detection and removal of previously unknown malware - comments to two articles recommended replacing the antivirus with systems that prevent infections. That is, the myth is ingrained, and if we do not prescribe the correct definition, the protection system will not automatically receive the necessary functions.

The situation is illustrated by a great bike. It is said that when Kennedy said “we will be the first on the moon!”, A special commission made only minor corrections to the mission goal - “The system must deliver astronauts to the moon and return them back.” But you could save.

It is also a common mistake to include in the definition of the protection system an enumeration of types of malicious programs or their actions. In this regard, the emergence of new types of malicious programs or their actions automatically removes them from the action of regulatory documents.

Why does antivirus miss viruses?

Before introducing the definition of the anti-virus protection system, let us once again define the malware's potential for circumventing the anti-virus protection systems (risk level).

At the moment, the most dangerous malicious programs are not developed by lone hackers - this is a well-organized criminal business that involves highly skilled system and application software developers in its criminal activities.

Attention! It doesn't matter who played what role in this “firm”. Perhaps the role of a simple system administrator. Ignorance is no excuse.

Testing for the non-detection of malware being developed by current antivirus solutions has made it possible to release only malware that cannot be detected (before receiving updates) by protection systems supposedly used by groups of users who are scheduled for an attack — including using heuristic mechanisms. The number of such programs produced by a single grouping can reach hundreds of samples - and none of them will be detected by antivirus software used by the target group of victims.

What problems are there with ensuring anti-virus security?

We repeat what has been said in previous articles:


By the way. We said earlier that the production of the most dangerous malware has been put on stream. But is this true for other malware? According to AVG (http://now.avg.com/kids-writing-trojans-show-computer-skills-friends), a third of modern malware is created by children.

Why do I need an antivirus?

Accordingly, the anti-virus protection system should provide:

  1. protection against the penetration of all already known types of malicious programs (including using technologies that allow detecting modifications previously found). The word "all" is not just highlighted - typical is a request to remove old viruses from the databases. Do not believe it - OneHalf is still alive!
  2. after receiving updates - detection and destruction (but not rollback of actions!) already running and actively opposing the detection of malicious programs.

The definition shows that the data in the regulatory documents definitions of anti-virus protection are not just false, but deliberately harmful to companies that focus on these definitions. Therefore, the functions implemented on the basis of these definitions and the composition of the anti-virus protection systems are also incorrect.

Comments to previous articles show that many, defining the task of anti-virus protection, forget about the second part.

You can perform the task of preventing the introduction of malicious programs without antivirus software - no one bothers you, and, moreover, sometimes the presence of an antivirus is contraindicated. But removing an already active infection without an antivirus is impossible. Yes, I know about the availability of specialists who can do it manually (and even there are companies that form such rapid response teams). But there are three but:


What is the difference between antivirus and antivirus protection system?

Antivirus protection system is not always an antivirus. This is any program / OS setup / procedure by which you reduce the risk of infection.

Accordingly, no one bothers you (except for the regulators, but everything is not so obvious there) not to use an antivirus to prevent infection, but for treatment without antivirus you will not manage. But there is one thing but ( www.infosec.ru/news/8119 ):

The most common vulnerabilities and weaknesses are:
  1. Password policies are not configured or incorrectly configured.
  2. Administer network equipment using insecure TELNET protocol.
  3. Event auditing is not configured or configured incorrectly.
  4. Firewalls contain redundant rules.
  5. Network segmentation was incorrectly performed, in particular, server segments are not separated from user segments.
  6. The update management process is not implemented or implemented incorrectly, as a result, for example, outdated software containing known vulnerabilities is used
  7. The lack of security settings for access switches, in particular, protection against vulnerabilities to attacks of the ARP Cache Poisoning class.
  8. No signature update and alert settings for intrusion detection tool.
  9. Using insecure protocols for remote access using VPN technology.
  10. Incorrectly configured restrictions on access rights to system files.

You can use a Kalashnikov rifle, or you can turn a sniper rifle yourself. If you are ready not only to set up the system, but to analyze the news of the IB in real time and, accordingly, also to improve the protection in real time - neither I nor the regulators (especially in the context of the 31st order of the FSTEC) are completely against it.

Well, in the next article we will talk about whether regulators and creators of standards require the use of antivirus, and what benefits can be gained if you read information security documents at night

Source: https://habr.com/ru/post/255015/


All Articles