Don't buy stand-alone antivirus: Trend Micro

Stand-alone antivirus applications were dangerous because they could not adequately protect users and so created a false sense of security, according to the top malware expert at Trend Micro. However, the company continues to sell its stand-alone antivirus app because of "customer demand".

At a press luncheon in Sydney yesterday, Trend Micro's top malware specialist Raimund Genes slammed companies — including his own — for selling stand-alone antivirus applications.

Raimund Genes
Trend Micro malware CTO

(Credit: Trend Micro)

"Normally the [Trend Micro] consumer team kills me for this because I think you shouldn't offer separate antivirus, you only should offer a security suite because just offering an antivirus offers a false sense of security for the user base," he said.

"Just buying an antivirus because it is $10 cheaper lowers [the user's] level of security but they think they are secure ... but the market demands it, the retailers demand it, the distribution channel demands it — this is why we still deliver it even if I hate it," said Genes.

A member of Trend Micro's consumer team who was attending the luncheon agreed with Genes. He said: "It is only because the market demands it. I would rather nobody bought stand-alone antivirus. We are trying to re-educate the market".

The comments directly contradict the descriptions on the Trend Micro website, which describes its antivirus (and anti-spam) application as the "essential security you need to safeguard all your data and files ... you can rest easy knowing you have systematic, ongoing protection against the latest malicious viruses, worms, Trojan horse programs, and spyware."

Gene's comments came after he was questioned about competition from free antivirus applications such as AVG. According to Genes, free antivirus applications were only useful to geeks who knew what they were doing.

"If you know what you are doing, it is not bad. As a security expert, why not AVG, why not something for free? But what you have to consider is that all these extras to the AV are not normally combined ... so if you are a security geek you are able to combine and get a free firewall component, a free AV component and combine them all to protect you. For the average end user that is mission impossible. You need a security suite that combines all the elements — that is what you are not getting for free," Genes told attendees.

Signature-based blacklists are dying
Genes also said that blacklist-based malware protection would be dead within two years.

The executive said Trend Micro discovered 800 new pieces of malware every hour targeting Windows-based systems. The company expects that figure to double next year, which will make the traditional approach to antivirus unworkable.

"Two years from now, you will not be able to store the [signature] files on a computer any more ... you will not have enough memory space," Genes said. "Some people are saying that antivirus is dead, and I have to agree the traditional methods to combat malware have no future."

"By 2010, every file that is opened will need to be scanned against 20,000,000 signatures," he said.

(Credit: Trend Micro)

One possible solution that has been touted by various security experts is whitelisting, where known good applications and files are allowed to execute and unknown files are blocked.

James Turner, a security analyst for IBRS, agreed that blacklists were dying and said whitelists provided a sensible solution.

"Imagine giving the bouncer to a club the phone book ... whitelists make sense — people talk about the range of applications that run in an enterprise, there are a fair few of them, but they're not constantly changing," said Turner.

The whitelist approach was adopted recently by Symantec in order to improve the efficiency of its malware scanners.

However, Genes argued that there were too many "good" applications being produced for effective whitelisting.

"Microsoft is generating 10,000 binaries every week. How do you tag them all as known good?" he asked. "There are so many custom applications in an enterprise environment — there are millions of freeware [releases] out there."

Genes said the rapidly evolving threat landscape required evolving security. "I think it needs to be a combination of different technologies, there is not one silver bullet any more."

Talkback

Has anyone seen a standalaone antivirus solution lately?

Interesting that Raimund Genes thinks Trend Micro should go against the common practice in almost every marketplace, of every industry worldwide, and only offer one solution. People make choices as to the level of protection they'll install and the price they are prepared to pay for it. They do the same with almost every item they purchase. We'd be delighted to see Trend Micro adopt a single product solution approach and loose even more market share. At AVG we might consider doing it sometime after Ford, Honda, Sony, Toshiba, Noikia, Apple, Dell etc. reduce their product ranges down to a single model.

Not everyone can afford top-level protection. For economic reasons they choose to have less protection. At AVG we provide a free solution and it's used by millions of people around the world. Indeed in the Australian marketplace a survey earlier in 2008 showed that 30% of households were using an AVG solution. These people aren't the "geeks" referred to by Genes - they're typical home users who are better off with some anti-virus and anti-spyware protection, rather than none.

We go to great lengths to explain to people that AVG Anti-Virus Free Edition provides only a base level of protection - better than nothing at all, but not the level of protection we'd prefer people use. We strongly recommend people buy and install our fully integrated, total security suite solution, AVG Internet Security, and many do.

At AVG, more and more we're seeing our top level, full suite Internet security solutions dominating software sales. But there is still a significant number of people who choose to pay for less protection, or use our free solution. It may well be that some people are combining a number of security solutions to craft the tailored protection level they desire, as suggested by Genes, but they would be in the minority. In practise we find the vast majority are simply using the free or entry-level commercial product by itself, because it's a bit cheaper. They choose to have less protection, just as they choose to have a Ford compact instead of a Rolls Royce.

Personally, I wouldn't go onto the Internet without effective two-way firewall protection in place. Yet most people are prepared to simply run the inferior one-way protection built into some operating systems. Indeed, there are still millions of people running older operating systems without any firewall protection in place at all.

And just what does Genes mean by "standalone antivirus"? Most commercial Anti-Virus solutions on the market today don't just provide anti-virus protection. Most also provide protection against spyware, adware, worms, Trojans, rootkits etc. So the entry-level commercial products of today are way more effective than the simple "standalone antivirus" solutions of old. Someone needs to get out more.

At AVG, our Research Lab is processing 25-40 thousand unique files per day and adding them to our protection regime. We can not only cope with it, but we can still deliver to our customers a protection solution that is fast, yet light on system resources.

Of course, we're also working on new approaches. A fine example is our LinkScanner technology, which delivers real-time protection against web threats. Yet the new safe search and surf solutions being implemented by our competitors are almost all purely blacklist based. So James Turner is wrong when he says blacklists are dying. Our competitors are turning to them more and more.

Whitelists can be used effectively in some cases, but like blacklists, they are simply not much help against transient web threats. When the threat is so transient that it's only active for days, no blacklist or whitelist based solution is ever going to be up-to-date enough. Only real-time checking of web threats, as provided by the AVG LinkScanner safe surf technology included in all commercial AVG products, truly protects. AVG LinkScanner checks the web page for threats at the time it really matters - when th

lloyd_borrettlloyd_borrett October 14th, 2008
Report offensive content Reply (0) (0)

FREE AVG/ZA COMBO best... or Linux

I agree with much of the AVG person's post. The Trend Micro person was plain WRONG in saying that to have a basic anti-virus and a basic firewall was too hard for average users, and only suitable for geeks.
I have 25+ years IT experience and for about a decade I've used ONLY the free AVG stand-alone anti-virus software (http://free.grisoft.com) AND the free ZoneAlarm stand-alone firewall (www.zonealarm.com). To this one ought add the optional AVG browser toolbar (tick option at install time) and an Ad-aware or similar pop-up blocker, but that bit is not as essential. The ONLY problem for non-experienced users is finding where on www.grisoft.com (or www.avg.com) and www.zonealarm.com you can get JUST the free download. Both companies have made an art of trying to bury this option deep within many web-pages that ask if you are REALLY sure you want to go without the added benefits of their commercial offerings. However, you just have to avoid the 'baited hooks'... which assumes a friend told you to 'stay the course' and go for just the free one... as that IS sufficient.
I've found that the greatest exposure to viruses for users of commercial (non-free) products is when the licence expires. With AVG FREE, you get permanent protection with near-automatic updates to latest program and definition files, without any 'licence-expired' exposure.
I've set-up people in their 80s with the AVG/ZA 'FREE COMBO' and they've not had problems.

Personally, I shifted about six months ago from dual-boot XP/Ubuntu to retaining dual-boot capability, but doing almost all computer work in Linux, using Ubuntu/Firefox/Thunderbird/OpenOffice combo for almost everything... And I've personally pleaded with Irfan of www.irfanview.com to port his best-ever image editor to Linux, but he insists I need to run it under WINE emulator for Linux (which is a bit slower).

Graeme Harrison (prof at-symbol post.harvard.edu)Graeme Harrison (prof at-symbol post.harvard.edu) November 28th, 2008
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

ZD Net: How to calculate what to move to the Windows Azure cloud http://t.co/gHWnhFHE

@ShineLawyers yes, the High Court does not allow tweeting from court room; see @joshgnosis' piece: http://t.co/eJNt1gmu re #iitrial @Duds

Apple, Samsung court ordered mediation fails: http://t.co/tqk6JiJA ^LH

Telstra GameArena hacked, 35K accounts lost http://t.co/tft1aPxH via @zdnetaustralia

by http://t.co/vmlLt4bh: CT, phone clone: Craig Thomson says his phone might have been cloned, and that's why it ... http://t.co/5b0X49iN

Twisted Wire today looks at the Craig Thomson affair. CT phone clone http://t.co/XLfsEWnJ

Facebook is killing text messaging: How quickly the world changes. What's after Facebook? http://t.co/ZiSXuXJG

@forensicdave i'm torn. i did a lol but it's gross and not sure zdnet views need to see that!

The question is not whether DDoS can be achieved or not but whether DDoS originating from compromised computers on a slower network (e.g....

38 minutes ago by ChrisWatson on National Botnet Network coming: Earthwave

@jmorrill @dsturnbull Adobe did this a while back.. the flash sandbox - http://t.co/3hNbFUUp

“@zdnetaustralia: Telstra GameArena has been hacked, resulting in 35K accounts being exposed http://t.co/AspW8kHA ^ML” = LOL

Telstra GameArena has been hacked, resulting in 35K accounts being exposed http://t.co/WkKRoEo4 ^ML

Google found itself embroiled in a vicious tax debate this week. Serves it right? http://t.co/Ga14Yg6x ^ST

A threat to the iPad comes from an unlikely source: Nvidia http://t.co/lprnQLpg #technology

Telstra GameArena hacked, 35K accounts lost http://t.co/BFAztjzb via @zdnetaustralia

Australia tax inquiry opens submissions - ZDNet Australia http://t.co/slemxvIM

by http://t.co/vmlLt4bh: Much ado about Google's tax: Although scenes of political "gotchas" between Communicatio... http://t.co/ezMeAMDs

RT @zdnetaustralia: Telstra to launch its first 4G Windows phone, the HTC Titan: http://t.co/9QyDsgrT ^LH

Clever beggars!! Westpac board goes paperless with iPads http://t.co/p4mcpHr6

Seagate has bought a controlling stake in LaCie http://t.co/HL9nCrvu ^ML

RT @zdnetaustralia We've updated our HP job cuts story with comment from HP Australia: http://t.co/bWw55HjI ^LH

The inquiry into the Australia Tax is now taking submissions. Here's what it's been asked to tackle: http://t.co/ISXYvQSr ^LH

by http://t.co/vmlLt4bh: Telstra GameArena hacked, 35K accounts lost: Telstra has revealed that a third-party com... http://t.co/OtzhTwYV

Telstra GameArena hacked, 35K accounts lost http://t.co/gwj2BoEb?

Android's biggest security flaws. A good read for anyone using Android devices: http://t.co/2RpIr5Wd

#SAP launches #SuccessFactors Sydney Datacentre for hosting #cloud# products to service customers #in the region http://t.co/LjzTP98X

We've updated our HP job cuts story with comment from HP Australia: http://t.co/2MSrEnx8 ^LH

A short commentary on major Social Media stuff ups and mistakes. Remember some of these? http://t.co/iYaRwew0 #in

Westpac board goes paperless with iPads http://t.co/dBaSipFk Opportunity for an alternate revenue stream? Secure apps for business.

JobWatch: where the #jobs are http://t.co/GmTv3FbC via @zdnetaustralia

Are specific gaming development degrees bollocks? http://t.co/z2zbaWvT ^ST

Google kicks Oracle in its patent teeth | ZDNet http://t.co/0K1NGnVM

Way to go Successfactors! #SAP #SAPRocks #sydney
http://t.co/AIq71RCn

Westpac board goes paperless with iPads http://t.co/JpLtmTgW via @zdnetaustralia

Apple's next iPhone: 4-inch display; 12.5% more productivity http://t.co/1DnHrEHX

by http://t.co/vmlLt4bh: Google didn't infringe on Oracle patents: jury: A jury has unanimously decided that Goog... http://t.co/M5ftCLct

Lets throw Windows RT in the mix of Android and iOS mobile devices. Some of the management features of Windows RT means easier LOB (Line...

3 hours ago by fhemani on Windows 8 set for BYOD: Microsoft

If getting a degree was only about getting *any* job, then I would agree that a more specialised program might limit opportunities. Howe...

3 hours ago by Mario Wynands on Surely IT is more than just a game?

I'm the Chair of the NZ Game Developers Association, and have also consulted or worked for the Universities of Auckland, Otago and Waikat...

4 hours ago by sknightly on Surely IT is more than just a game?

Learning only matters if it helps you cross the bridge between where you are & where you want to be. In this respect, if where you want ...

4 hours ago by mitch.olson on Surely IT is more than just a game?

15 Oct 2007 It's a good thing that Kim Kardashian has a new show on E! titled "Keeping Up With the Kardashians" because it appears that i...

4 hours ago by Amampnema on IT Business Forum overcomes political uncertainty

As one of the founders of an 18 person game developer in NZ, I can tell you that your fears are not justified. We hire graduates from th...

4 hours ago by JonathanRogers on Surely IT is more than just a game?

@butterflyeffecs - really? Seriously?! You actually expected more of zdnet??? This article really does take the cake though - its gone we...

13 hours ago by lex on Android fragmentation steers Vic Health

Goods Shopping Location Discount Of Japan's Largest Abroad Train Brands. Coach Escape Shelter 89% Off.We Entertain Jammed Items Such As A...

15 hours ago by befeffofs on Reservoir blogs: Fan fakes Tarantino diary

1963年ナイキの創業者フィル・ナイトが訪日、オニツカ(現アシックス)の経営陣を訪問。 最新の機能性や斬新なデザインによって、常に新しいもの求める若者たちの心を掴んできたナイキスニーカー。今回はエアジョーダンやエアマックスなど、ナイキスニーカーの歴史に欠かせない名品から今...

15 hours ago by Speerbprayexy on Reservoir blogs: Fan fakes Tarantino diary

15 hours ago by Ideoforie on Reservoir blogs: Fan fakes Tarantino diary

Ferragamo Shoes Is Distinguished Brand.Ferragamo Is So Baby Valuation Broaden, It Is Secure To Shopping Outlet Online Stores.Ferragamo Ba...

15 hours ago by axollaCrake on Reservoir blogs: Fan fakes Tarantino diary

We Are Specialty Fit out Miu Miu Handbags, Miu Miu Purse, Miu Miu Sunglasses And So On. Miu Miu Sale Online Big Reduction With No Trade O...

15 hours ago by MoxboowsVix on Reservoir blogs: Fan fakes Tarantino diary

Pay off Trainer Wallet&Coach Pocket In Our Coach Store With Sad Sacrifice And Finish Quality, Save 80% Off. Cheap Carriage Overnight bag ...

15 hours ago by Fefinfani on Reservoir blogs: Fan fakes Tarantino diary

クリスチャン ルブタンは靴職人としてのスピリットが強いことで有名で、インタヴューでは下記のように語っています。Christian Louboutin「私は女性に、私の作る靴をファッションとは別の領域のにある、美の対象としてみてほしい。靴というものはアクセサリーではなく、その...

16 hours ago by ganitaickexia on Reservoir blogs: Fan fakes Tarantino diary

Celine luggage,Celine carrier bag,pocketbook Celine,CELINE Celine is synonymous with trait and fastidiousness prevalent since founding in...

16 hours ago by unulseDralola on Reservoir blogs: Fan fakes Tarantino diary

16 hours ago by Elundaninulge on Reservoir blogs: Fan fakes Tarantino diary

Normally would expect better from zdnet. I call BS. It appears that if you look at their decision it is about using HTML5 to develop thei...

17 hours ago by butterflyeffecs on Android fragmentation steers Vic Health

oBoDwZrOrsjUq //www.2012chanelbagsforsale.com]chanel handbags gWbyPIERM niLqoOE //www.2012chanelbagsforsale.com]chanel outlet hBaJhfpEu...

17 hours ago by khngmspwbzm on Deakin Uni opts for Cisco Unified Computing

Akku Asus A32-K72 Original,Kompatibler Ersatz akku für Li-ion Asus A32-K72 Original Laptop Akkus Asus A32-K72 Original,A32-K72 Original...

18 hours ago by akkuakku on HP Compaq 6730b

This story has been voted 10 times in the last 24 hours!

1 day ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

1 day ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar