Old Acquaintances

If you think that virus authors are quickly discouraged by knock out blows from antivirus programs, think again.

IBM’s Internet Security Systems has recently revealed that an old foe of anti-malware applications is slowly making its way back to center stage again. The worm, which debuted in January 2003, is known as Spammer. It damaged countless systems during that year, making it one of the most dreaded and unwanted programs in recent history.

Resurrected?

Many thought that the worm had already been completely wiped out of every PC unit after security suites focused on its eradication during the months and years after its discovery. In fact, many have already forgotten about it during the past two years. However, IBM’s revelation had brought back its ghost, along with the reluctant prediction that the worm may come back with a vengeance.

What’s the Worry?

Many are downplaying the possible dangers that Spammer could bring to present computer systems. For one thing, security suites have already dealt with it successfully in the past. Hence, they shouldn’t encounter any difficulty in doing a repeat of their bout with the worm a few years ago.

The problem though, is that security software are having a tough time keeping at pace with the release of new viruses or the modified versions of old unwanted programs. It’s not as if Symantec or McAfee will be able to automatically detect the release of every worm or virus that is born in cyberspace. That’s almost next to impossible. Most of the time, they only come to know about the unwanted program after it has already infected a number of systems. There are thousands of hackers and malware authors around the globe. The number is simply and obviously overwhelming.

Keeping the Program Manageable

It would be very easy for antivirus applications to just retain old virus definitions in order to stem future attacks from old worms. However, this is quite impractical. Without retiring old virus codes, the size of anti spyware or antivirus programs could easily swell to exponential proportions. I’m sure you wouldn’t want your antivirus to be as large as Windows Vista, would you?

This practice of trimming down antivirus programs to manageable levels by retiring old definitions creates gaps on the security of a PC unit. Hence, all that a defeated virus author has to do in order to make a comeback is to put his creation in hibernation for a few years, then resurrect it after a new version of the antivirus that eliminated the worm comes out. This is a very easy task for the malware maker, especially since he need not even have to make any modification anymore.

New Approach

Security suites and system utilities, such as registry cleaners, should come up with a new plan on how to prevent the resurrection of old worms and viruses without having to resurrect its old warriors. There must be some way by which an antivirus or anti malware software could efficiently protect a unit from all known forms of unwanted software without being bloated by definitions and other algorithms.

, , , , , , , , , , , , , , , ,

Posted by Ruel on August 24th, 2007 .
Filed under: General | 1 Comment »