3 ms·
Not necessarily - I think it has the potential to be a very good move for Intel. I thought about my last post more, and I can think of a few applications where
by Marticus 16y ago
Not necessarily - I think it has the potential to be a very good move for Intel.
I thought about my last post more, and I can think of a few applications where it could give Intel some huge advantages.
Something that came to mind: We all agree that AV software eats CPU cycles. What's to say Intel can't just start putting custom hardware that is designed solely to offload signature checking onto a separate chip? With the increasing sizes of detection databases (anomalies, threats, etc), eventually it will get to a point where the typical CPU cannot feasibly cross-reference known threats AND perform proactive checking in a fast enough environment to make it useful.
Not to mention network detection via the same means. Pretty soon you will be seeing motherboards or at least CPUs that have other dedicated hardware to checking signature sets on an extremely fast basis versus having to try and mix other, non-security-related cycles with what I'll call "user" cycles.
- InclinedPlane 16y agoNo thank you! AV software is not security, it's a stopgap measure for when you have to "do something" but are too lazy to implement real security measures. And McAfee is one of the lowest quality AV vendors out there (remember when they pushed out a definition update that made XP instances unbootable? that costs a lot of people a lot of headache, and millions of dollars).
- Marticus 16y agoIt isn't software at that point as you would normally think of it - it would be a dedicated hardware piece that simply cross-references signatures with a known detection library and reports to the Intel chip. And you think end users have any grasp of how to implement "real" security measures? Oh hell no. Joe Schmoe at XYZ web design corp is inevitably gonna download that porn at work and get some worm.
- noonespecial 16y agoAgreed. Just wait till they push the signature to the flash om some special chip that calls a vital windows binary a virus. Not only will you not be able to boot, you won't even be able to reinstall, or pxe-boot, or run a live cd... Thats one deep rabbit hole.
- InclinedPlane 16y agoAye. And imagine how much damage false-positives can have on smaller software companies. A company like MS runs all of its binaries through the major virus scanners as a matter of course for any release build, not just to check for viruses but to make sure that they don't get tagged by a broken heuristic detector or some such. But not every company has that luxury (and even so, it didn't save XP from McAfee's blunder). Besides which, all AV amounts to variations on turd polishing. You'll never achieve robust security through black-list methods.
- azim 16y agoI think you're on the right track, but I don't believe this is about AV on the desktop. Enterprise-grade AV is a much bigger business, and tends to get pushed in to categories like IDS/IPS, web proxies, and email scanning. This all of happens "in the network" before packets ever hit your pc. It's extremely regex heavy, and in order to scan at high data rates we often rely on purpose-built regex accelerator cards.
- Marticus 16y agoAnd yes, true. But for end-users that aren't behind a corp firewall / NAT / etc, this is an easy solution that they don't have to worry about. Out of sight, out of mind (CPU cycles) sells, unfortunately.