4 ms·
The scaling problem isn’t that hard with traditional signature based AV, the upfront work is largely the same irrelevant of scale of infections. You just keep
by fullspectrumdev 3y ago
The scaling problem isn’t that hard with traditional signature based AV, the upfront work is largely the same irrelevant of scale of infections.
You just keep updating your obfuscator/packer tool and constantly deploy new, undetected binaries.
There’s online “crypter” services which are quite cheap that will do this for you - give you a constant stream of new, unique, undetected versions of your malware executable.
AV is basically very good at blocking yesterdays threats - the shit it knows about.
Professional blackhats just factor constant evasion into their operating costs (which includes other costs like new C&C domains, VPS’s, buying traffic for installs. etc) anyway.
- datadrivenangel 3y agoIt's not hard, it just adds cost. If the cost is more than the reward, we get less malware. This is good.