4 ms·
I can imagine AV engines having massive attack surfaces due to having to support a ton of exploitable file formats and decompression methods, and often supporti
by wmt 12y ago
I can imagine AV engines having massive attack surfaces due to having to support a ton of exploitable file formats and decompression methods, and often supporting decade+ old detections. It still is a surprising that some vendors (I'm looking at you Bitdefender!) have obviously not even tried to fuzz their product. Koret's presentation is already a year old, so I hope vendors would've now gotten at least some of their shit together. I wouldn't bet too much money on it though, as it still has virtually no effect on how much the product will be sold. Take a guess many people will still give money to Bitdefender because they have had a really good review performances.
There's definitely a pattern that AV companies put their efforts in being able to say they're #1 in outside tests or in reviews. In ye olden times someone would just take multiple vendors, scan against 1000000 old viruses and rank them based on the detection %, and as the end result the "best" (and the most sold) products ended up being resource hogs. Later reviewers took notice and started also measuring file copying performance and detection capabilities against active malware, and in a year or two many vendors adapted and improved their performance and their efforts against malware that actually is being spread.
Hopefully reviewers will take notice and include some exploitability metrics in the future so that vendors need to focus on it or go out of business.
Funny thing is that despite Bitdefender having thousands of exploitable points in their product, at the moment your average user will still be less vulnerable against online criminals than most those who don't run anything.