Microsoft Security Intelligence Report v14: Why antivirus software matters

Status
Not open for further replies.

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
3,057
3,966
56
Oklahoma
ssupdater.b1.jcink.com
Antivirus software helps protect your computer from malicious software (malware) and can be downloaded or installed inexpensively or for free. Still, according to the latest findings from the Microsoft Security Intelligence Report
(SIR), 24 percent of computers worldwide are not running up-to-date antivirus software, leaving them over five times more likely to be infected with viruses.

The Microsoft Security Intelligence Report (SIR) analyzes the threat landscape of exploits, vulnerabilities, and malware using data from Internet services and over 600 million computers worldwide. Threat awareness can help you protect your organization, software, and people.

Full article
Download SIR Vol. 14 (pdf)
 
Lost count of how many computers I've come across that have an outdated non-licensed Norton/McAfee/TrendMicro installed that offers no protection because it was pre-installed trialware that has ended.

Sure enough I'll run a quick scan with Malwarebytes and they have some nastys lurking on the system, I'll get rid of them to the best of my ability and then install a free antivirus such as Avast or MSE and give them a quick run down on how to avoid malware. (works 5% of the time, usually I'm called back a week or two later to remove more malware they've managed to get infected with).

Not guaranteed that if these people had an active antivirus working that these nastys would have got blocked but atleast it would have provided some protection and that is what matters in my opinion.

Anyways I got to get back to my grandmother who is learning how to use HIPS with multiple security software layered on top of each other because an antivirus is simply not enough for her! She is a better malware hunter then any of us will ever be.

Thanks.
 
24 percent of computers worldwide are not running up-to-date antivirus software, leaving them over five times more likely to be infected with viruses.

Sorry i cannot resist to say this.
If MS is right that 24% does not run up to date software, then this also means that good old MS itself does do not a good job in keeping,
Windows Defender,
Windows Firewall
Windows Malicious Removal Tool (KB Patches)
MS Security Essentials

Up to date.
Because 99.9% of all Windows Operating Systems out there have at least 1 of the mentioned 4 running.

Also MS needs to realize that their way of programming windows, specially Vista Home, Windows 7 Home and now Windows 8 has produced rather buggy releases where some older versions are still buggy till this date.
Which forces Security Firms to change and adapt their programs to make up for the little changes provided by MS to patch the OS itself.
So it is really hard for a third party Security Developer to launch a fitting software package that can protect Windows in the first place.
That being said as a professional myself i do know for a fact that if those vulnerabilities and exploits are being fixed in Windows OS before it being shipped, then these 24% do not really matter.
Because even with those 24% not being up to date their AV will provide enough standoff to prevent infection by even newer viruses, based upon the plane and simple fact that 75% of all the Viruses and Trojans out there are based upon those very vulnerabilities and exploits.
As independent tests have proven 90% of all AV software seem to be able even with outdated databases to prevent infection from real viruses.
Where most of them only seem to have a problem with vulnerabilities and exploits and the remedy against it.
Afteral most of these vulnerabilities and exploits are only being able to damage the system, due to the fact that they enjoy the protection of the Windows OS itself. Specially because most of these "holes" are critical or elevated processes which are being locked from the user itself as part of the OS core files.

The main reason i say this is because personally speaking i am getting a little bit fed up with MS and their security talks.
In fact i do not want to sound like a pessimistic prick but a good 65% of all the dangers out there can be directly traced back due to MS its failure to get it right because the only reason those vulnerabilities and exploits is because of MS itself.

And it makes me laugh to read these stories, and yes they are right and yes its a rather big concern that 24% of the systems out there are outdated and probably infected.
Because thats nearly a quarter of all the PC running on windows.
And thats a BIG number and each single one of them is a potential hazard.
Keep in mind as long systems are not patched up properly both on OS level and on security application & solutions levels you will effectively allow worms, Trojans and Botnets/Rootkits to circulate the Internet.
Because it is proven that the targeted viruses (Low distribution and dangerous) ones only make up a fraction of all the pests out there.
So MS should patch up their systems before they release it, and by doing so there might come a time where heavy security solutions become a thing of the past.
Leaving only relatively harmless malware to be handled by AV developers. On top of that you will effectively put 70% of all the hackers and script kiddies out of a job, as their ways in just vanished.

Does that make any sense what i am saying?

Anyway nice article.

Cheers
 
Microsoft has the resources to make the best security product and give it to Windows users for free. But there is a major problem with this idea.

First Microsoft would get accused of trying to run a monopoly in the PC security business. Second they would lose several business partners that provide income and resources. Third, the PC security market would crash and many people would loose their jobs which would be bad for the economy. Forth, Microsoft would have no competition in PC security because they would probably not keep it updated or make a complete effort to make sure that it was sufficient. Fifth, this would led to way for other OS makers (Apple, Linux or new companies) to take over the PC market.

Microsoft has limits just like any other big company.

Thanks.:D
 
Some people that knows bit well regarding security, are barely attacked by infection unlike long time before.

Because knowledge were shared by known experience users and even though they don't even bother to update their software; a repeated cycle habits where a possible chance of infection was slight to happened.

Not patching Windows doesn't even an alarm for them, or sometimes its set for default.
 
Imo MS should go back to their roots, building a OS and focus on it, and stop trying to build a can do it all installation which is bound to have flaws.

There is no harm in making your own firewall, or AV and there is no harm in building additional security features to come with the programs, IF these modules reflect the current standards.
And fact is that this is not the case.
So stop putting them into the OS itself, and open up windows kernel and core components to their security partners. And ill bet that the knowledge amongst their partners will be able to secure the OS and thus the very workings of windows in ways MS just cannot do it.

I mean look at MSE its nice to have but it does not provide real security.
Look at their firewall, its just not making the cut same applies for Windows Defender.
So that does present the user with a false sense of security.
Because if ANY person gets himself a average Internet security program from a third party vendor then the protection level that comes from it out of the box is already so much higher then MS its own products can provide.
So imo MS should phase them out, and focus on the OS and core protection and leave the outer layer to AV developers.
As for monopoly MS has already a monopoly, due to the can do it all config of MS.
The only thing breaking that monopoly is the end user who disables additional features in favor of third party programs who do a much better job then any security product MS has released.

Next to the holes in windows, the biggest weakness it has is the ability to do it all.
Which means the moment a malware penetrates the OS then it can work from there and have access to everything.
But if this same malware penetrates a modular designed OS then its power is so much limited and thus it down grades the effectiveness of viruses itself.

Its something the industry has been saying for years, but MS values money more then providing a good OS.

Same goes for windows server OS, if you look at Linux or Novel then you can only come to one conclusion and that is that MS has taken it to far, and thus leaving them self subject to massive vulnerabilities and exploits.
Obviously ANY OS can be compromised if you do not take care of it, but the problem is that windows OS is already compromised out of the box.
On a positive note there are more and more voices in the MS industry who start to see what we all have been yelling for years, and with the rock solid track record other OS developers have and their increasing market share it seems evident that if MS does not change its habits then sooner or later it will be beaten in it own category, like every single product they have been releasing.

I mean look upon any program MS offers, and you will see that there is a third party available who does beat them hands down.
The only thing MS has left which stands solid is their OS, but with the new MAC, Linux and Solaris based OS Developers out there its save to say that if they do not change fast and start listening to their costumers and partners in the industry then i can see MS fade away, because those partners they have develop all their products mainly for windows, what would happen if some developer suddenly gets it right... then those partners will go with the main stream and start producing products for other OS vendors.
Which leads to the down fall of MS.
 
I mean look upon any program MS offers, and you will see that there is a third party available who does beat them hands down.

I wouldn't say that is the case with office.
 
From out of the corners, there are existed free and open source alternative Office application since same features at all thus they choose it.
 
Status
Not open for further replies.

You may also like...