Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Some one in the antivirus industry please clarify something for me. Which is more important/critical for an AV company: the software or regular virus definition updates. My guess is that the virus signature database is where they create maximum value?


I have been in the AV industry for a while and I would say both.

AV companies have a lot of behaviour analysis/decoding/parsing done inside their code that is as important as their "static" signature set.

In fact, I would say that having access to the code and how they analyze the files/memory/etc is more valuable to a competitor (and the "bad guys") than the static signature set.


In what sense have you ever been in the AV industry? I'm not sure whether this account belongs to David or Dre, but neither of you have an AV company on your LinkedIn profiles.

I admire you for building a business on cleaning up hacked Wordpress installs (seriously), but that's not the same game that Kaspersky is playing.


The signature database is where they'll get more money from. However, this is still bad for them. It gives people the chance to look through the code for vulnerabilities and it allows competitors to look at any techniques they're using. But the worst part is that they're a computer security company that couldn't keep their source code secure. Clearly, accidents happen even when one has the best policies and such in place. Sometimes it's merely chance as opposed to an indicator of something in a statistically valid way. However, it's still embarrassing. I don't find that there's a lot of testing of the efficacy of anti-virus software out there and so purchases are partially made on faith (would love to know if I'm wrong here since I'd be interested in the results). Anyway, as a purchase made partially on instinct, this makes purchasers feel less happy in their gut (so to speak).


There is some testing being done on them but it's really only the known viruses that are tested against. It's the viruses that are unknown that are what you want to worry about.


Both are very important.

From an industry point of view its always the DB size that matters. When MS bought Giant it was due their DB size, it was huge and useless e.g there were installers that generated random guid for active x controls, registering those guids as a signature was pointless but they still went with it, when it was time to sell the MS guys fell for it. I worked for a company that was sold eventually and it was the same story when the founders decided that its time to sell it was all about the number of signatures.

Kasperskey are known to have a brilliant engine, this leak is a huge blow for them

On a different note: I wonder how this happened in the first place, the security companies that I worked for were pretty strict on code access, I couldn't checkout any code I wish, only a few people could pull the entire code repository.


I'm not in the AV industry, but as someone involved in malware cleanups I can tell you that having access to the source code makes it slightly easier to go through the code base in order to identify ways of getting around the AV.

It's also possible to do some source code analysis to identify vulnerabilities in the product that might not be otherwise fairly easily exposed.

The virus signature database is pretty much worthless for all but the lowest hanging of fruit. There are plenty of tricks botmasters use to get around signatures, and AV firms are moving (or have moved) to more behavioural characteristics to detect malicious code. It guess it all depends whether that's in the updates or in the code base.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: