Multi-engine scanners are so last century
Monday, October 5, 2020
You've probably visited websites where they advised you to turn off Dr.Web Security Space's SpIDer Gate or Parental Control so that you could easily get to a location the anti-virus was blocking.
If a user is undecided about whether Dr.Web is actually wrong, some sites recommend that they make sure the alarm is indeed a false one. To do so, users are given the suggestion to check the file with a multi-engine scanner (such as VirusTotal), before downloading it. But these advisers overlook certain aspects of the complex phenomenon that anti-virus security has become.
What are multi-engine scanners? These are websites where users can upload files to scan them with multiple anti-virus applications. VirusTotal is probably the most popular site of this kind, but there exist other similar services. To have their files checked by the engines, users may choose to upload a file's checksum rather than the entire body of data. In this case, the site can only deliver a verdict if a file with the same checksum has previously been scanned.
Legitimate multi-engine sites relay information about new malicious files to anti-virus developers, while disreputable ventures offering the same services naturally don't.
How do multi-engine scanners work? Uploaded files are handed over to running anti-virus scanners that examine them and return a verdict. However, they only check files against their malware database records, without actually launching them. As a result, if an anti-virus doesn't have the required malware signature in its virus database and if its heuristic routines don’t detect anything, even an ordinary encryption ransomware trojan will be pronounced as harmless. On a side note, Dr.Web was able to identify and block Wannacry, thanks to its heuristic methods, which have been honed and perfected—we kid you not!—since 1994.
A multi-engine scanner report merely shows whether the anti-viruses "know" about the file. Nothing more. No multi-engine scanner can warrant that a file is clean.
But let's present our arguments in their proper order.
- Virus makers use multi-engine scanners, too—before they release a new malware sample into the wild. They check it against all popular anti-virus engines. By doing so, they ensure that no anti-virus can detect the new pest with 100 percent certainty, at least for a while.
- And that only includes signature-based scanning. But seriously, who now actually expects virus databases to ensure robust anti-virus security? Should another Wannacry-like outbreak happen, the time needed by malware analysts to add the new signature to the database may be just enough to bring the entire world to the verge of destruction. Anti-viruses have long been supplementing virus databases with technologies that enable them to detect malicious behaviour—after a file has been launched. These include the preventive protection functionality.
- Executable packers. A file can be compressed with a packer that the anti-virus scanner doesn't support. In this case the anti-virus won't be able to extract the contents and verify it against signatures in its database. How does this undermine anti-virus security on computers? If a malicious file has been compressed multiple times or if the container uses a compression format that many anti-viruses do not yet support, the malware will be guaranteed to bypass a multi-engine security check, without being detected by at least some of the anti-viruses. On another side note, Dr.Web incorporates technologies that can extract malicious objects compressed with unknown compression formats.
- Privacy. Let's say you have just received a strange email, ostensibly from your boss, but something doesn't feel right. You want to check it and upload the message to a multi-engine scanner site. It may turn out that the file is actually clean, but the problem is that you have just forwarded it to someone else's server. If no anti-virus regards a file as malicious, some multi-engine scanners make an extra effort to send the file to anti-virus laboratories for more in-depth examination—which is the right thing to do. But would you like your classified corporate document to be disseminated across multiple anti-virus companies around the world and potentially be used to harm your employer?
And here’s an anecdote to wrap things up. Several years ago, a renowned anti-virus developer set out to prove that other less known developers had been stealing its malware signatures. To accomplish this, a Windows calculator file was compressed several times, ranked as malicious in the anti-virus's databases, and uploaded to VirusTotal. A few minutes later, a number of other anti-viruses began to regard the Microsoft file as malware.
This story is not intended to reveal the heinous nature of multi-engine scanners but rather to demonstrate that one can't rely on them completely. Nowadays, the scanners are a thing of the past. In our new century, they can't keep computers safe—unlike Dr.Web’s comprehensive security technologies.
The Anti-virus Times recommends
If your anti-virus prevents you from downloading or launching a file, beware of even trying.
If it warns you against visiting a certain site, heed the warning. The anti-virus does that for a reason.
It is trying to keep you safe!
Tell us what you think
To leave a comment, you need to log in under your Doctor Web site account. If you don't have an account yet, you can create one.
Comments
Неуёмный Обыватель
02:46:53 2020-10-06
Lia00
02:08:43 2020-10-06
Niuxin
00:49:34 2020-10-06
Шалтай Александр Болтай
22:20:19 2020-10-05
EvgenyZ
22:15:52 2020-10-05
Toma
22:12:53 2020-10-05
Dmur
22:06:30 2020-10-05
Masha
21:48:28 2020-10-05
Philip
16:10:36 2020-10-05
In the Linux world the saying is the more eyes the better. "Virustotal" used to be a Spanish company it is now owned by Google who now go under the title of alphabet? Any files uploaded to them are kept for future analysing it does have a privacy warning but nobody reads it.
Virus writers malware writers do not upload their spiteful software to "Virustotal" for testing.
They used to be a big Spanish anti-virus software company who I think fell on its face twice and eventually switch to new management. They would delete programs without warning the user. They famously deleted the key generator for Windows 7 which was used for pirating Windows 7, you can imagine how annoyed people were.
The key generator was a safe program but it was used for pirating Windows 7, and a Spanish company would just delete it without a warning and the users of Windows 7 would get a message on the next boot telling them they cannot use Windows 7 as it is a pirated copy!
You know the business saying the customer is always right. it is not the business of antivirus anti-malware products to police their customers on behalf of Microsoft or anybody else. Nobody absolutely nobody is going to pay to have a policeman on their computer.
Virus programs anti-malware programs look for viruses and malware, and anything else is none of their business.
Татьяна
15:18:47 2020-10-05
GREEN
12:44:37 2020-10-05
If he warns that you don't need to visit the site, listen. He has a reason to sound the alarm. We are trying for you! "
This is how we believe and listen.
"There are a lot of deceptions on earth and various reptiles, it gives hope at the dawn of Dr.Web to people
Either they need the file, the site is wrong, there are many antiviruses, he is the only one on our guard "
Пaвeл
09:52:11 2020-10-05