Possibly Your Best Defense Against Malware: A Cloud Service
Ann Arbor (MI) - How often have you heard the word "cloud" this week ? We tend to believe that you should hear this word at least once a day, if you consider yourself an informed computer user. Following cloud computing devices, legal questions, various cloud computing projects of industry giants, we are also hearing more and more about possible services - services that may offer value and convince users to subscribe to cloud services. One of most convincing services we have seen so far is CloudAV, a project developed at the University of Michigan.
Farnam Jahanian, professor of computer science and engineering in the Department of Electrical Engineering and Computer Science, believes that cloud computing could make antivirus software much more efficient than your average antivirus software subscription is today.
Jahanian’s approach still uses conventional commercial antivirus software to check files for threats. However, the technology moves the actual antivirus software off a user’s computer into a network cloud. This allowed Jahanian’s group to run multiple antivirus software applications in parallel, each in a dedicated virtual machine. The 12 evaluated antivirus programs included Avast, AVG, BitDefender, ClamAV, CWSandbox, F-Prot, F-Secure, Kaspersky, McAfee, Norman Sandbox, Symantec and Trend Micro.

Common sense suggests that two malware detection engines work better than just one and ten will be better than just two. But how much better ? If the results published by Jahanian’s group hold up in the real world, then the improvement should be enough to make you switch to such a service once it becomes available (provided the price is right.)
According to the research group, the detection rates of any of evaluated antivirus packages ranged between 40% and 78.5% (average : 59.6%) after one week of discovery and between 62.7% and 89.2% (average 73.9%) after 3 months. Adding a second engine increased the average detection rate after one week to 77.6% and to 87.7% after 3 months. Five engines resulted in 90.5% (1 week) and 94.8% (3 months) and ten engines achieved 94.4% (1 week) and 96.7% (3 months).
The research results suggest that malware detection run in parallel are especially effective right after a new malware is expected. Every added engine can dramatically improve the detection rate. After three months, that effect levels off. Already three engines achieve a rate of 92%, which is better than the best engine out there today, according to the research group. The research results suggest that the advantages of more than five detection engines are rather marginal for viruses that have been in the wild for at least 3 months - and the cost may not scale favorably with the practical benefit.
We have to say that we are truly impressed with the results of this relatively simple idea (why didn’t we think of this ?) and there may be a very interesting service in the works that will appeal especially to larger corporations. It would be interesting for the home user as well, but at this time we doubt that the capabilities of five or ten antivirus engines could be offered for a reasonable price.
But think about it : No more hassle updating your antivirus software and improved malware detection rates. Nice.
- Networking,
- Business,
- research ,
- virus ,
- cloud
- Let The (War)games Begin! Black Hat And Defcon Hacking Conventions Begin
- AMD Ditches Close-To-Metal, Focuses On DX11 And OpenCL
- Study Finds Macs Cost 2X Windows PCs
- Sony To Expand Monthly Lithium Ion Battery Production Capacity From 41 Million Cells To 74 Million C
- Numonyx And Hynix Extend NAND Flash Cooperation
- Memory Module Makers See Strong July Sales
- Elpida Ready To Launch 16 GB FB-DIMM
- Jobs Admits MobileMe Launch "Not Up to Apple Standards"
- Thailand Pulls GTA IV Following Murder of Taxi Driver
- Nokia And Microsoft In Alliance To Make Zune Phone?
- IRobot Unveils Security Robot
- Carmack: PCs Not Important As Consoles
- America Movil to Offer iPhone in Ten More Countries this Month
- Jobs Appoints New Head of MobileMe
- No Linux for U.S. Lenovo Netbook - Only XP
- John Carmack Explains Why Blu-ray Makes Rage Better on PS3
- TSA Finds "Stolen" Laptop in TSA Office
- AMD's 790GX served with secret sauce for overclocking





Can't imagine the av makers being too happy about that. An alternative would be for them to share their av info in a standardised xml kind of thingy, that way the av info can be shared, but I think thats wishful thinking.
One other thing, cloud av would slow your pc down to a crawl if every file had to be checked via the internet when scanned, would nearly be as slow as Norton lol. And no internet would be no av protection....
All the AV software is a lot betting at stopping common malware that the above results indicate.
You are match more likely to be hit with common malware, so in most cases any of the leading AV software is good enough.
Now na ISP running a big mail server would do very well using all the AV engines combined, as ALL there customers get the benefit. So even if the benefit is very small to each customer, the overall benefit can be large.