Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm not in the AV industry, but as someone involved in malware cleanups I can tell you that having access to the source code makes it slightly easier to go through the code base in order to identify ways of getting around the AV.

It's also possible to do some source code analysis to identify vulnerabilities in the product that might not be otherwise fairly easily exposed.

The virus signature database is pretty much worthless for all but the lowest hanging of fruit. There are plenty of tricks botmasters use to get around signatures, and AV firms are moving (or have moved) to more behavioural characteristics to detect malicious code. It guess it all depends whether that's in the updates or in the code base.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: