Antivirus bypass using timing-based techniques
In order to sell security products, antivirus vendors have to emphasize two central characteristics, as follows:
- High level of detection—Protecting the user from threats
- User-friendly—Comfortable user interface (UI), clear images, fast scans, and more
For example, we can look at a particular endpoint that has about 100,000 files. If we were to demand maximum detection from antivirus software, scanning all of those 100,000 files could take a few days—and, in a few cases, even longer. This is an extreme demand that antivirus vendors cannot possibly meet, and are not supposed to.
In order to avoid this kind of situation, antivirus vendors do everything possible to maximize wait time during a scan, even if this means that at best, detection is less precise, or at worst, that malware is not detected at all.
Antivirus vendors prefer to scan about 100,000 files in 24 minutes, with a detection rate...