New Sourcefire Immunet and ClamAV data provides snapshot of consumer malware threats

Dark Reading Staff, Dark Reading

August 10, 2011

2 Min Read

Most infected consumer Windows machines are infested with more than one malware malady, according to new data released last week during Black Hat USA in Las Vegas by Sourcefire.

Overall, one out of every six or seven consumer machines is infected, according to new malware statistics gathered from Sourcefire's software-based ClamAV and cloud-based Immunet customers during the first three weeks of July. That's about 15.74 percent of the company's consumer customers tracked during that period.

Of those infected users, 70 percent have one or more reported infections on their machines, a statistic that Sourcefire attributes to either constant risky or unsecure behavior online, or attacks that use multiple forms of malware.

And one infection can lead to subsequent ones, according to Adam O'Donnell, chief architect in the cloud technology group at Sourcefire.

Nearly 84 percent of malware detections came out of Sourcefire's Immunet cloud-based service, and around 72 percent of of threats Sourcefire detected were unique ones that didn't show up again.

"This metric speaks to the importance of detection technologies that are not purely 1-1 signature based," according to a Sourcefire report. "At the same time, detection of singleton threats only represented 19.34% of in-field detections. That happens primarily since we might detect the same popular threat on multiple machines."

Sourcefire's advanced threat detection engines flagged about 14 percent of the threats via the cloud service, and 52 percent of threats overall were detected through the cloud-based service.

Have a comment on this story? Please click "Add Your Comment" below. If you'd like to contact Dark Reading's editors directly, send us a message.

Read more about:

Black Hat News

About the Author(s)

Dark Reading Staff

Dark Reading

Dark Reading is a leading cybersecurity media site.

Keep up with the latest cybersecurity threats, newly discovered vulnerabilities, data breach information, and emerging trends. Delivered daily or weekly right to your email inbox.

You May Also Like


More Insights