What is antivirus software and how does it work? | Computing
You’ve probably been hearing about antivirus software as long as you’ve had a computer. It’s been a staple of almost every pre-built PCs since the early 90s, and if you ask your friendly, neighborhood ‘IT guy’ how to protect your system, invariably they’ll suggest you have some sort of antivirus solution in place. If you use best practices for staying safe online like not clicking on links or attachments in emails, not visiting dodgy websites, and sticking to curated app stores on your mobile devices, your antivirus may simply operate in the background not seeming to do much, even though it does.
But what is antivirus software, and how does it work? There are a number of definitions and depending on which company you go to for their security solution, their tactics for targeting malicious applications like viruses and ransomware can be quite different. Being well-versed in what these sorts of tools can do is the best way to make an informed choice about the best antivirus software for you or your small business.
What is antivirus?
Antivirus software, or as it’s more commonly known today, anti-malware software, is a tool that looks for applications that run on your PC (or smartphone) that shouldn’t be there. It uses a number of methods to differentiate between that Word document you’re editing and a nasty piece of software that’s going to throw up annoying pop up adverts or steal your bank details. It can even spot when otherwise legitimate applications have been hijacked by a virus.
Some antivirus software uses “live” protection to automatically block such viruses and malware from running at all, even stopping you visiting websites or opening emails that may have viruses attached to them. Others, known as remediation tools, offer scanning functionality only, and must be run in order to clean up a malware infection after it has taken hold.
When antivirus software finds a malicious program on your system it will typically offer options for quarantining it — making it unable to operate as intended — or delete it entirely. Although getting rid of them makes sure your system is cleaned from the infection, quarantining does have some benefit in that it makes it easier for the antivirus software companies to analyze the threat and potentially alter their antivirus solution to be more capable of defending against it in the future.
Do you need antivirus software?
Modern operating systems come with a number of built-in protections like firewalls or Windows Defender, to help prevent viruses from taking hold on your system. If you’re careful with how you use your devices and steer clear of links, attachments, and dodgy websites, or even operate on a virtual machine, then you may well be safe from most virus threats.
That said, there are threats out that even the most well-prepared PC or mobile user can’t prepare for. Sometimes legitimate download servers are hijacked and flaws in the Wi-Fi network you connect to could leave you vulnerable in other ways entirely. Having a robust antivirus solution that runs alongside all of the modern operating system and browser protections is a great first step in protecting yourself and your system. At worst, it provides peace of mind that you should be protected against nasty threats like ransomware, and at best, it halts those threats in their tracks should you stumble across them as you venture forth online.
You don’t always have to pay for it, as there are great free antivirus applications out there. However, we’d recommend you have at least one of them running on all your devices, just to make sure you at least have the basic protections in place.
Which antivirus should you choose?
Choosing the right antivirus is much like any other technological decision — it very much depends on you. There are tools that are great remediation scanners, others with plenty of preemptive protective measures, and some that do more than just block malware attacks. But there are some that are worth recommending over others to help you get started. After all, downloading just any old security software can sometimes put you at even greater risk.
Some of our favorite antivirus programs include the likes of BitDefender’s Antivirus Free Edition and Avast Free Antivirus. Out of the premium solutions, MalwareBytes is one of the best, offering protections against all sorts of threats, as well as active web protection to help you avoid dodgy websites entirely.
If you’re looking for the best Mac Antivirus, here are some of our favorites.
How does antivirus work?
Antivirus software has changed a lot over the years. While the earliest iterations of it were bespoke programs designed to specifically target individual viruses, today there are millions upon millions of different pieces of malicious software out there. To combat that ever-evolving threat, antivirus software has changed and expanded in scope. The best anti-malware solutions today use a combination of different tactics to help protect your PC and MacOS desktops, as well as your smart devices and networks.
Here are the three methods antivirus software most commonly use:
The most tried, tested, and reactionary of the methods used to combat viruses and other malware, signature-based detection looks for the specific digital code of a virus and if it spots it, quarantines or deletes it. Think of it like a virus’ fingerprint. The upside to it is that once a virus has been identified it can be added to a signature database which is stored locally or in the cloud and then accessed when scanning a system for threats. The downside to it is that it’s not very useful for brand new threats. It requires at least one person or system to be attacked by the malicious software and identify it before everyone else can be protected against it.
With hundreds of thousands of new viruses being created every day, more is needed to keep modern systems safe. That’s why, although MalwareBytes’ free tool provides mere signature scanning, its premium versions do much more.
A more modern technique for tracking down known and unknown viruses and malware is behavioral detection. Instead of looking at what a piece of software is, behavior monitoring looks at what software does. The way a human might operate certain programs, or the operating system like Windows or MacOS may perform certain functions is quantifiable and relatively well-defined. Viruses and other malicious programs, however, tend to perform certain functions which aren’t typical of a user.
Malware might attempt to shut down or bypass anti-virus solutions on the system. It might try to make it so that it runs every time you startup your system without asking, or contact an external server to download other malicious software to your system. Behavioral analysis looks for software attempting to perform these functions and even at the potential for applications to perform them, once again quarantining or deleting them as they are detected.
Although there is greater potential for false positives with behavioral detection than signatures, it’s a crucial component in the antivirus puzzle. Ransomware attacks that encrypt files and demand payment to unlock them, require a very fast response and signatures alone would be unlikely to be able to stop it. Behavioral detection however, like that offered by BitDefender, can spot encryption and halt it in its tracks, even rolling back any encrypting it has done in some cases.
Teaching computers how to do something has always been difficult and time-consuming, but machine learning allows computers to teach themselves in a much more efficient manner. That’s exactly what machine learning in antivirus leverages in order to provide another important layer in modern anti-malware protections.
Antivirus software that uses machine learning can analyze the code of applications and decide based on its understanding of malicious and benign programs, whether that particular piece of software is dangerous or not. It’s effectively an artificial intelligence solution and when used in conjunction with other security protocols has proved extremely effective at combating threats new and old. In some cases, companies like Cylance are using it as their only antivirus solution, though most offer a more rounded toolset.
Machine learning does require internet connectivity so that it can leverage the power of cloud-connected databases of information which it then draws from to detect malicious software. However, it can evolve and adjust far quicker than the more human curated methods of antivirus protections and that helps keep the most modern solutions up to date with the ever-evolving threat landscape.