Avast WEBforum

Consumer Products => Avast Mac Security => Topic started by: TED123 on December 19, 2015, 05:49:53 PM

Title: Three ?s for Vlk on Avast for Mac
Post by: TED123 on December 19, 2015, 05:49:53 PM
1) On many AV tests Avast for Mac has been called out for heavy resource use. On one test is was the worst, but it was on a download being scanned inline so I can give that a partial pass.

There have been a couple posts here on about Avast for Mac stressing out SSD drive with excessive read and writes.

What is Avast doing to reduce this resource use? 


2) While I know this may or may not have anything to do with resource use. 
Does the Mac have a more efficient coding language  that COULD be used as per windows with
"assembly"  but for the Mac?  Would "swift" be a better language to compile Avast for Mac in?


3) Is Avast working on implementing a heuristic engine for Avast for Mac so it will be the first AV company to advance Mac AV with the same advancements the PC based AV has.  I assume you know, Patrick Wardle of Synak, an OS X malware researcher who has stated that ALL Mac AV programs lack any heuristic engine for OS X, and making ALL Mac AV programs basically very simplistic and somewhat noneffective for the upcoming Mac advanced malware. 


Here is a short six minute video with Patrick at BlackHat 2015

https://www.youtube.com/watch?v=yHZ9XGvNeik

Vlk, PLEASE advance  Avast for Mac faster then the rest of the SLLLLOOOWWWW  development cycle that AV companies are doing on OS X AV.  Maybe a collaboration with Patrick Wardle and Avast would be a WIN WIN for Avast.


.
Title: Re: Three ?s for Vlk on Avast for Mac
Post by: tumic on December 21, 2015, 11:36:09 AM
Title: Re: Three ?s for Vlk on Avast for Mac
Post by: TED123 on December 21, 2015, 12:50:39 PM
As for #3, Patrick Wardle has stated there is NO Mac AV on the market that has a heuristic engine,  they are ALL simple definition scanners. I guess I would have to take his word on that one. He has tested all of names including Avast for Mac with very simple zerodays and ZERO Mac AVs caught simple malware that had a bit or two changed of commonly known malware. He said any AV with a good heuristic would have pick it up right away.
Title: Re: Three ?s for Vlk on Avast for Mac
Post by: tumic on December 21, 2015, 01:22:15 PM
Well, such experiments only show, if there are heuristic detections for certain file
types, not if the engine is capable of doing heuristic detections in general. In case
of Mac malware there may be no reason to do such scans at the moment as there
may not be a real malware spreading with modifications.

Because of performance reasons, we always try to do only the detections required
(= for malware that is really "out there"). In fact the whole detection processing is
more and more based on statistical data.