Live data from Hacker News

Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

vice.com

11–20 of 60 posts

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#11

The advertisement take about this product being able to detect the malware two years before it's even written is discernibly turgid. Chuckled well off that. When will companies selling ML stop making these statements in attempts to whoa people? Like, the claim is ridiculous, how did they even come up with this, ans moreover, what's the possible basis for such a statement? How do they verify that and how would they pr…

So the approach described essentially defeats the purpose of antivirus software as it's known. Malware so happens to be (usually) embedded in the legit software. If that real-world fact is the way to defeat their model, is it of any use? You get the binary off the spoofed page, boom, you're pwned instantly and that piece of software is totally worthless at its primary goal despite being advertised as a killer product.

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#12

The featured article links to an article from Cylance that _does_ actually claim their model could've _theoretically_ detected and flagged malware before its creation. _"...before the cybercriminals set up the crypto-system, the payment details of the campaign, the C2 infrastructure and before anything else was readied, our model was fully able to predict and prevent that campaign’s malware."_ They claim that a 2015…

Old school antiviruses also has heuristics so they could make the same claim. It wouldn't be true in practice because malware authors would just test their malware against common antiviruses and tweak it before shipping so that the heuristics don't pick it up. Just like these researches did against their "AI". AI really just meaning "generated heuristics", doesn't it? If it becomes a problem for malware authors they…

yes

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#13

Earlier quoted context omitted.

Old school antiviruses also has heuristics so they could make the same claim. It wouldn't be true in practice because malware authors would just test their malware against common antiviruses and tweak it before shipping so that the heuristics don't pick it up. Just like these researches did against their "AI". AI really just meaning "generated heuristics", doesn't it? If it becomes a problem for malware authors they…

yes

sorry

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#14

The advertisement take about this product being able to detect the malware two years before it's even written is discernibly turgid. Chuckled well off that. When will companies selling ML stop making these statements in attempts to whoa people? Like, the claim is ridiculous, how did they even come up with this, ans moreover, what's the possible basis for such a statement? How do they verify that and how would they pr…

yes

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#15

The advertisement take about this product being able to detect the malware two years before it's even written is discernibly turgid. Chuckled well off that. When will companies selling ML stop making these statements in attempts to whoa people? Like, the claim is ridiculous, how did they even come up with this, ans moreover, what's the possible basis for such a statement? How do they verify that and how would they pr…

So the approach described essentially defeats the purpose of antivirus software as it's known. Malware so happens to be (usually) embedded in the legit software. If that real-world fact is the way to defeat their model, is it of any use? You get the binary off the spoofed page, boom, you're pwned instantly and that piece of software is totally worthless at its primary goal despite being advertised as a killer product…

yes

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#16

Earlier quoted context omitted.

So the approach described essentially defeats the purpose of antivirus software as it's known. Malware so happens to be (usually) embedded in the legit software. If that real-world fact is the way to defeat their model, is it of any use? You get the binary off the spoofed page, boom, you're pwned instantly and that piece of software is totally worthless at its primary goal despite being advertised as a killer product…

yes

sorry

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#19
I have used their home offering Cylance Smart Antivirus, and I essentially concluded that machine learning is just not enough to detect malware. It's nice signature is small and works even when you do not have latest signature, but there are a lot of false positives. (and it's generally identify the threat just by class of its threat, and not by specific identify of a threat, so there's no way to assess its impact.)

This combined with Cylance's attitude to treat games as its own class of malware (they would tell their user "just add the file to exclusion list" and there's no way to add the file by class -- mind you, this is a "home" product.)

I've tried Sophos Home, which also features machine learning based detection (on their paid premium version), but they use it to supplement the signature / behavior based detections -- which I feel is a more modest approach. For most of "known" threats it get caught by the signature engine by their identity ("EOF97/EicarDrp-A"), if not, it'll identify the threat by its class ("ML/PE-A").

Oh, also, EOF97/EicarDrp-A is actually a EICAR test file embedded in PDF file, I think this type of file is where Cylance's approach would struggle. (I don't think Cylance's engine even look at anything other than executables, anyways, however.)

Re: Researchers easily trick Cylance's AI Antivirus to think Malware is 'Goodware'

#20
That's what you get when you hype Machine Learning as AI. But you can't really blame the "AI antivirus" much more than regular ones, they can be fooled similarly easily. Antivirus can't generally protect you against anything else than old malware, with new one you are always on your own. That said, making old malware undetectable again takes more effort against regular antiviruses.
Post reply on HN