Malware shifts and value chains.

Amrit Williams is calling me on predicting malware emergence. His assertion is that by the time AV improves enough to push attackers onto Macs at their current market share, then attackers will shift to another layer altogether and abandon the idea of monetized malware. I had always assumed that the value chain established by attackers would be largely preserved, but he may be right: there could be a point where AV is so good that attackers will just move to popping webmail accounts and routers rather than attacking client systems. Now wouldn't that be nice.

Hey Adam,

My basic assertion was that the effectiveness, or more appropriately the lack thereof, of AV on Windows, had limited, if any effect on an increase in Mac malware

So couple of points I would like to make:

1. I don't think AV will ever improve enough to be the catalyst that will push attackers to other layers or platforms. I do believe the platforms themselves, combined with other security measures have a higher likelihood of improvement and are more critical in driving attacks against other layers and platforms

2. Even if AV were to improve to a point where it was highly effective against new attacks, I doubt this would result in the switch to new platforms since it would be fairly easy to port the technology.

3. By layer I meant application-based attacks, especially as they relate to enterprise applications, web services, SOA, et al.

4. I am confused by your statement that I asserted attackers would abandon the idea of monetized malware by going after new layers. First off I never said that at all, so it can hardly be an assertion. Second attacking different layers would still largely be driven by financial gain - which would result in monetized malware

I hope that makes sense

