How useful are AV detection scores with malware lifespan of 7 hours?

As you know, the number of new (unique) malware files per day is increasing in high numbers — so far, we're getting something around 2,000 to 2,500 samples per hour from various sources. The average lifespan of a malware file (used with criminal intent) is, however, only seven hours, according to Symantec.

Current AV software tests are still focusing mainly on some kind of “detection scores”, but testing the software against millions of inactive, outdated and thus “dead” files can’t be seen as useful anymore and the results of such tests are not only less meaningful, but they mislead the average user a lot.

Andreas Marx, quoted on the Sunbelt Blog:

http://sunbeltblog.blogspot.com/2007/12/some-additional-commentary-about.html

let’s hope v5 gets ahead of this problem :stuck_out_tongue:

We’re having to hope everything from version 5… I wish it came to beta quicker than it will…