Latest AV weapons for disarming software miscreants
"We know that virus writers test their codes against signature-based detection. Behavior-based methods are a necessary trade-off. Signature-based methods are still more effective with established infections. Behavior-based methods treat the newest types of infections," said David Finger, product marketing manager for Trend Micro.
In the early days of antivirus protection, all vendors used basically the same approach. Antivirus software scanned a computer's memory and all the files on the hard drive, and then compared them to a database of signatures that matched known malicious code.
The only real difference among antivirus software vendors was in the ability of their researchers to find new malicious code before their competitors did. How rapidly and how often vendors issued signature updates also differentiated good antivirus programs from the better ones.