True Aspect

A reference library for antivirus concepts

True Aspect explains the ideas behind antivirus software one concept at a time, in short entries written for readers in Australia who want to understand what the software does before deciding whether they need it.

Affiliate disclosure

Some entries on True Aspect link to the Norton AntiVirus Plus website. Those are paid affiliate links: if a reader follows one and buys a subscription, KLIMA Z.A.I., s.r.o. is paid a commission by the affiliate network that operates the link. The reader pays the vendor's normal price; the commission is funded by the vendor, not added to the purchase.

Commission does not decide which concepts appear in this library, what the entries say, or the order they are listed in — entries are listed alphabetically and nothing can buy a position. The full explanation is on the Affiliate Disclosure page.

Index of entries

Behavioural detection
Judging a program by what it does rather than by what it is.
Cloud backup
Why a second copy of a file is the only defence that survives encryption.
Device performance
What security software actually costs in processor time, memory and battery.
Firewalls
Filtering connections, and the difference between the one in the router and the one on the device.
Norton AntiVirus Plus at a glance
What the vendor states about this product, and what it leaves unstated.
Password managers
Storing one strong secret instead of remembering fifty weak ones.
Phishing
Deception aimed at a person, and the narrow part of it software can block.
Ransomware
Encryption used as extortion, and why recovery is a backup question.
Signature detection
Matching files against a catalogue of known malicious code.

How the concepts relate

The entries in this library are not a sequence of steps. They describe layers that overlap, and a reader who understands the overlaps can tell which gaps a product fills and which it leaves open. The diagram below places each entry at the point where it acts: before code reaches the device, at the moment code runs, and after something has already gone wrong.

Where each concept acts Three stages. Before code arrives: firewalls, phishing, password managers. While code runs: signature detection, behavioural detection, device performance. After an incident: ransomware, cloud backup. Before code arrives While code runs After an incident Firewalls Phishing Password managers Signature detection Behavioural detection Device performance Ransomware Cloud backup → → Each stage assumes the one before it will sometimes fail.

Reading across the diagram gives the single most useful idea in the field: every layer assumes the one before it will occasionally fail. Signature detection exists because filtering connections does not catch everything; behavioural detection exists because the catalogue is never complete; and backup is treated here as a security control rather than as housekeeping because neither of those assumes nothing will ever be encrypted.

A reading order for newcomers

A reader starting from nothing gets the most out of the library in this order. Signature detection first, as the oldest idea and the one most people already half-know. Then behavioural detection, which explains why that idea was not enough alone. Then phishing, which moves the problem from the machine to the person. Then ransomware and cloud backup together, since neither makes full sense without the other. The rest, in any order.

The five entries most readers need first

  1. Phishing — because deception aimed at a person is the entry point for most losses reported in Australia, and no scanner addresses the part of it that matters most.
  2. Ransomware — because the consequence is total and the recovery options are decided long before the attack.
  3. Cloud backup — because it is the only item on this list that still works after everything else has failed.
  4. Password managers — because credential reuse turns one breach anywhere into a breach everywhere.
  5. Signature detection — because understanding what a scan actually compares makes every vendor claim easier to read.

Common misunderstandings, corrected

"Antivirus software makes a device safe."
It reduces the chance that known and recognisably behaving malicious code runs. It has no effect on someone voluntarily entering a password into a convincing imitation of a bank's site, which is a far more common way to lose money.
"Macs and phones do not need to be considered."
The platforms differ in how software is installed and sandboxed, which changes what is useful on each. It does not make the phishing, credential and backup entries less relevant, since those concern accounts rather than operating systems.
"A scan that finds nothing proves a device is clean."
A scan proves that nothing matching the current detection set was found in the locations examined. That is a useful statement and a much narrower one.
"Free and paid products differ mainly in detection quality."
They frequently use the same detection engine. The differences are more often in the additional components bundled alongside it, in support, and in licence terms.
"Being careful is enough on its own."
Care prevents a great deal. It does not help when a service a reader uses is breached, when a supplier's invoicing email is compromised, or when a flaw is exploited without any action by the user.

Where Norton AntiVirus Plus sits among the concepts

One entry describes a commercial product rather than a concept: Norton AntiVirus Plus at a glance. It is written only from what the vendor states, and anything unstated is marked as such. True Aspect has a paid affiliate relationship with that product and no other, which is why that entry is the most tightly constrained page here: no feature list from memory, no price, no comparison in its favour.

The vendor's own description, current pricing in Australian dollars, supported systems and licence terms are best read at the source.

Visit the Norton AntiVirus Plus website

What official Australian bodies say, and where

Where an entry makes a claim about risk, law or reporting, it links to the body responsible rather than restating figures second-hand. Readers can go to the same sources directly:

Key terms, A to Z

Behavioural detection · Credential stuffing · Encryption · False positive · Heuristics · Immutable backup · Multi-factor authentication · Phishing · Quarantine · Ransomware · Real-time scanning · Sandbox · Signature · Versioning · Zero-day

Each term is defined where it is used, in the entry it belongs to. Definitions are kept in one place rather than repeated, so a correction only has to be made once.

How entries are written and checked

Entries are written by the KLIMA Z.A.I., s.r.o. editorial team. Each begins with a two-sentence definition, states what the concept does and does not cover, and ends with the limits of the idea. Claims about Australian law or official guidance link to the body responsible; claims that cannot be linked are written as general guidance or left out. No benchmark figures or detection rates appear here, because True Aspect runs no tests and will not reproduce numbers it cannot verify.

Entries are reviewed on a rolling basis and the date of the most recent review is shown in the footer of every page. More detail on the method, including the commercial relationship behind the one product entry, is set out on the About page.