A reference library for antivirus concepts
True Aspect explains the ideas behind antivirus software one concept at a time, in short entries written for readers in Australia who want to understand what the software does before deciding whether they need it.
Affiliate disclosure
Some entries on True Aspect link to the Norton AntiVirus Plus website. Those are paid affiliate links: if a reader follows one and buys a subscription, KLIMA Z.A.I., s.r.o. is paid a commission by the affiliate network that operates the link. The reader pays the vendor's normal price; the commission is funded by the vendor, not added to the purchase.
Commission does not decide which concepts appear in this library, what the entries say, or the order they are listed in — entries are listed alphabetically and nothing can buy a position. The full explanation is on the Affiliate Disclosure page.
Index of entries
- Behavioural detection
- Judging a program by what it does rather than by what it is.
- Cloud backup
- Why a second copy of a file is the only defence that survives encryption.
- Device performance
- What security software actually costs in processor time, memory and battery.
- Firewalls
- Filtering connections, and the difference between the one in the router and the one on the device.
- Norton AntiVirus Plus at a glance
- What the vendor states about this product, and what it leaves unstated.
- Password managers
- Storing one strong secret instead of remembering fifty weak ones.
- Phishing
- Deception aimed at a person, and the narrow part of it software can block.
- Ransomware
- Encryption used as extortion, and why recovery is a backup question.
- Signature detection
- Matching files against a catalogue of known malicious code.
How the concepts relate
The entries in this library are not a sequence of steps. They describe layers that overlap, and a reader who understands the overlaps can tell which gaps a product fills and which it leaves open. The diagram below places each entry at the point where it acts: before code reaches the device, at the moment code runs, and after something has already gone wrong.
Reading across the diagram gives the single most useful idea in the field: every layer assumes the one before it will occasionally fail. Signature detection exists because filtering connections does not catch everything; behavioural detection exists because the catalogue is never complete; and backup is treated here as a security control rather than as housekeeping because neither of those assumes nothing will ever be encrypted.
A reading order for newcomers
A reader starting from nothing gets the most out of the library in this order. Signature detection first, as the oldest idea and the one most people already half-know. Then behavioural detection, which explains why that idea was not enough alone. Then phishing, which moves the problem from the machine to the person. Then ransomware and cloud backup together, since neither makes full sense without the other. The rest, in any order.
The five entries most readers need first
- Phishing — because deception aimed at a person is the entry point for most losses reported in Australia, and no scanner addresses the part of it that matters most.
- Ransomware — because the consequence is total and the recovery options are decided long before the attack.
- Cloud backup — because it is the only item on this list that still works after everything else has failed.
- Password managers — because credential reuse turns one breach anywhere into a breach everywhere.
- Signature detection — because understanding what a scan actually compares makes every vendor claim easier to read.
Common misunderstandings, corrected
- "Antivirus software makes a device safe."
- It reduces the chance that known and recognisably behaving malicious code runs. It has no effect on someone voluntarily entering a password into a convincing imitation of a bank's site, which is a far more common way to lose money.
- "Macs and phones do not need to be considered."
- The platforms differ in how software is installed and sandboxed, which changes what is useful on each. It does not make the phishing, credential and backup entries less relevant, since those concern accounts rather than operating systems.
- "A scan that finds nothing proves a device is clean."
- A scan proves that nothing matching the current detection set was found in the locations examined. That is a useful statement and a much narrower one.
- "Free and paid products differ mainly in detection quality."
- They frequently use the same detection engine. The differences are more often in the additional components bundled alongside it, in support, and in licence terms.
- "Being careful is enough on its own."
- Care prevents a great deal. It does not help when a service a reader uses is breached, when a supplier's invoicing email is compromised, or when a flaw is exploited without any action by the user.
Where Norton AntiVirus Plus sits among the concepts
One entry describes a commercial product rather than a concept: Norton AntiVirus Plus at a glance. It is written only from what the vendor states, and anything unstated is marked as such. True Aspect has a paid affiliate relationship with that product and no other, which is why that entry is the most tightly constrained page here: no feature list from memory, no price, no comparison in its favour.
The vendor's own description, current pricing in Australian dollars, supported systems and licence terms are best read at the source.
Visit the Norton AntiVirus Plus website
Paid affiliate link. KLIMA Z.A.I., s.r.o. earns a commission on subscriptions bought after following it, at no additional cost to the reader.
What official Australian bodies say, and where
Where an entry makes a claim about risk, law or reporting, it links to the body responsible rather than restating figures second-hand. Readers can go to the same sources directly:
- The Australian Cyber Security Centre publishes plain-language guidance for individuals and small business at cyber.gov.au, and operates ReportCyber for reporting cybercrime.
- Scamwatch, run by the National Anti-Scam Centre, collects and publishes scam reports at scamwatch.gov.au.
- The Office of the Australian Information Commissioner oversees the Privacy Act 1988 (Cth) and the Notifiable Data Breaches scheme at oaic.gov.au.
- The Australian Competition and Consumer Commission administers the Australian Consumer Law, including the consumer guarantees that apply to software sold in Australia, at accc.gov.au.
- The eSafety Commissioner handles online safety, including image-based abuse and harm to children, at esafety.gov.au.
Key terms, A to Z
Behavioural detection · Credential stuffing · Encryption · False positive · Heuristics · Immutable backup · Multi-factor authentication · Phishing · Quarantine · Ransomware · Real-time scanning · Sandbox · Signature · Versioning · Zero-day
Each term is defined where it is used, in the entry it belongs to. Definitions are kept in one place rather than repeated, so a correction only has to be made once.
How entries are written and checked
Entries are written by the KLIMA Z.A.I., s.r.o. editorial team. Each begins with a two-sentence definition, states what the concept does and does not cover, and ends with the limits of the idea. Claims about Australian law or official guidance link to the body responsible; claims that cannot be linked are written as general guidance or left out. No benchmark figures or detection rates appear here, because True Aspect runs no tests and will not reproduce numbers it cannot verify.
Entries are reviewed on a rolling basis and the date of the most recent review is shown in the footer of every page. More detail on the method, including the commercial relationship behind the one product entry, is set out on the About page.