True Aspect

Signature detection

Quick answer

Signature detection identifies malicious software by comparing files against a catalogue of patterns taken from code that is already known to be malicious. It is fast and precise about what it knows, and blind to anything that is not yet in the catalogue.

Signature detection is the oldest working idea in antivirus software and still the first stage of almost every product sold today. A vendor collects samples of malicious code, extracts something that identifies each one reliably, and distributes that set of identifiers to the software installed on readers' devices. When a file is opened, written or scanned, the software checks it against the set.

The term "signature" is a historical one and slightly misleading. Early signatures were literal byte sequences: a specific run of bytes that appeared in one virus and almost nowhere else. Modern equivalents are more often cryptographic hashes of whole files, fragments matched with wildcards, or small pattern-matching programs that describe a family of related samples. The principle is unchanged — a file is being compared against a description of something previously seen.

What the comparison actually involves

Hash matching
A hash function reduces a file to a short fixed-length value. If two files produce the same value, they are, for practical purposes, the same file. Hash matching is exact: it catches that file and nothing else, so changing a single byte in the malicious file defeats it entirely.
Pattern matching
Instead of describing the whole file, the signature describes a distinctive fragment — a decryption routine, an unusual string, a sequence of instructions. This survives small changes to the rest of the file and can cover a family of variants at once.
Generic and heuristic signatures
Broader rules that describe structural traits shared by a malware family rather than any particular sample. These shade into the territory covered in behavioural detection, and the boundary between the two is a matter of degree rather than of kind.
Reputation lookups
Rather than shipping every identifier to every device, many products send a hash or a fragment to the vendor's servers and receive a verdict. This keeps the local catalogue smaller and the shared one current, at the cost of requiring a network connection and sending information about files to the vendor.

Why the catalogue is never complete

A signature can only be written after a sample exists and someone has obtained it. That creates an unavoidable window between the first appearance of a piece of malicious code and the moment protection against it reaches a device. During that window, signature detection offers nothing against that specific sample.

Attackers have made the window easy to exploit. Automated packing and obfuscation tools can generate thousands of functionally identical variants, each with a different hash, from a single original. Some malicious code is compiled fresh for each target. This does not make signature detection useless — the overwhelming majority of what a typical device encounters is old, mass-distributed and well catalogued — but it does mean a product that relied on signatures alone would be a product with a known and permanent hole in it.

On update frequency

Because the value of a catalogue decays with time, the interval between updates matters more than the size of the catalogue. Products that fetch updates many times a day are describing a different thing from products that update daily, and a device that has been switched off for a fortnight is carrying a fortnight-old catalogue regardless of what the vendor does.

False positives, and why they are treated so seriously

A false positive is a clean file identified as malicious. Where the misidentified file belongs to the operating system or to a widely used business application, the consequence can be a large number of unbootable or broken machines at once. This is the main reason vendors are conservative about broad signatures and test releases heavily before distributing them.

From a reader's point of view, the practical consequences are worth knowing. Files identified as malicious are usually moved to quarantine — an isolated store where the file cannot execute — rather than deleted outright, precisely so that a mistake can be reversed. Software written by small developers, older utilities and self-compiled programs are over-represented among false positives because they are rare, unsigned, and therefore unfamiliar to reputation systems. Overriding a detection is possible in most products and is a decision that should be made only when the source of the file is genuinely known.

Signature detection compared with behavioural detection

The two approaches answer different questions and are used together, not as alternatives.
AspectSignature detectionBehavioural detection
Question askedIs this file one we have seen before?Is this program doing something that malicious programs do?
TimingBefore the file runsUsually while the program is running
Novel threatsNot covered until cataloguedCan be covered without a prior sample
False positivesComparatively rareMore frequent, because behaviour is ambiguous
Resource costLow, mostly at scan timeContinuous, see device performance
Explains itselfYes — names the specific threatOften only as a generic or suspicious-activity label

What this means when reading vendor material

Several common marketing phrases become easier to interpret once the mechanism is clear. "Real-time protection" generally means the signature check runs when a file is created, opened or executed, rather than only during a scheduled scan. "Cloud-assisted" generally means reputation lookups are part of the process. A claim about the number of threats in a database says something about the vendor's collection, not about the device: a device is only as current as its last successful update.

Claims expressed as a detection percentage deserve particular care. Such figures come from a test against a specific sample set at a specific time, and they are not transferable between products, test houses or months. True Aspect does not publish detection figures, because it does not conduct tests and will not restate numbers it cannot verify.

Scheduled scans and on-access checking

Two modes of operation sit behind the same catalogue. On-access checking inspects a file at the moment it is used, which is where the protective value is: a malicious file sitting unopened on a drive does nothing. A scheduled full scan reads everything, including archives and files that have not been touched for years, and its purpose is different — it finds material that arrived before a signature for it existed, or that was stored while protection was disabled.

This explains an outcome that otherwise looks like a contradiction: a device that has been protected continuously can still report detections during a full scan. The catalogue has since grown, and files that passed inspection in March match a signature written in August. That is the mechanism working as designed, not evidence of an earlier miss.

Key terms on this page

Signature
A stored description that identifies a known piece of malicious code.
Hash
A short fixed-length value derived from a file, used to recognise that exact file.
Quarantine
An isolated store where a suspected file is held so that it cannot run and the decision can be reversed.
False positive
A clean file wrongly identified as malicious.
Zero-day
A flaw or sample for which no protection yet exists at the time it is first used.

Where to go for independent guidance

The Australian Cyber Security Centre publishes guidance on keeping devices and software current, including why update intervals matter, at cyber.gov.au. Its advice is written for individuals and small organisations and does not recommend commercial products.