← Back to catalogue
Research draft

antivirus software

vr.tr.antivirus-software · INF.MED

Enable an AI agent to recognise antivirus software, assess its protection state and limits, and determine which inspection or remediation actions are appropriate and authorised.

Thing Registry Information and virtual systems

Research draft, second pass

A second pass drafted this model: the structure a model of this thing needs, and what is known about it in the world. The line under this one says how the second half was obtained - researched against sources, or recalled without web access, in which case nothing here was read anywhere and every claim is a lead to verify. Unreviewed either way.

recalled by Codex without web access - no source was read

Researched by: Codex

Purpose and description

Enable an AI agent to recognise antivirus software, assess its protection state and limits, and determine which inspection or remediation actions are appropriate and authorised.

Antivirus software is security software designed to detect, block, quarantine or remove malicious software using techniques such as signature matching, heuristic analysis and behavioral monitoring.

It can be Inspect enabled protection components, health signals and update status.; Run an authorised scan with explicit targets, resource limits and handling policy.; Update protection components and verify that the update became active.; Review detections and supporting evidence before selecting a response.; Quarantine, remediate or restore an item when supported and authorised, recording the outcome.; Review exclusions and protection settings against the device's intended use and applicable policy..

Distinguishing features

Provides functionality intended to identify or prevent malicious software; a generic file search or integrity checker alone does not qualify.

Produces malware-related verdicts or protection decisions using an identifiable inspection mechanism; a firewall that only filters connections does not qualify on that basis.

May operate on demand, continuously or both; absence of continuous monitoring distinguishes a deployment mode rather than automatically excluding the software.

When embedded in a security suite or endpoint platform, its malware inspection and handling functions can be identified separately from neighbouring functions.

A product's advertised capabilities and an installation's enabled, healthy protections are separate records.

Scope

+ Product, engine and deployment identity, including supported operating environments

+ Malware detection methods, inspection coverage and configured exclusions

+ Protection readiness, update freshness and dependencies

+ Detection verdicts, quarantine and remediation capabilities

+ Evidence of effectiveness, operational costs and privacy implications

- Malware families, samples and attack techniques as independently modelled threats

- The protected device, operating system and its overall security posture

- Network firewall policy and network intrusion detection outside antivirus functionality

- Organisation-wide incident response, threat hunting and endpoint detection and response beyond antivirus functions

- Backup services and general data recovery

- Generic software licensing and distribution systems beyond their effects on antivirus operation

Characteristics

Product and engine identity
Vendor, product, edition, product version and detection engine version Links capabilities, support conditions and assessment evidence to the software actually deployed.
Protection mode
On-demand, scheduled, real-time or a documented combination Determines when inspection occurs and which exposure periods remain.
Inspection coverage
Documented targets such as files, archives, memory, processes, scripts, boot areas or removable media Prevents an agent from assuming that protection of one target implies protection of all targets.
Detection mechanisms
Documented mechanisms such as signatures, heuristics, behavioural analysis, reputation queries or model-based classification Identifies what evidence the software uses and which dependencies or limitations must be investigated.
Operational protection state
Active, partially active, disabled, failed or unknown, with observation time and component detail Installation alone does not establish that protection is operating.
Protection update age
Elapsed hours since each relevant engine, signature or detection-content update; unknown where unavailable Supports freshness assessment against the product's update model and applicable policy.
Exclusion configuration
Excluded paths, processes, file types or other targets, with matching semantics and approving authority Makes deliberate inspection gaps visible and reviewable.
Permitted response actions
Report, block, terminate, quarantine, disinfect, delete or restore, as supported and authorised Separates technical capability from permission to change the protected system.
Evaluation evidence
Test report linked to product version, settings, platform, date, workload and threat set Keeps effectiveness and performance claims tied to the conditions under which they were measured.

Also called

Avira Free AntiVirusAntiVir PersonalEdition PremiumAvira Antivirus Premium 2012

Where this came from

wikidata · CC0 1.0

Drafted structure

Bundle to layer to finding to question, as the second pass will find it: 6 bundles · 11 layers · 19 findings · 37 questions.

Antivirus identity and boundaries Establishes which antivirus software is represented and separates its functions from the surrounding security platform.

An agent must identify the actual engine and deployment before applying capability claims or taking protection actions.

Product and engine

Identifies the product offering and the malware inspection implementation it uses.

Identifiable antivirus component

Record the product, edition and engine identities, including any separately supplied inspection component.

  1. Which product, edition and engine versions identify this antivirus implementation? definition
  2. Which vendor documentation or installed-component evidence establishes these identities? provenance

Deployment and functional boundary

Connects the antivirus component to its installation and identifies neighbouring security functions.

Deployed protection boundary

Distinguish the antivirus installation, its protected environment and its management service from broader endpoint or network security functions.

  1. Which device or execution environment hosts this installation, and which management service controls it? definition
  2. Which functions belong to antivirus protection, and which belong to firewall, endpoint investigation or other neighbouring models? boundary
Malware inspection and verdicts Describes what the software can inspect and how its detection results should be interpreted.

Protection coverage and verdict meaning must be explicit to avoid treating uninspected content or an uncertain result as safe.

Inspection targets and gaps

Records supported inspection targets and limits that prevent their examination.

Effective inspection coverage

Record enabled inspection targets alongside exclusions, access restrictions and limits on encrypted, nested or oversized content.

  1. Which file, archive, memory, process, script or boot targets can this deployment actually inspect? boundary
  2. Which exclusions, permission failures or content limits cause inspection to be skipped or incomplete? measurement
  3. How does the software expose skipped and incompletely inspected targets to an agent? definition

Detection evidence and semantics

Connects detection mechanisms to the meanings and limitations of reported verdicts.

Interpretable malware verdict

Preserve the reported classification, inspection context and supporting evidence without equating every alert with confirmed malware.

  1. Which documented mechanisms contribute to this verdict, and what evidence does the product expose? provenance
  2. How are malware, suspicious content, potentially unwanted software, inspection failure and no detection distinguished? definition
  3. What additional evidence is required before acting on an ambiguous or disputed detection? action
Protection readiness and maintenance Captures whether configured protection is operating and receiving the resources it needs.

A present or recently updated installation may still provide incomplete protection because components, permissions or dependencies have failed.

Runtime protection health

Evaluates the operating state of enabled protection components and scheduled inspection.

Verified protection operation

Record component health, real-time protection state and scan completion evidence with timestamps.

  1. Which health signals show that enabled protection components are operating rather than merely installed? measurement
  2. When did each required scan last complete, and which targets or errors remained unresolved? measurement
  3. Which supported recovery action applies when a component stops or a required scan repeatedly fails? action

Updates and service dependencies

Tracks protection updates and dependencies on support, subscriptions and remote services.

Maintained detection capability

Record update freshness and identify which protection functions degrade when updates or external services are unavailable.

  1. When were the engine and applicable detection contents last successfully updated and activated? measurement
  2. Which functions depend on connectivity, an active entitlement or continued support for this operating environment? boundary
  3. What documented freshness criteria and recovery steps apply when updates or remote lookups fail? action
Detection response and recovery Models the handling of detected items from initial response through verification or restoration.

Antivirus actions can interrupt workloads or remove needed data, so an agent needs explicit authority, item identity and outcome evidence.

Response policy and authority

Separates available handling mechanisms from the actions permitted for a particular detection.

Authorised detection handling

Associate each response with the detected item, applicable policy, approving authority and expected operational effect.

  1. Which response actions are supported for this detection and target type? definition
  2. Which actions may the agent execute automatically, and which require approval under the applicable policy? action
  3. Which running processes, shared files or essential services could the proposed response affect? boundary

Quarantine and remediation outcomes

Tracks isolated items, completed remediation and conditions for restoration.

Traceable remediation and restoration

Preserve original item identity and location, response results, residual concerns and the evidence supporting any restoration.

  1. What evidence confirms that blocking, quarantine or remediation succeeded, and what remains unresolved? measurement
  2. How is a quarantined item linked to its original location, detection evidence and retention conditions? provenance
  3. What review and authorisation are required to restore an item or reverse a false-positive response? action
Effectiveness and operational tradeoffs Assesses evidence for protection quality alongside performance, compatibility and data handling.

An agent must judge whether protection is suitable for the actual workload without generalising beyond test evidence or ignoring its operational effects.

Protection quality evidence

Records bounded evaluation results for detection, prevention and false positives.

Contextualised effectiveness results

Bind each reported result to its test population, date, version, configuration and outcome definition.

  1. Which inspected reports support effectiveness claims for the relevant version and configuration? provenance
  2. How were detection, successful prevention and false-positive rates measured, including their denominators? measurement
  3. Which threats and operating conditions were outside the evaluation and therefore remain unassessed? boundary

Workload fit and data handling

Examines inspection overhead, coexistence requirements and information sent outside the protected device.

Acceptable protection footprint

Record workload impact, compatibility evidence and remote data flows before changing protection settings.

  1. What CPU, memory, storage I/O and application-latency effects occur during representative scans and real-time inspection? measurement
  2. Which compatibility or coexistence requirements constrain use with other security software and critical applications? boundary
  3. Which samples, file metadata or telemetry may leave the device, and which controls and permissions govern that transfer? action
Evidence and external alignment What the world already says about this thing, gathered so the model can be checked against it.

A model that cannot be lined up against existing standards, identifiers and practice cannot be adopted by anyone who already uses them.

Reported evidence

Findings from the breadth pass, kept separate from the structural claims.

Check these first

Recalled without web access and unsourced; every item is a lead to verify.

  • This describes the functional software category, rather than a particular product, release, licensed copy or installation.
  • Standards are recalled references, not verified citations; applicability and edition-specific requirements need checking.
  • No universal typical detection rate or false-positive rate is defensible without specifying testing methodology, samples, configuration and date.
  1. Which of these check these first hold for the sense of antivirus software this model covers, and on what evidence? provenance

Kinds and varieties

Recalled without web access and unsourced; every item is a lead to verify.

  • Real-time endpoint protection
  • On-demand malware scanners
  • Centrally managed enterprise antivirus
  • Gateway antivirus for email or file traffic
  • Bootable rescue scanners
  1. Which of these kinds and varieties hold for the sense of antivirus software this model covers, and on what evidence? provenance

Identifiers and schemes

Recalled without web access and unsourced; every item is a lead to verify.

  • Common Platform Enumeration (CPE) - cpe:2.3:a:<vendor>:<product>:<version>:... - Identifies particular antivirus software products and versions, where catalogued; it does not identify the general concept.
  • Cryptographic file hash - SHA-256: 64 hexadecimal characters - Identifies an exact installer, executable or malware sample by its bytes, rather than identifying a product across versions.
  1. Which of these identifiers and schemes hold for the sense of antivirus software this model covers, and on what evidence? provenance

Standards and regulation

Recalled without web access and unsourced; every item is a lead to verify.

  • NIST SP 800-53, control SI-3, Malicious Code Protection - issued by the US National Institute of Standards and Technology.
  • ISO/IEC 27002 - issued by ISO and IEC; includes guidance on protection against malware.
  1. Which of these standards and regulation hold for the sense of antivirus software this model covers, and on what evidence? provenance

Real-world use

Recalled without web access and unsourced; every item is a lead to verify.

  • Scanning downloaded files, attachments and removable media before execution or opening.
  • Monitoring endpoints for malicious files and suspicious execution behavior.
  • Quarantining or removing detected malware during incident response.
  • Applying centrally managed protection policies and collecting detection reports across organizational devices.
  • Scanning a compromised system from a separate recovery environment.
  1. Which of these real-world use hold for the sense of antivirus software this model covers, and on what evidence? provenance

Typical measurements

Recalled without web access and unsourced; every item is a lead to verify.

  • Detection rate - 0-100 by definition; observed results depend on the test corpus and conditions. - %
  • False-positive rate - 0-100 by definition; meaningful comparison requires a specified benign test corpus. - %
  1. Which of these typical measurements hold for the sense of antivirus software this model covers, and on what evidence? provenance

Failure modes and hazards

Recalled without web access and unsourced; every item is a lead to verify.

  • Missing new, obfuscated or otherwise evasive malware.
  • Misclassifying legitimate software as malicious and disrupting work through blocking or quarantine.
  • Losing protection because updates fail, protection is disabled or configuration is inadequate.
  • Increasing resource consumption or causing compatibility problems with applications and other security software.
  • Introducing vulnerabilities through privileged scanning components that process attacker-controlled files.
  1. Which of these failure modes and hazards hold for the sense of antivirus software this model covers, and on what evidence? provenance

Regional variation

Recalled without web access and unsourced; every item is a lead to verify.

  • Rules governing telemetry, sample submission and cross-border data transfers can affect cloud-assisted scanning deployments.
  • Government procurement restrictions and approved-product requirements can affect which antivirus products organizations may deploy.
  1. Which of these regional variation hold for the sense of antivirus software this model covers, and on what evidence? provenance

Neighbouring kinds and how to tell them apart

Recalled without web access and unsourced; every item is a lead to verify.

  • Anti-malware software - The terms substantially overlap in modern usage; antivirus historically emphasized viruses, while anti-malware explicitly names the broader threat category.
  • Endpoint detection and response - EDR emphasizes endpoint telemetry, investigation and response workflows; antivirus emphasizes malware detection and prevention, although suites combine them.
  • Firewall - A firewall controls network traffic according to policy; antivirus evaluates files or execution behavior for malicious content or activity.
  • Computer virus - A virus is malicious code that replicates by infecting other code or host objects; antivirus is software intended to defend against malware.
  • Antivirus software installation - An installation is a deployed instance with a particular version, configuration and update state; the registered thing here is the software category.
  1. Which of these neighbouring kinds and how to tell them apart hold for the sense of antivirus software this model covers, and on what evidence? provenance

What the second pass must settle

  • Does the existing world-model catalogue already cover antivirus software, requiring this registry entry to link to that publication?
  • Should this entry include gateway and server-side antivirus implementations, and what deployment-specific extensions would they require?
  • Which primary sources establish a useful common vocabulary for verdicts and remediation outcomes across products?
  • How should protection readiness be assessed for products whose detection capability depends substantially on remote services rather than locally versioned detection content?
  • Which evaluation evidence and workload-specific thresholds are sufficient to judge effectiveness, false-positive burden and performance acceptability?