Signature-based detection is a method of identifying malware and attacks by comparing files or network traffic with a database of known patterns, called signatures.
How signature-based detection works
A signature describes something unique to a known threat. Common forms include:
- Hashes – the MD5 or SHA-256 value of a malicious file; exact but defeated by changing a single byte.
- Byte patterns and strings – sequences of code or text typical of a malware family, often with wildcards.
- Rules – combinations of conditions, such as YARA rules for files or Snort and Suricata rules for network traffic in an intrusion detection system.
Vendors analyse new samples, write signatures and push database updates to clients several times a day. The scanner checks files on access, on download and during scheduled scans.
Why signature-based detection matters
Signatures are fast, precise and produce few false positives, which makes them the foundation of antivirus engines such as the open-source ClamAV and of network security tools. They are also easy to share: indicators and rules published by researchers let many organisations detect the same threat quickly.
The weakness is that signatures only detect what is already known. Zero-day malware, polymorphic malware that changes with each copy, packed or obfuscated files and fileless attacks can slip through until a new signature is written. Criminals routinely test their samples against public scanners before distribution. For this reason modern security products combine signatures with heuristic analysis, behavioural monitoring, sandboxing and machine learning.
How signature-based detection is used
- Keep signature databases updated automatically on all endpoints and gateways.
- Use custom YARA and IDS rules for threats specific to your organisation.
- Do not rely on signatures alone; add behaviour-based detection and EDR.