Page 1 of 1

Size of full Defender virus def db fluctuates wildly?

Posted: Tue Apr 02, 2019 12:10 pm
by meerkt
It's puzzling how the size of Microsoft's Defender full definition db doesn't grow continuously, considering the number of virus signatures grows should grow over time. There's a limit to what can be gained from improved compression or definition formats.

Recently there was a strange big drop:

2018/09 database: 200 MB
2018/12 (I think it was): 160 MB
2019/03: 80 MB
2019/04: 120 MB

If they regularly prune older viruses, doesn't that defeat the idea?

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Tue Apr 02, 2019 12:23 pm
by roncat
I would hope they would patch some vulnerabilities, so the need to scan for that particular virus goes away... or they just EOL any remaining vulnerable systems (sorry, DOS 6.22).

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Tue Apr 02, 2019 12:46 pm
by meerkt
Viruses need to be detected even if a vulnerability they relied on was fixed.
I don't think the 60% decrease in size was due to dropping DOS viruses. :)

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Wed Apr 03, 2019 1:22 pm
by ozzuneoj
That is really strange. I'd love to read an explanation of this.

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Wed Apr 03, 2019 1:58 pm
by meerkt
FWIW, I tested it with 36 DOS viruses, including in .COM files. It failed to detect only 1.
Two were deemed Win32 for some reason, the rest as expected.

Trivia: The one it missed was also undetected by AVG, Avast, Kaspersky, but was recognized by ESET, McAfee, and Symantec.

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Wed Apr 03, 2019 2:16 pm
by roncat
Defender must be able to support that thumb drive with a bootable DOS 6.22 image on it... no wonder the virus file is so large.

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Thu Apr 04, 2019 2:33 pm
by Arvald
My guess would be the db grows incrementally with new definitions then every once and a while they incorporate them into a core database.

Re: Size of full Defender virus def db fluctuates wildly?

Posted: Tue Aug 20, 2019 4:24 pm
by meerkt
Also the core db decreases in size.

Anyway, still curious.

2019/6/1 150MB
   mpasbase.vdm 45MB
   mpasdlta.vdm  8MB
   mpavbase.vdm 77MB
   mpavdlta.vdm 12MB
   mpengine.dll 15MB

2019/8/20 114MB
   mpasbase.vdm 51MB
   mpasdlta.vdm  7MB
   mpavbase.vdm 40MB
   mpavdlta.vdm 10MB
   mpengine.dll 14MB