← Field Notes · Detection
What Heuristics Actually Buy You, and What They Cost
Behavioral detection promises to catch the malware nobody has seen yet. It delivers that, and a second bill that rarely gets discussed.
Heuristic and behavioral detection exist to solve a problem signature matching cannot: catching malware on its first appearance, before anyone has analyzed a sample and added it to a list. Instead of asking whether a file matches something already known to be bad, a heuristic engine asks whether a file looks like it might be bad, based on patterns, and a behavioral engine watches what a running program actually does, flagging processes that encrypt large numbers of files quickly, inject code into other processes, or attempt to disable security tools, regardless of whether the executable itself has ever been seen before.
This works, in the sense that it catches things signature matching structurally cannot. It is also the primary reason antivirus software has a reputation, well earned across decades, for slowing computers down and crying wolf. A heuristic engine is making a probabilistic judgment, and probabilistic judgments have error rates in both directions. A false negative lets real malware through. A false positive quarantines a legitimate program, and in security-conscious environments, particularly software development shops where compilers and build tools do genuinely unusual things to memory and the file system, false positives from behavioral engines are common enough to be a standing joke.
The computational cost is real too. Watching every running process's behavior in real time, correlating actions across time and across processes, takes CPU cycles that signature matching, a single hash lookup, does not. This is the actual, unglamorous reason antivirus software earned its reputation for slowing machines down: not the scanning itself, but the always-on behavioral monitoring layered underneath it.
None of this is an argument against heuristics. It is an argument for being honest about the tradeoff. A detection method that catches more unknowns necessarily makes more mistakes doing it, in both directions, and vendors that market behavioral detection as a strict improvement over signature matching, rather than a different tool with a different error profile, are eliding a real cost that shows up on their customers' machines as either a missed threat or an incorrectly quarantined file.
The more defensible position, and the one the more careful security researchers have argued for years, is that these are complementary layers rather than competing generations of technology. Signatures handle the enormous volume of reused, commodity malware with zero ambiguity. Heuristics and behavioral analysis take the harder, genuinely uncertain cases that signatures cannot touch, and accept a worse error rate because the alternative, catching nothing new at all, is worse.