Whats wrong with defensive systems that learn over time by adding new virus definitions or attack signatures?
What we are very bad at is dealing with attacks that are new, that we have not seen before. The only strategy that can be used today is something called “anomaly detection.” The problem with that is that what looks anomalous may in fact be valid. By the time you turn the sensitivity of anomaly detection up high enough that it sees most attacks, it’s also issuing many false alarms.