True Aspect

Device performance

Quick answer

Security software consumes processor time, memory, storage input and battery, mostly through continuous inspection of files as they are used. The cost on current hardware is usually modest and steady, with brief peaks during full scans and updates.

Complaints that a security product has made a device slow are common, and they are a mixture of accurate observation and misattribution. Understanding where the work actually happens makes it possible to tell the two apart, and to reduce the cost without disabling protection.

Almost all of the continuous cost comes from one mechanism. Real-time protection inserts itself into the path by which the operating system opens, reads and writes files, so that each operation can be checked before it completes. The check itself is fast; it is the frequency that matters. A system compiling software, indexing a mailbox, copying a large folder or installing an update performs an enormous number of file operations, and a small addition repeated that many times becomes measurable.

Where the cost sits

Real-time file inspection
Continuous and proportional to file activity. Noticeable during bulk operations, negligible while reading a document.
Behavioural monitoring
Continuous observation of running processes, described in behavioural detection. Low but constant, and growing with the number of processes.
Scheduled full scans
A deliberate peak. Every file is read, which is demanding on storage and, on portable devices, on the battery.
Definition updates
Short bursts of network and disk activity, frequent but individually small.
Browser components
Extensions that check links add to the browser's own memory use, which is often where the user notices it.
Bundled extras
Backup agents, password managers, tuning utilities and network tools each run as separate processes. On a constrained device this is frequently the larger share.

A note on published performance figures

Laboratories publish comparative impact measurements, and they are measured on specific hardware with specific workloads. They do not transfer reliably to a particular device. True Aspect does not publish such figures, because it does not conduct tests and will not restate numbers it cannot verify.

Measuring rather than guessing

Both major desktop platforms include a tool that attributes resource use to processes: Task Manager on Windows and Activity Monitor on macOS. Opening one while the device feels slow and sorting by processor or memory use answers the question directly, and the answer is often something else — a browser holding many tabs, a synchronisation client uploading a large folder, a platform update installing in the background, or a search index rebuilding.

Two patterns are worth distinguishing. Slowness that coincides with heavy file activity and subsides afterwards is consistent with real-time inspection and is working as designed. Slowness that is constant, or that began after installing several products at once, is usually about the number of resident components rather than about scanning.

Adjustments that do not weaken protection

  1. Run full scans when the device is idle and on mains power. Most products schedule this and most schedules can be changed. A scan at two in the afternoon on battery is the worst case of both.
  2. Install one security product, not several. Two real-time scanners inspect each other's activity and each other's quarantine, which produces both slowdowns and false alarms.
  3. Deselect bundled components that are not used. A tuning utility or a second password manager that duplicates one already in use is pure overhead.
  4. Keep the operating system current. The interfaces security products use for inspection improve with platform updates.
  5. Consider the hardware honestly. On a device with a mechanical hard drive or 4 GB of memory, the limiting factor is the hardware. Replacing a mechanical drive with a solid-state one changes file-heavy work more than any configuration setting.

Exclusions

Most products allow specific folders, file types or processes to be excluded from inspection. Used precisely, this is legitimate and sometimes necessary — large database files, virtual machine images and software build directories are standard examples, and vendors of such software usually publish the exclusions they recommend.

Used broadly, it is the most effective way to disable protection while believing it is active. Excluding a whole drive, the downloads folder, or all files of a common type removes the inspection exactly where it is most needed. An exclusion should name a specific path, exist for a reason the user can state, and be recorded so it can be reviewed later.

The cost of removing a product

Switching products is where performance problems most often originate, because security software installs components deep in the system and ordinary uninstallation sometimes leaves them behind. Remnants of a previous product and a current one can interact in exactly the way two installed products do. Most vendors publish a dedicated removal tool for this reason, and running it after uninstalling, before installing a replacement, avoids a class of problem that is difficult to diagnose afterwards.

A related point concerns expired subscriptions. A product whose licence has lapsed may continue to run while no longer updating its catalogue, which carries the full performance cost for a diminishing share of the benefit described in signature detection. Either renewing or removing it is preferable to leaving it in place.

Mobile devices and tablets

The picture is different on phones and tablets. Both major mobile platforms sandbox applications so that one app cannot freely inspect another's files, which means mobile security apps cannot perform the continuous file inspection that desktop products do. What they typically provide instead is link checking, Wi-Fi assessment, app permission review and, on Android, scanning of installable packages. The performance cost is correspondingly smaller, and the battery cost comes mainly from background network activity rather than scanning.

Readers comparing a subscription across device types should therefore expect the components to differ by platform rather than assume the desktop feature set is present everywhere. Which components a particular product provides on which platform is a matter for the vendor's documentation; the at a glance entry in this library records only the device types the vendor lists and marks the rest as not stated.

Key terms on this page

Real-time protection
Inspection performed as files are opened, written or executed.
Exclusion
A path, file type or process the product is instructed not to inspect.
Sandboxing
Platform isolation that prevents one application from reading another's data.
Resident component
A part of a product that runs continuously in the background.