| |||||||
| Data Security Viruses, Firewalls and Safe computing |
![]() |
| | LinkBack | Thread Tools | Rate Thread |
| ||||
| Study: Antivirus Software Catches About Half Of Malware, Misses 15 Percent Altogether Written by Daniel Tuesday, 03 March 2009 Newly released data from Damballa finds nearly 5 percent of machines in enterprises are bot-infected Mar 02, 2009 | 02:43 PM By Kelly Jackson Higgins DarkReading About 3 to 5 percent of all systems in an enterprise are infected with bot-related malware -- even within organizations running up-to-date antimalware tools, according to new data from Damballa. [Front page...]
__________________ "Though all men live in ignorance before mystery, they need not live in darkness... Justice is foundation and ETERNAL." DKE "All that we do is touched by Ocean Yet we remain on the shore of what we know." Richard Wilbur ![]() Subscribers! Ask Pitch about a Custom Sig Graphic |
| ||||
| I'm going to get on my soapbox now ![]() This merely firms my belief that anti-virus software is overrated. It can't keep in step with the number of malicious programs that are introduced each day, and isn't able to be proactive. It is only as effective as the last virus definitions it has. Anyone serious about security should be using three things: HIPS-type behavioral software [which has the capability of being proactive; it doesn't need definitions], a firewall, and most importantly, good, safe surfing habits. How you get members of an organization to use the third thing is completely beyond me, though. I haven't run resident anti-virus in over two years. I find them to be clunky, bloated, and only marginally effective - with the exception of my favorite, NOD. I do run on-demand scans regularly, and have not had a virus infection in any of my machines in all of that time. Remember that I run 2 Internet shops; that means that Joe Customer comes in and surfs where he wants. He plugs in his thumb drive [God knows where it's been]. He isn't employing safe surfing habits [for sure]. Here's why[unashamed plug for a great product here]: SoftSphere Technologies, the official site of the DefenseWall HIPS - Host Intrusion Prevention System - Sandbox, Virtualization, Anti-Spyware, Anti-Rootkit, Anti-Malware, Anti-Keylogger And their forums, where the developer himself is present daily: Gladiator Security Forum -> SoftSphere Technologies Support Forums I am fairly intimate with this software, I have been a beta-tester for some time now, and I can say that it does everything it says it can. It has a small footprint, and won't affect your normal operations. In fact, it requires very little setup and you will most likely forget it's there after a while. It only requires you to understand the trusted-untrusted rules model and how to use it. And the support is second to none on the forum, with most problems addressed in a matter of hours. It's not free, but there is a fully functional trial on the website. Check it out, and ask me if you need more info.
__________________ #1: Tt Armor, ASUS Maximus Extreme, Q6600@3.6G, 2G Corsair Dominator DDR3-1800, Tagan BZ900W, H2O by Swiftech, 2xLeadtek 9600GT, 2xRaptor 150G RAID0, Logitech G15/G5, XP SP3 #2: Tt Shark, ASUS A8N32-SLI Deluxe, Opteron 185@3.15G nude, 2G Corsair XMS, Tt ToughPower750, H2O by Tt, 2xASUS 8800GT, 2xRaptor 74G RAID0, Raptor 150G, Sidux "Moros", BFS Kernel #3, #4: Opteron 170@2.75G nude, A8N-SLI Deluxe, Ubuntu 9.04.......#5: A64x2 4800+@2.8G.......#6-40: Pentium D 3.0G Last edited by ThunderRd; 3rd March, 2009 at 10:30 PM. |
| ||||
| Quote:
The HIPS would let you know that something wants to execute, and would ask you if it is OK. Of course, answering this question *correctly* requires a knowledge of your own system. Some HIPS, like Core Force and Neoava, are somewhat chatty, and require a fair amount of user interaction. DefenseWall is an example of a HIPS that doesn't need as much interaction, and is a good introduction to a layered security. It is different because of the basic trusted/untrusted model. I don't pretend to be an expert here, and welcome any comments pro or con. I know only what I know, and I am *personally* convinced that we can be SAFER by using the above strategy, rather than blindly relying on commercial anti-virus programs.
__________________ #1: Tt Armor, ASUS Maximus Extreme, Q6600@3.6G, 2G Corsair Dominator DDR3-1800, Tagan BZ900W, H2O by Swiftech, 2xLeadtek 9600GT, 2xRaptor 150G RAID0, Logitech G15/G5, XP SP3 #2: Tt Shark, ASUS A8N32-SLI Deluxe, Opteron 185@3.15G nude, 2G Corsair XMS, Tt ToughPower750, H2O by Tt, 2xASUS 8800GT, 2xRaptor 74G RAID0, Raptor 150G, Sidux "Moros", BFS Kernel #3, #4: Opteron 170@2.75G nude, A8N-SLI Deluxe, Ubuntu 9.04.......#5: A64x2 4800+@2.8G.......#6-40: Pentium D 3.0G |
| ||||
| The biggest issue that I see is that HIPS, AV and other similar software are all sticking plasters to cover up problems within the OS security model and processor hardware. Not all malware is designed to be written to disk - there's a number of examples that are designed to execute in the process space of whatever they've attacked. These don't write themselves to disk, and there's no clicking on them to start them. Javascript based malware served over SSL is an example - especially as it's designed to remain within the web browser, rather than affect other programs. That still gives it the capability of intercepting data entered into a web browser.
__________________ |
![]() |
| Tags |
| antivirus , virus |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
| Rate This Thread | |
| |
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Software Study Finds "No Significant Relationship" Between School Shootings and Viole | Daniel ~ | GAMES! OH YEAH! | 0 | 26th January, 2009 01:27 PM |
| Half-Life resurrected with Half-Life 2 Engine by Fans | danrok | GAMES! OH YEAH! | 11 | 3rd January, 2009 09:01 AM |
| malware and phishing -- skyrocketed at rates of 50 to 200 percent. | Daniel ~ | Data Security | 8 | 29th March, 2007 01:29 PM |
| Falcon flies to space but misses orbit | Gizmo | Random Nonsense! | 14 | 22nd March, 2007 07:10 PM |
| MS IE patch misses the mark | Southern Man | Random Nonsense! | 2 | 18th May, 2002 05:15 PM |