Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Symantec's Ramzan on solving the antivirus puzzle
Search Topic:
Uniqs:
165
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
JRB2 HAPPY BIRTHDAY »
« New security settings in IE8  
AuthorAll Replies


Stem Bolt
Premium
join:2002-11-08
Cleveland, OH

Symantec's Ramzan on solving the antivirus puzzle

»news.cnet.com/8301-1009_3-10278426-83.html
quote:
What are the main challenges with blocking viruses and spam?

Ramzan: One of biggest challenges overall is that these things are rapidly evolving. We're seeing variations upon variation of various types of malware and viruses. The traditional approach of trying to use a signature-based detection to detect that this part file is good or bad is going to be limited. Signatures were very good 10 years ago when there were a small number of samples out there that were on a large number of machines. Nowadays, when you have essentially micro-distribution of a large number of threats, where maybe there are millions and millions of threats out there and each is on only a few machines, having a signature to try to protect against those threats doesn't work as well. That's because you're only protecting a few users at once with a given signature. It doesn't scale nicely. With reputation-based protection, we look at not only what the software is doing, but we might know that this application is only on five machines in the world. That's something we can monitor very easily. Whereas before the attacker would try to be the needle in a haystack and hide...we now have a very powerful magnet so we can find those needles effortlessly.

So is signature-based antivirus protection dead?

Ramzan: No, not at all. I think that signatures are very useful, but in a certain context. There are still threats out there that do get to a large number of machines. For example, we've seen the Conficker, or Downadup worm come out recently. That's a classic example of a threat that makes sense to protect with signatures. Signatures are simple, they're easy to compute, they've been around for a long time. They have their uses, but they only protect you against one spectrum or one part of the spectrum of possible threats out there.
--
Norton 2010 BETA + Online Armor Free + Router/SPI
-
Forums » Up and Running » Security » Security JRB2 HAPPY BIRTHDAY »
« New security settings in IE8  


Wednesday, 11-Nov 03:28:04 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [129] Moto Sold About 100,000 Droids
· [95] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [69] Government Will Release Some Telco Wiretap Lobbying Documents
· [62] Verizon's Hanging Up On Rural America
· [51] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [32] Sprint Announces Job Cuts
· [25] Google Offers Free Holiday Airport Wi-Fi
· [24] Mediacom Hints At 50, 100 Mbps Speeds
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· [Rant] windows 7 is the most retarded os ever and its broke to [Rants, Raves, and Praise]
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· MagicJack Error Broken Storage [MagicJack]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Slow speed lately? [TekSavvy]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· MS forensics tool for law enforcement leaked online via P2P [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Holy work line speeds!! [TekSavvy]