The i-Technology Media!
Register | Log in
   
 
.NET  ·  AJAX  ·  CLOUD  ·  ECLIPSE  ·  FLEX  ·  OPEN WEB  ·  iPHONE  ·  JAVA  ·  LINUX  ·  OPEN SOURCE  ·  ORACLE  ·  PBDJ  ·  SEARCH  ·  SILVERLIGHT  ·  SOA  ·  VIRTUALIZATION  ·  WEB 2.0  ·  WIRELESS  ·  XML
Comments
Improving the Efficiency of SOA-Based Applications
jhv1blz5 wrote: The article validated SOA as an IT architecture paradigm that can be leveraged in many ways. Taking data storage, scalability and application performance to a nifty level using SOA Application Grid infrastructure will no doubt enhance data and application performance on Oracle architecture platforms, it also has the promise of a cost effective and efficient IT delivery model. The very benefits of SOA.
Jul. 3, 2009 10:31 AM EDT
Cloud Computing | Virtualization
November 2 - 4
Register Today and SAVE !..
Did you read today's front page stories & breaking news?
Live Google News by SYS-CON!

Top Three Links You Must Click On


Security
Antivirus Software Is Not Dead – It's Evolving
Identifying good programs

By: Carey Nachenberg
Nov. 21, 2008 09:15 AM

Contrary to some industry observers, antivirus software is not dead. It is, however, undergoing a game-changing transformation.

It has to. After all, the current model of detecting viruses through blacklisting simply cannot keep pace with the unprecedented volume of malware released every day. To continue to be effective, antivirus must transition from the current signature-based model to a new hybrid model that uses whitelisting to allow trustworthy applications, blacklisting to block prevalent known malware, and reputation-based ratings to automatically categorize the "long tail" of unknown malware and legitimate software.

An Inflection Point
By some measurements, the volume of malicious software is now outpacing the production of legitimate programs. Symantec recently measured the adoption rate of new software applications and found that out of almost 55,000 unique applications deployed during a weeklong measurement period on Microsoft Windows PCs, 65 percent were malicious.

It could get worse as attackers adapt. They have already shifted away from mass distribution of a small number of threats to micro distribution of millions of distinct threats. Using servers that generate a new malware strain every few hours - or minutes - they can unleash individual attacks against each victim. So far, cybercriminals have created millions of distinct malware strains, and antivirus software vendors are collecting tens of thousands more every day. If these attack trends continue, the public could face millions of new threats every year.

At the same time, antivirus vendors are feverishly working to generate up to 20,000 new virus fingerprints each day. However, most products detect only a fraction of new malware, even as many strains of older malware go undetected. Furthermore, attackers can easily circumvent most generic signatures by tweaking existing malware files, scanning them with an antivirus scanner, and repeating the process until the scanner no longer detects the infection. Such modifications can be done by hand or, unfortunately, all too easily via automation.

As a result, whereas a few years ago a single signature could protect tens of thousands of users against a widespread threat, today a single signature typically protects less than 20 users against a micro-distributed threat.

Clearly, in such an environment, traditional signature-based detection - or blacklisting - alone is not enough.

Identifying Good Programs
As the volume of malicious code continues to skyrocket, security techniques must increasingly focus less on analyzing malware and more on analyzing "goodware."

Whitelisting has traditionally been used on high-value servers because their static configuration makes a whitelist easy to build. Yet, even though most infections occur on desktops and laptops, whitelisting has not been extended to these systems. Why not? Because desktop machines are far more dynamic than locked-down servers, employees download software packages on them to do their jobs, and desktop applications often self-update - thereby making it extremely challenging for an enterprise to create and update a whitelist for such machines.

Nevertheless, a comprehensive whitelist could virtually eliminate traditional infections on these endpoints. Some companies have taken a do-it-yourself approach wherein the vendor or customer manually constructs the whitelist. Other vendors have chosen to partner with top software OEMs to build the list, while still others deploy Web spider software to gather files for the list. Unfortunately, thus far, none of these approaches have yielded a comprehensive enough and current enough whitelist that can reasonably be used to lock down desktops and servers without costly manual administration.

A new approach to building whitelists supplements whitelisting with new reputation-based protection technologies. Reputation-based protection is game-changing in that it leverages the wisdom of millions of users to provide customers with actionable information about the software they download and install. This helps customers make the right choices based on the experience of other real users just like them. Early indications show that this approach, when complemented by traditional antivirus technology, radically improves protection, especially against the onslaught of personalized malware seen today.

Taming the Long Tail
One of the most difficult challenges of antivirus protection today is figuring out how to deal with threats that are on so few systems that they often go undetected using traditional blacklisting. After all, if only a handful of people in the world have a specific threat, a security vendor has little chance to discover that specific threat and write a signature for it.

Unfortunately, because there are so few common versions of today's malware, malicious programs tend to occupy this so-called "long tail" of software distribution. Similarly, it's difficult for security companies to locate less popular, yet entirely legitimate, software applications and add them to a whitelist. Imagine a small software vendor that caters to just a handful of customers. What are the odds that this vendor's software will be discovered and added to a whitelist in a timely fashion?

This is where the addition of reputation-based security looks promising. A reputation-based rating system for applications can provide users with an accurate security score, not unlike a credit rating, for every application they encounter on the Internet. This enables users to make more-informed decisions about the programs they download before installing them. Moreover, organizations can use the highest-confidence ratings to identify legitimate applications and then automatically populate their whitelists.

Most legitimate software is created for mass distribution and today's malicious programs have extremely limited distribution before they're mutated for the next user. To respond to this, a reputation-based system can leverage a prevalence-based reputation approach to assign lower ratings to less-prevalent software.

For example, an administrator could stipulate policy guaranteeing that only highly prevalent applications - for example, those with at least 10,000 other users - are allowed in an enterprise. Such a policy would weed out all but the most prevalent malware, which traditional fingerprinting via blacklisting can detect easily, yet allow the deployment of most popular legitimate applications.

As another example, a reputation-based system can derive reputation ratings based on the provenance, or source, of the application, and assign higher ratings to applications from known, trusted vendors. Using these and numerous other techniques, organizations can deliver highly accurate reputation ratings for applications that can fundamentally change the efficacy of security software.

With complementary blacklisting, whitelisting and reputation-based technologies safeguarding both enterprise and consumer endpoints, business and homes have a more formidable, long-term solution to the malware epidemic. Perhaps the greatest benefit of a hybrid approach is that it would finally return the burden of antivirus protection from the shoulders of weary customers back to security vendors.

Published Nov. 21, 2008— Reads 1,606
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
About Carey Nachenberg
Carey Nachenberg is a Symantec Fellow in the Security Technology and Response Group at Symantec Corporation.

Add Your Feedback

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers
ADS BY GOOGLE
Breaking Java News
Tieto Signs Long-Term Agreement to Deploy OneSpin Solutions’ Formal Assertion-Based Verification Solution
Free Entertainment With BT Office Furniture
Nationwide Traffic System Deployed in Australia Using ITIS TrafficScience(TM) Cellular Floating Vehicle Data (CFVD) Technology
Sigma-tau Submits Marketing Authorization Application to EMEA for a Novel Anti-Malarial
GoldenAgeMedical.Com Announces National TV Campaign

ADVERTISE   |   MAGAZINE SUBSCRIPTIONS   |   FREE BREAKING-NEWSLETTERS!   |   SYS-CON.TV   |   BLOG-N-PLAY!   |   WEBCAST   |   EDUCATION   |   RESEARCH

.NET Developer's Journal - .NETDJ   |   ColdFusion Developer's Journal - CFDJ   |   Eclipse Developer's Journal - EDJ   |   Enterprise Open Source Magazine - EOS
Open Web Developer's Journal - OPENWEB   |   iPhone Developer's Journal - iPHONE   |   Virtualization - Virtualization   |   Java Developer's Journal - JDJ   |   Linux.SYS-CON.com
PowerBuilder Developer's Journal - PBDJ   |   SEO / SEM Journal - SJ   |   SOAWorld Magazine - SOAWM   |   IT Solutions Guide - ITSG   |   Symbian Developer's Journal - SDJ
WebLogic Developer's Journal - WLDJ   |   WebSphere Journal - WJ   |   Wireless Business & Technology - WBT   |   XML-Journal - XMLJ   |   Internet Video - iTV
Flex Developer's Journal - Flex   |   AJAXWorld Magazine - AWM   |   Silverlight Developer's Journal - SLDJ   |   PHP.SYS-CON.com   |   Web 2.0 Journal - WEB2
Apache   |   CMS   |   CRM   |   HP   |   Oracle Journal   |   Perl   |   Python   |   Red Hat   |   Ruby on Rails   |   SAP   |   SaaS

SYS-CON MEDIA:   ABOUT US   |   CONTACT US   |   COMPANY NEWS   |   CAREERS   |   SITE MAP
SYS-CON EVENTS:   |  AJAXWorld Conference & Expo  |  iPhone Developer Summit  |  Cloud Computing Conference & Expo  |  SOA World Conference & Expo  |  Virtualization Conference & Expo
INTERNATIONAL SITES:   India  |  U.K.  |  Canada  |  Germany  |  France  |  Australia  |  Italy  |  Spain  |  Netherlands  |  Brazil  |  Belgium
 Terms of Use & Our Privacy Statement     About Newsfeeds / Video Feeds
Copyright ©1994-2008 SYS-CON Publications, Inc. All Rights Reserved. All marks are trademarks of SYS-CON Media.
Reproduction in whole or in part in any form or medium without express written permission of SYS-CON Publications, Inc. is prohibited.
 
close this window