Free Newsletters
InfoWorld Daily

InfoWorld
Log-in | Register

Malware flood driving new AV

Symantec researchers say number of malicious applications is rapidly outpacing the volume of legitimate programs, forcing some to rethink AV, defense tactics


If only a few people among the millions of Symantec customers who could contribute usage data to such a program were utilizing some application in question, it would be prudent to recommend that people avoid the program until its nature has been better determined, he said.

Using opt-out tools that provide anonymous feedback on applications that were built into Symantec's existing Norton AntiVirus and Internet Security 2008 products, the company is already gathering the type of data necessary to create such a system of recommendation.

"Right now this is just a long-term research project, but we hope that as we get more users involved in the system, we can truly get a better idea of what is on people's computers so that we can identify malicious software based on the demographics of who is using it, versus what it does," Nachenberg said. "We're hoping to get more clarity through the large base of users we have; by collecting this data we should be able to get the most comprehensive view of the usage patterns to derive reputation information for everything they use."

Faced with questions over potential privacy issues driven by Symantec's ability to watch just who is using what applications and how, the researcher reiterated that users must be made aware of the data collection, allowed to opt-out, and guaranteed that all the information aggregation is done in an anonymous fashion.

By offering users the ability to decide whether or not to use an application based on demographics, versus simply blocking programs based on its own observations, the company will also give people more freedom to determine what tools they feel are appropriate to use, he said.

"If we know that only five people are using a program, given the tens of millions of users we ultimately hope to have in the system, we can be totally objective and recommend that people wait until it is scrutinized further before using it," the researcher said. "We will need to have some manual process for white-listing programs as well, but we think that using this approach we can deliver a reasonable amount of quality with a low false positive rate."

If the volume of new malware strains arriving on the Web continues to outpace the proliferation of legitimate programs, Nachenberg said that AV vendors including Symantec may need to move to a white-listing approach in general, and focus more attention on identifying good applications instead of trying to chase down all the bad.

"If there is less software to analyze that is good, it makes more sense to spend our time scanning for good programs and simply telling our users to avoid everything else," he said. "We're considering models where we can produce the world's largest up-to-date white list of software, but it's not something we can put together in a year; maybe in two-to-three years time."

Matt Hines is a senior writer at InfoWorld.
« PREVIOUS PAGE | 1 | 2 


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





REMOTE ACCESS: MAINTAIN SECURITY AND DECREASE THE BURDEN ON IT
Join this interactive webcast to discover how IT Managers can control access rights, end-user security settings and end-point authorization. Sponsor: Citrix(R) GoToMyPC(R) Corporate

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 10/10/2008

A look back at the week: AMD splits into two, Panasonic sets world record...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist