July 06, 2009

Symantec desktop security software boasts reputation analysis

Symantec is readying the 2010 editions of Norton Internet Security and Norton AntiVirus, adding to its flagship consumer software a type of malware defense based on what's called reputation analysis.

Traditional signature-based defense "is still there and valid as a last line of defense," says Symantec senior director of product management Dave Cole about the 2010 editions of Windows-based desktop security software out in beta Monday and shipping in the September timeframe for Windows 7, Vista and XP. But signature-based defense, which detects malware through a known match, is a technology under strain due to the enormous explosion in the amount of malware created by cybercriminals. So in the Symantec products, signature-based defense will be working in conjunction with reputation analysis, which decides whether the code is good or bad through statistical sampling and behavioral patterns in order to derive its reputation.

[ Discover what's new in business applications with InfoWorld's Technology: Applications newsletter. ]

"It's a hybrid," Cole says, comparing the malware-detection methodology in the 2010 security-software products to that of a hybrid car that can use both gasoline or battery power to run.

The reputation analysis capability in the 2010 editions of Norton Internet Security and Norton AntiVirus will rely on information gleaned from a community of tens of millions of Symantec customers. It allows for information about attack data to be submitted anonymously.

"We can use that data to statistically infer what's appropriate," Cole says, pointing to Symantec technology called Sonar II to call out to a cloud-based service to see if there are known signatures related to the code that's been identified as suspicious.Many factors, including who is publishing the code and where the Web site is, come into play to make a decision on what's good and bad. And it's Symantec as the judge in getting ride of bad code.

"If it's bad, it's convicted," Cole says. "We tell the user we made a decision."

If there's reasonable doubt, Cole says, the user will get a "detection alert" as a notification the code appears to be malware so the blocking and eradication process will proceed. The user will have a chance to override in these cases, but it won't be advised.

In addition to this reputation-based feature, Symantec is swapping out its older antispam engine for the BrightMail engine, which is expected to boost spam filtering by about 20%.

In addition to antimalware protection, the Norton Internet Security software includes a firewall, antiphishing and the Identity Safe controls. It will also ship with the client software for Online Family, an interactive cloud-based service that helps parents and children reach agreement on appropriate online activities -- and then enforces them through monitoring, blocking and real-time reports, if desired.

That service is free until year-end. Symantec's earlier Parental Controls feature will be retained in the 2010 edition as well.

In addition, the 2010 products for Windows-based machines will include recovery tools that let the user remove any infection by booting outside the operating system that's infected. "It's a scan-and-clean environment," Cole says. "You can scan the system with the latest definitions and remove it."

He added that the 2010 security products will show some of the underpinnings for the reputation data so that the tech-savvy user can learn the nitty-gritty about why an application, uncovered in any particular place, is rated the way it is. That process of displaying reputation-analysis data is expected to increase over time.

Close

On Twitter now

Applications

Powered by Twitter

On Twitter now

additional resources
White Paper - How to Improve Delivery of Advanced Web Applications

White Paper

Virtual Workforce: The Key to Expanding The Business While Cutting Costs

Get the independent advice and expertise you need to support a virtual workforce.

Go inside:
The three-step approach to making a virtual workforce a reality.
The four flavors of client virtualization technologies.
The three key initiatives that solve IT challenges.
Download now »
White Paper: Successfully Secure Your Wireless LAN With Wi-Fi firewalls.

White Paper

Addressing Linux Threats Leveraging Fewer Resources

The increase in Linux popularity has increased the frequency and sophistication of malware attacks. Read this 2 page white paper now to learn how you can protect your Linux environment with real-time protection that is certified by all major Linux vendors.

Download now »
White Paper - The 2009 Handbook of Application Delivery

White Paper

The 2009 Handbook of Application Delivery

Ensuring acceptable application delivery will become even more difficult over the next few years. As a result, IT organizations need to ensure that the approach that they take to resolving the current application delivery challenges can scale to support the emerging challenges. This handbook elaborates on the key tasks associated with planning, optimization, management and control and provides decision criteria to help IT organizations choose appropriate solutions.

Download now »
White Paper - Is Your Backup System Outdated?

White Paper

Mid-range Storage Considerations

A common misconception is that mid-range storage requirements are dramatically different than that of a larger enterprise. Mid-range storage users may require less capacity, but they have similar functionality and management requirements. This ESG paper examines mid-range storage needs and reviews a new solution that adjusts size while retaining value, performance and functionality.

Download now »

Applications Newsletter

Stay informed of the latest news and technologies around application, project and performance management.

White paper

Turn Your IT Department into a Lean Machine

Like any valuable resource, IT is a terrible thing to waste. But by applying the same lean techniques that have been used to streamline manufacturing processes, IT departments can reduce costs, improve performance and better manage resources.

Download now! »

Podcast

Economy Makes Automation a Must-Have Tech for 2009

Stephen Elliot, vice president of strategy for CA's Infrastructure Management and Data Center Automation business unit, explains why difficult economic times drive the need for simplified management capabilities and advanced automation tools.

Listen now! »

White paper

What You Need to Know About Virtual Infrastructure Management - Now

According to a recent study CA conducted with 300 CIOs and top IT executives, 64 percent of respondents say they've already invested in virtualization, and the other 36 percent reported that they plan to invest in virtualization.

Download now! »

Webcast

Leveraging Virtualization and Process Automation

In this video learn about process automation in a virtualized world. How CA and VMware are enabling enterprise datacenter automation.

View now! »
©1994-2010 Infoworld, Inc.