Showing posts with label worm. Show all posts
Showing posts with label worm. Show all posts

Friday, October 5, 2007

Symantec - "We don't (just) sell anti-virus".

I went to a Symantec presentation today to learn about their new End Point Protection and to take a sip of their Kool-Aid.

They took great pains to make sure that the audience was aware that they do not sell anti-virus software anymore - they sell "end point protection". Which, really, is anti-virus with other stuff.

The point is that even according to Symantec's reports viruses are dying out. (By virus I mean a program that self replicates - not a trojan, spyware, rootkit or worm). Trojans and worms and rootkits are becoming easier to modify and deploy and signature lists (against which these uglies are compared and blocked) are becoming too slow.

The moral of the story - viruses are (pretty much) dead... they have been replaced with new threats. Symantec painted a picture of their protection product as the silver bullet that will protect a PC against all the new threats. It looks good but I'm not 100% sold. I'd recommend the product but I'd back it up with a lot of other Information Security goodies.

Friday, September 14, 2007

The Seven Habits of Highly Effective Security Plans [Part 2]

Please read The Seven Habits of Highly Effective Security Plans [Part 1] first.

Stephen starts his book with the idea of a paradigm and goes to great efforts to explain what it is and why one needs to understand it.

In terms of Information Security I think that the paradigm shift has been forced upon us on July 13, 2001 but it has taken until now for us to be able to understand and deal with the new understanding.

That was the date that the Code Red Worm struck. The darling of Security at the time - the firewall was no match for this worm and anti-virus was infective too.

Today the worm would be very much less effective because we now have more defenses. We have proper patch management, IDSs, deep packet inspection firewalls and application security. These were all around in the time of the Code Red Worm, they were just not being used effectively. We had the technology but the mind set was not right.

When the SQL Slammer Worm arrived it proved that we still hadn't learned our lesson. The paradigm shift had not happened yet but we are slowly getting there.

The fact that new worms are coming out all the time but we haven't had a global epidemic of Slammer proportions means that we are learning our lesson. The fact that the Storm worm is still being successful means that there is still some way to go.

Our first paradigm shift was from realising that:
  1. security has to be done all the time
  2. technology alone will not save us
I think the next one is that we can't tack on security. We need to think security from the beginning even if it means somethings need to be redesigned or abandoned totally.

To Be Continued.

Tuesday, May 8, 2007

The Plastic Swimming Pool Theory of Security


This is one of my theories of Security and why it is such a battle.

I'm not sure if I made it up or heard it somewhere but I stand by it.

"When one person pisses in a swimming pool it affects everyone"

This is why patching is so important but ignored. When a PC on the Internet is compromised by a worm the person who is running the PC may be affected a bit. Their link may slow down slightly but when 100,000 of them are used in a bot-net to attack companies it affects the companies, not the person who owns the PC.

It is the same with TJX etc, personal information stolen from their databases leads to identity theft and hence false purchases all over from many different stores. Everyone is affected.

So, just don't piss in the pool, please. And patch!