Blocking the new attacks
Most antivirus software uses what is known as "signature-based" technology, which searches for files or packets that contain the distinctive traces of known viruses.
By contrast, some of the cutting-edge security technology emerging today uses "behavior-based" tactics that search out files or packets that show signs of suspicious activities. Suspicious activity could entail a small, rogue application opening an e-mail address book and sending mail to every address in it.
"The real problem is being able to block viruses," Sabo said. "Patch propagation takes time, so antivirus programs are the only defense for most people." Given the new generation of viruses, however, the older methods can no longer protect corporate networks or individual computers.
"Traditional antivirus programs can't defend against malicious scripts that are not referenced in the signature database," Sabo said, pointing out that firewalls fall short as a complete defense for similar reasons. "Firewalls deal with packets of data. They cannot see what a Web page is doing."
.: Hacker-Antivirus Race
"When a new vulnerability is released, there is a race between hackers and the antivirus companies," Sabo told the Finjan seminar audience. The computer user is very much at risk of infection during the first critical hours or days after a virus is released. Blended attacks pose more than one level of threat, so just disabling ActiveX controls using Internet Explorer's settings is futile. Disabling ActiveX controls can cause additional trouble anyway because so many applications rely on ActiveX controls to work properly.
Antivirus programs that are good at catching known attacks should constitute the first line of defense. "We then analyze what gets through because it isn't yet referenced in the signature database of the antivirus program," Sabo said.
Finjan's new defense system, known as Vital Security, is an integrated suite that includes URL filtering, spam control, content filtering and SSL scanning. It examines mobile code, scripts, processes and various applications by analyzing and monitoring the behavior of active content using a technology called "sand-boxing."
.: A Better Mousetrap
Finjan officials stressed that the Internet threat is very real. Because e-mail filtering is stopping almost all traditional attacks, hackers are now looking for new delivery methods.
Hackers seem to have found the answer, and it is the Internet. These new viruses are so dangerous because they do not require users to do anything to get the virus.
Only behavior-blocking software can repel these new kinds of attacks. Currently, consumers are at a distinct disadvantage because of the way the most popular operating systems are built. As the war escalates, however, it's certain that more antivirus companies, like Finjan, will incorporate behavior-blocking technology into their software.
Useful links:
123 Kidz Area.com Your Family Internet Directory - Child Safe Family Friendly.
Online games for young and old, Resources and tips for parenting, Shopping,
Coloring, printables, e-cards - we have something for the entire family!
A Biz Directory - An internet directory offering webmasters free and paid website submissions.
Elib Directory : E-commerce and shopping online in Africa :Human edited, quality, international directory of shopping related websites. Contains sites of which the primary focus is to allow the consumer to select and obtain goods and services over the Web.
