All the latest UK technology news, reviews and analysis

SoBig opens a new can of worms

by Iain Thomson

More from this author

04 Sep 2003

Be the first to comment

  • Tweet this

The flurry of worms, Trojans and other malware is forcing corporates to rethink their security systems, boosting interest in alternatives to traditional antivirus software.

With security spending expected to rise, IT directors are now seriously considering running combination services, which use a mixture of heuristic and more traditional virus identification files, to block fast-spreading viruses.

Heuristic scanning systems, which do not identify specific malware but block emails based on their behaviour, performed well at identifying and stopping SoBig infections.

It was stopped because its transmission system mimicked spam distribution software, which was picked up by heuristic scanning.

Neil Hammerton, managing director at EMF Systems, which offers both antivirus and heuristic scanning, said conventional software has to find a virus and build an identity file before it can be banned.

"Modern viruses are so fast that you need to be able to react fast. Heuristic scanning can pick up on malware very quickly; none of our customers got hit by the virus."

Heuristic scanning looks at the capabilities and activities of files within a PC or by scanning email servers.

If an application contains code likely to be found in malware the code is isolated until it can be examined. The downside, though, is that heuristic scanning has a reputation of producing a lot of false positives.

Traditional antivirus software has relied on finding a virus in the wild, engineering an identification file and encouraging users to download the latest update or send it off to users' machines automatically.

The disadvantage is they are unable to stop new viruses before they become established in the wild.

"Vendors are going to have to change from the traditional virus identification model," said Mark Fisher, technical manager at Trend Micro.

"We mix our traditional antivirus identification service with content scanning and filtering to boost effectiveness."

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

97%

1%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Inside Sales / Fluent French / London / 30K TO 35k 10K OTE /

Inside Sales / IT Sales / Business Development / Fluent...

Senior Web Developer / Engineer (HTML, JavaScript, CSS)

Title: Senior Web Developer / Engineer (HTML, JavaScript...

Java Developer (J2SE / JEE)

Job Title: Java Developer (J2SE / JEE) Salary: up to...

Agile Test Manager

Job Title: Agile Test Manager Salary: up to 55k per...

To send to more than one email address, simply separate each address with a comma.