bugwatch
bugwatch

Bug Watch: can you trust third parties?

Automated systems that 'push' out antivirus updates from vendors directly on to users' machines are being marketed by some of the big players in the market. There is even one plan to deliver automatic updates via satellite.

Graham Cluley, Sophos

Bug Watch: Each week vnunet.com asks a expert from the IT security world to give their views on recent virus and security issues, with advice, warnings and information on the latest threats. This week's expert is Graham Cluley, senior technology consultant at UK-based antivirus company Sophos.

Automated systems that 'push' out antivirus updates from vendors directly on to users' machines are being marketed by some of the big players in the market. There is even one plan to deliver automatic updates via satellite.

Advertisement

The logic sounds simple and attractive, but there's a problem: network managers and computer users don't always remember to update their antivirus software regularly enough.

Solution: design a system so that the computers update automatically.

However, while attractive on face value, these systems have two big flaws. First, do you really want a third-party company updating the software on your network without your approval, particularly when that software (like antivirus protection) runs at a very low level at the heart of your Windows NT or Novell server operating system?

This week antivirus software proved to be a bigger problem than the viruses it was supposed to protect against when one antivirus vendor issued an update that stopped many of its customers' computers from working.

In internet newsgroups and message boards, companies told of late nights manually uninstalling antivirus software in an attempt to get their networks running again.

Antivirus programmers may play three-dimensional chess and wear purple loon pants, but they are still human - and humans sometimes make mistakes.

In this case, the antivirus company hadn't tested its DAT (virus update) files with an older version of its scanning engine - and worse, hadn't stopped its users from running the older engine with the latest DAT files.

Automatically pumping out the latest virus protection to these users meant their systems turned to treacle as an incompatibility between engine and DAT file caused chip use to rise to 100 per cent.

The second big flaw in this system is that such a solution removes the need for users to worry about updating their antivirus software and ensuring that they have the latest antivirus identities. But therein lies the biggest problem: when automatic systems remove the worry and the responsibility, complacency and absolute trust in the antivirus software follows.

The result is that users forget to practise safe computing and the next Love Bug or Melissa rips through their system before an antivirus identity can be produced by vendors. It took several hours for any of the antivirus companies to patch for the Love Bug, but following safe computing guidelines would have kept users secure.

Antivirus software only plays one part in a solid IT security solution, and suggesting that automatic updates will provide total protection against viruses and immunise networks is counter-productive. User education is the key to long-term protection.

For their part, corporate users of antivirus software should not update all their PCs automatically without first testing the update works on a small number of PCs.

If you're a system administrator looking after virus protection in your company, take my advice. Test your antivirus software actually works before rolling it out over your enterprise, and ensure that all your users are aware of and are practising safe computing. Otherwise your chief executive may have to deliver your P45 in person because he can no longer get into his email.

Next edition: 17 November

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Security fears hamper Wap adoption

A survey conducted by Excellence in Computing Solutions has revealed that misconceptions about the security aspects of Wap are hindering its widespread adoption.

Bug Watch

Bug Watch: 'tis the season to get infected

Bug Watch: Each week vnunet.com asks an expert from the IT security world to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

Corporate telecoms networks vulnerable

Encryption regulations are leaving corporate mobile telecoms networks exposed to industrial espionage, according to a security expert.

Bug Watch: The rise of the network Trojan

The Microsoft hacking incident is one of the first high-profile cases of cyber espionage. It shows a growing trend towards viruses carrying Trojans that can launch websites or steal passwords. Experts have been predicting this evolution for the past two years.

Related whitepapers

Related jobs

Most watched

Xperia X1

Video Review: Sony Ericsson Xperia X1

First Looks Editor Ian Williams gets hands on with the Sony Ericsson Xperia X1

iPhone

Video Review: iPhone 3GS

We put Apple's latest iPhone through its paces

IT white papers

Search white papers

Top categories

Poll

Poll: Summer smartphones

Poll: Summer smartphones

Which smartphone will you be taking to the beach this summer?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

HTC Hero

Hands on with the HTC Hero

V3.co.uk gets a walk through of the Hero, which includes...

NetGear ReadyNAS NVX

Review: NetGear ReadyNAS NVX

NetGear's four-bay compact network-attached storage gets a serious speed boost

AMD

AMD adds to six-core Opteron line up

New HE processors promise even lower power consumption

Adobe Systems

Adobe launches ColdFusion 9 and ColdFusion Builder

Firm promises enhanced developer productivity

Primary Navigation