Salem
Salem: This isn't about blocking software, it’s about defining policies for access

RSA 2009: Symantec boss pushes “reputational security”

Tools block access to applications with dodgy antecedents

Iain Thomson in San Francisco

The new head of Symantec, Enrique Salem, used his keynote at the RSA 2009 conference to call for a new operational approach to security.

The old methods of either blacklisting software or whitelisting it for full access are no longer sufficient in today's threat environment, he said. Instead, his company is working on new software that assesses the reliability of applications based on their history and reputation.

Advertisement

“We've spent three years building software that divines reputations automatically,” he said. “In this model we divine a computer's reputation of the program from its origin, age, source and using some other secret source that we can't disclose. The new method isn't just about blocking software, but about defining policies for access.”

He gave the example of a systems administrator who can set policies to only allow software on the network that is more than 30 days old, to eliminate new malware, and that is in use by at least a million people.

“That sounds to me like the Conficker virus,” said Adi Shamir, professor of the Computer Science Department at the Weizmann Institute of Science in Israel.

“It was around longer than 30 days. Also I understand the security code on that malware is very good.”

Moving to another theme, Salem said that security features need to be automated to make them faster and more effective. For example, if an employee loads protected data onto a USB memory stick then they should automatically be alerted that they are breaching policy, with a similar warning being sent to the administrator.

This was an issue of particular interest to Salem, as he admitted he had personally lost a USB stick containing confidential information. Half of lost USB sticks contain confidential information, he said.

The new approaches to security are needed because the threat landscape is getting much more difficult, Salem said. Attacks are reaching 200,000 every half hour worldwide and 90 per cent of those attacks are aimed at harvesting confidential information.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Do you agree?

Related whitepapers

Related jobs

Most watched

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file sharers

Intel unveils its micro server platform

Small-enclosure systems take aim at hosting market

IT white papers

Search white papers

Top categories

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Spotlight

eu flag

V3.co.uk weekly debrief, 6 Nov 09

This week, Europe decides what to do with illegal file...

Dell Adamo XPS

Dell launches ultra-thin Adamo XPS

World's thinnest laptop will be available by Christmas

Top 10 articles, 6 November 2009

The worst Microsoft products of all time, and a USB...

Iain Thomson

Pirate Bay shutdown could be inspiring online militancy

Recent Swedish attacks raise worrying possibility

Primary Navigation