A clever anti-malware gateway can achieve zero latency by using a span/tap port to inspect Internet traffic for malware and malware references (in contrast to inline inspection).
A clever antimalware gateway can achieve zero latency by using a span/tap port to inspect Internet traffic for malware and malware references (in contrast to inline inspection).
When it recognizes malware, either via URL, IP address or (after the last packet of malware executable is received) signature matching, the gateway attempts to prevent the unwanted computer program from entering your network by simply spoofing the source (malware) and destination (client) machine addresses with TCP RESET packets that it transmits to each session partner.
The TCP RESET instructs both sender and receiver to cease the current transfer of data. The appliance merely listens to the conversation flow and, when it detects malware, commands the client and the spyware host to halt.
Too clever by half, perhaps –TCP RESET has several drawbacks.
First, a cyber attacker can cause a "self-inflicted DoS attack" by flooding your network with thousands of offending packets. The TCP RESET gateway responds by issuing two TCP RESETs for every offending packet it sees.
The TCP RESET approach is worthless against a cyber attacker who uses UDP to "phone home" the contents of your sensitive files.
The gateway has to be perfectly quick … it has to send the TCP RESET packets before the client (victim) has processed the final packet of malware.
Ergo – deep and thorough inspection of network traffic before it's allowed to flow to the client is the most effective way to stop malware.
To what extent do these products support TCP RESET? McAfee avoids it, using instead what it calls a "positive security model" – it employs an inline approach for blocking malware. Websense is on the fence, using TCP RESET to control P2P and IM protocols, but relying on inline packet inspection for HTTP, Secure-HTTP and FTP. Facetime gives customers the option of using TCP RESET or inline malware blocking. Symantec also offers both inline and span/tap port malware detection. Trend Micro emphasizes inline packet inspection, only using span/tap ports for out-of-band monitoring, scanning and notification.
Payscale uses alumni post-grad pay to rank 187 colleges and universities with computer science...
Vint Cerf is known as a "father of the Internet," and like any good parent, he worries about his...
How mainstream is big data? We asked two speakers at HP's Big Data Conference 2015 in Boston whether...
Sponsored by SevOne
Sponsored by HP
After spending three full days at VMworld 2015 in San Francisco, I’ve learned some things
Cisco’s security consulting chief James Mobley outlines four areas CISOs need to develop their skills...
Microsoft Research distinguished scientist Victor Bahl has been spreading the word about Micro...
Security, usability and support costs are just a few of the factors IT leaders need to consider when...