- New attack fells Internet Explorer
- Steve Jobs is a man of a few words
- Oddball gifts for uber geeks
- Global warming research exposed after hack
- Google adding IPv6 to YouTube

Network behavior anomaly detection does not provide a true security solution against viruses and worms. With the growing sophistication, speed and damage potential of today's virus and worm attacks, companies need a solution that actively defends their networks.
The ingredients required to mount a meaningful defense against these new and virulent attacks include speed, accuracy and the ability to actively block attacks from spreading to other machines, systems and networks.
Anomaly detection falls short in these areas and gives users a false sense of security. The approach has three main drawbacks:
Most anomaly-detection products were built for network performance monitoring and diagnostics. They weren't designed to protect the network from zero-day attacks, targeted attacks and worm storms. Anomaly detection systems are unable to mitigate slow, stealthy and sophisticated attacks. Hackers are using this method, essentially spreading an attack over a longer time, to fly under the radar of anomaly-detection engines and other security devices.
Comments (2)
Anomaly detection is not the best way to prevent virus, worm attacksBy Anonymous on February 13, 2007, 9:37 pmFor "behaviour" based anomaly detection methods you are absolutely right(protocol anomaly detection on the the other hand works great!). Because security is a more...
Reply | Read entire comment
hiBy Anonymous on September 5, 2008, 3:48 amgive me pls exact meaning of way to prevent virus pls...pls...pls...
Reply | Read entire comment
View all comments