- Is the Cisco MARS mission going to abort?
- First iPhone worm spreads Rick Astley wallpaper
- 10 stunning 3D buildings made with Google SketchUp
- Open source software ready for big business
- Four reasons to buy (and one reason to avoid) the Droid

Network behavior anomaly detection does not provide a true security solution against viruses and worms. With the growing sophistication, speed and damage potential of today's virus and worm attacks, companies need a solution that actively defends their networks.
The ingredients required to mount a meaningful defense against these new and virulent attacks include speed, accuracy and the ability to actively block attacks from spreading to other machines, systems and networks.
Anomaly detection falls short in these areas and gives users a false sense of security. The approach has three main drawbacks:
Most anomaly-detection products were built for network performance monitoring and diagnostics. They weren't designed to protect the network from zero-day attacks, targeted attacks and worm storms. Anomaly detection systems are unable to mitigate slow, stealthy and sophisticated attacks. Hackers are using this method, essentially spreading an attack over a longer time, to fly under the radar of anomaly-detection engines and other security devices.
Comments (2)
Anomaly detection is not the best way to prevent virus, worm attacksBy Anonymous on February 13, 2007, 9:37 pmFor "behaviour" based anomaly detection methods you are absolutely right(protocol anomaly detection on the the other hand works great!). Because security is a more...
Reply | Read entire comment
hiBy Anonymous on September 5, 2008, 3:48 amgive me pls exact meaning of way to prevent virus pls...pls...pls...
Reply | Read entire comment
View all comments