Network World
Tuesday, October 14, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

RE: Secure Web gateways: slamming the door on malware

I don't get it. If anti-virus isn't good enough for the detection of malware once it's installed, how is anti-virus going to be good enough on a gateway?

Why not detect and block ALL executable files unless from an known good source; Microsoft updates, Adobe, Intuit, etc. Then when your gateway reports that someone is trying to download a file, the "gatekeepers" can contact that user and see if it's something they really need. Nine times of out ten, they're going to either say "no" or "I wasn't trying to download a file".

If they weren't trying to download a file then you have a real good candidate for further investigation.

Why continue to rely on signatures when we all know the bad guys know how to evade them?

Why not stick to a policy of "only traffic that is absolutely necessary for the business"?

This strategy combined with Layer 7 identification of protocols can prevent and detect infection. No signatures to update, no anti-whatever to update. Just good sound security policies.

Click to read the article this is in response to.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: