Network World
Saturday, November 22, 2008
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community: Security

Navigation

Good for customers with slow branches

I'm working with enterprise customers who are facing a problem when it comes to virus definitions update to comupters reside in branches with slow links. It takes long time to distribute the definition file across these links. Good move from Trend micro.... hope other vendors start thinking about re-designing their definition delivery mechanisms.

http://extremesecurity.blogspot.com

Click to read the article this is in response to.

Does this save you much in the long run?

0

If it goes out to the net I suppose machines with no Internet connectivity aren't going to work nicely. So clients are going to hash everything it sees, cross check it via the net then report back on what to do. It doesn't replace pattern files it just replaces the need to have them on your system. Does this save you much? I guess the meat and potatoes is not the actual scanning of memory and files code?
Wouldn't this method introduce a race condition, getting the results of the hash back before execution, seems like a no brainer on who would win, unless of course the executable is "frozen" until results are in which would probably cause a lot of angry impatient clients?
Also if I wrote a piece of malware couldn't I just redirect all Trend traffic or block it or send fake results to the client so it would be ignore it? If your Internet link goes out do you loose detection capabilities? If Trend's signature servers go out or are DDoS'ed is everyone using Trend down? Wasn't this an issue back in the worm days?
Also for companies that have remote locations with all Net traffic routed thru one location it would definitely mean an increase in wan bandwidth. Seems like a sketchy idea to me.

Kvetch, before all, please

0

Kvetch, before all, please forgive with may bad really bad english.
Your concerns are true, but first at all...
how did the new malware comes from?
you may think...USB, CD-Rom, FileShare...etc.
you may right, but...what made dificult to detect today malware is the capacity of hackers to create new piece of codes and upload it to a web site.. so, if Trend uses the reputation of the IP Address, they will block the download of the new bit o malware before the user can establish the conection.
About the DDoS that you say, I was checking how Trend work with their updates today, and they use the Akamai Network to replicate the pattern files, that could be used to do this check also... so, I'm not an expert, but I think that it's a little bit dificult to do a DDoS to the akamai network.
About the point that you mention concerning the network traffic...how much traffic will DNS queries generate on those companies? maybe you must think about this method in that way.
Tracing back to the first issue that you mention, I think that Trend Micro will not relay ALL the detections on the cloud. I think that they are going to REDUCE the amount of malware being analized by the traditional Pattern File... if they not, all File Infectors Viruses are going wild once again, like the 80's..

I hope that I can be understod.
Regards,
Shad

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: