Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Trend Micro retools antimalware software

Moving virus patterns to the Web could slash code sizes by 70%, Trend Micro says
By Ellen Messmer , Network World , 06/18/2008

Trend Micro is taking a new approach to product development that relies more on cloud-based security than traditional downloading of virus-pattern files.

"The new strategy is called the Smart Protection Network," says Eva Chen, Trend Micro's CEO (pictured).

Existing antimalware defenses from Trend Micro revolve around signature-based pattern matching of viruses, which requires computers to receive updated pattern files, Chen points out. But this technique is growing unwieldy with several million new viruses discovered each year.

Looking ahead, Trend Micro envisions "moving the pattern files into the cloud," Chen says. Instead of downloading a huge pattern file, a Trend Micro "smart agent" on the desktop or server will read a file and calculate a hash code and checksum for it. The client-side product would utilize the cloud to check to see if the content is harmful.

"Signatures are added to the cloud, not the desktop," Chen says. The technique is expected to result in a software product that's about 70% less hefty in terms of code.

Trend Micro's strategy also calls for having a crawler scour the Web and producing a signature based on any malware found. "Nowadays, the hacker will hack a Web site or set up a phishing site," Chen says. "The end-user will be downloading files that are usually small programs that continue to download small components to evade detection, and this eventually becomes a bot."

Chen says Trend Micro's new approach will provide better protection against this type of threat. "We already include Web-threat protection to block users visiting those sites," she says.

Cloud-based security of this nature "is changing our product architecture and how we manage it," says Chen, who adds that the first versions of Trend Micro's Smart Protection Network products are expected out by year-end.

"We are using cloud computing because when you have a humungous amount of data and you have to search quickly, it's like an ocean."

In addition to its Smart Protection Network architecture strategy, Trend Micro also this week announced versions of its InterScan Web Security and Messaging Security products to work on VMware's ESX virtual-machine platform.

Both the InterScan Web Security Software Virtual Appliance and InterScan Messaging Security Software Virtual Appliance are expected to be available in the third quarter of this year. Pricing has not been set.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (4)
Login
Forgot your account info?

Kvetch, before all, pleaseBy Shad on June 20, 2008, 12:07 amKvetch, before all, please forgive with may bad really bad english. Your concerns are true, but first at all... how did the new malware comes from? you may think...USB,...

Reply | Read entire comment

I wonder if this is the bug they foundBy Anonymous on June 19, 2008, 10:24 pmhttp://support.mozilla.com/tiki-view_forum_thread.php?comments_parentId=75676&forumId=1

Reply | Read entire comment

Does this save you much in the long run?By Kvetch on June 18, 2008, 11:55 pmIf it goes out to the net I suppose machines with no Internet connectivity aren't going to work nicely. So clients are going to hash everything it sees, cross check...

Reply | Read entire comment

Good for customers with slow branches By xmachine on June 18, 2008, 4:41 pmI'm working with enterprise customers who are facing a problem when it comes to virus definitions update to comupters reside in branches with slow links. It takes...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed

Whitepapers

Magic Quadrant for Application Delivery Controllers

Gartner summarizes its view on Application Delivery Controllers, evaluates strengths and weaknesses...

Vulnerability Management For Dummies

Download this concise book "Vulnerability Management for Dummies," to learn about the simple steps...

The ROI and TCO Benefits of Data Deduplication for Data Protection in the Enterprise

This paper examines and quantifies the costs and benefits of backup with deduplication storage as...

Webcasts

Transforming the Enterprise WAN Edge: Video from Cisco

Life on the edge of your WAN has changed dramatically. With the need to deliver advanced services,...

PoE Plus: Impact on the PoE Market

The standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Harnessing the power of communications to increase workplace performance

Due to the convergence of IT and telecommunications technologies, the business workplace has been...

Special Reports

The Evolution of Network Security

We have so many holes punched in our firewalls today that many industry insiders question the value...

The self-managed network

We aren't there yet, but advances in network and systems management tools are making it possible to...

Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.