Test: Enterprise-level anti-spyware software
Webroot shines in sweeping up the spyware.
By Barry Nance
,
Network World
, 12/13/2004
- Share/Email
- Tweet This
- Print
Like viruses and other harmful programs, spyware is a huge security problem. Worse than a typical virus, a spyware program can send corporate data directly from your company's client computers
to an Internet-based data collection facility, such as a shady adware site or other group of bad guys.
The perfect anti-spyware tool detects all spyware, identifies all the files and registry entries associated with the spyware,
and safely removes all its traces, remnants and residue. In a corporation, the ideal tool also offers a central console through
which network administrators easily can disinfect client computers. The ideal tool is simple to install and deploy, and conveniently
updates its own spyware signature list. Status displays and reports give you a quick and accurate picture of how badly spyware
is harming your company. A good tool also will be able to detect and remove Trojans, dialers, malware and browser hijackers
(see graphic, below).
Buyer's Guide: Anti-Spyware softwareDetailed vendor specs.Detecting BHOsHow we did itArchive of Network World reviewsSubscribe to the Product Review newsletter
We recently invited several anti-spyware vendors to submit products to our Alabama lab. We tested Webroot Software's Spy Sweeper
Enterprise Version 1.5, InterMute's SpySubtract Pro Version 2.5, Tech Assist's Omniquad AntiSpy Enterprise Edition Version
4.0 and PepiMK Software's SpyBot - Search & Destroy Version 1.3.
Webroot's Spy Sweeper Enterprise proved itself the best anti-spyware tool in our tests, winning a Clear Choice Award. It contained
the most spyware definitions, gave us excellent control over its client agents from a central console, ran quickly and unobtrusively,
had an intuitive user interface, and displayed useful reports of its activity.
Find and remove
Spy Sweeper Enterprise is said to thwart about 35,575 spyware programs; Omniquad AntiSpy Enterprise contains about 10,000
spyware definitions; and SpySubtract Pro has about 31,124. The freeware SpyBot Search & Destroy contained more than 10,000.
Auditing each vendor's list with a sampling technique verified the authenticity and validity of each vendor's spyware definitions.
All four products automatically update their definitions by accessing vendor master lists via the Internet. Spy Sweeper Enterprise
updates generally occur weekly, Omniquad AntiSpy Enterprise updates occur every three days (sometimes more frequently) and
SpySubtract Pro updates occur every one to two weeks. All four accurately detected and disposed of the 20 examples of miscreant
spyware we introduced into our test network (see "How we did it").
Spy Sweeper Enterprise includes four server components - an administration console, enterprise database, update server and
client server.
The administration console is the user interface for configuring clients, managing spyware definition updates, establishing
alerts and notifications, viewing reports and remotely directing client spyware scans, including running an immediate spyware
scan on a specific remote client or group of clients.
The enterprise database component stores configuration settings and scan results. The update server automatically obtains
the latest spyware definitions from the vendor on the scheduled weekly basis, or an administrator can tell Spy Sweeper Enterprise
to retrieve definitions on demand.
The client server module sends configuration settings and definition updates to the clients, and receives the scan results
from those clients. On each client, Spy Sweeper Enterprise's client agent scans for spyware - periodically or on demand.
When spyware is detected (either incoming or pre-existing), the client disables and quarantines the spyware. It then sends
an alert to the client server, which records the event in the database and tells the administration console to notify a network
administrator. Because Spy Sweeper Enterprise consumes little bandwidth and because you can spread its workload across multiple
servers, we found it scales extremely well. Each scan took only about 4 minutes and consumed few resources as it ran unobtrusively
in the background on each client.
Comment