Skip Links

Network World

  • Social Web 
  • Email 
  • Close
Clear Choice Test: VoIP Analysis
Introduction | Complete scorecard | Test archive
Inside this test package
Anti-malware Product-by-product summary
Also:

New approaches on attacking malware

By Barry Nance , Network World , 09/18/2006
  • Share/Email
  • Comment
  • Print

A new category of antimalware tools has emerged, neither gateway tool nor desktop cleaner. This approach manipulates executable file permissions to actively allow, deny or limit the running of any computer program.

Instead of trying to recognize malware, this approach uses whitelists, blacklists and policies to set Windows permissions for executables, even if logged in as an administrator. SecureWave's Sanctuary, Green Border Technologies' GreenBorder Pro, Savant Protection and Winternals Software's Protection Manager are some products in this category.

For example, Protection Manager (starts at $25 per managed computer) uses Windows privilege levels to deny the running of an unknown application, run a known application with reduced privileges, or allow an application full access to files/directories, including operating system directories. Letting a program run at a lower privilege level denies the program access to Windows system directories and files, for example.

Doing this lets you allow Microsoft Word to have free access to all directories except system directories. Beyond whitelists, Protection Manager works "on demand" to let users dynamically adjust an application's privileges, or (if desired) stop an application.

When a user unwittingly clicks on a Web page link that downloads malware on a machine protected by the software, Protection Manager intercepts the launch of the malware and prevents it from running. Protection Manager features can be managed from a central location, and it integrates with Active Directory to let administrators easily protect whole groups of users in one fell swoop.

Microsoft was so impressed with Protection Manager that it bought the Winternals Software company.


< Previous: Zero-latency approach gives FaceTime edge | Next: Still no 'malware' definition >

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed