Skip Links

Network World

  • Social Web 
  • Email 
  • Close

How we did it

By Barry Nancy , Network World , 05/04/2007
  • Share/Email
  • Comment
  • Print

We collected a suite of 100 malware samples, including adware, trojans and rootkits, which we moved to an isolated, quarantined network.

The quarantined network consisted of three subnets. Subnet 1 had 25 client machines with a variety of operating systems, including Windows NT, 98, 2000, 2003, ME, XP, Vista, Red Hat Linux and Macintosh OS X. The FCS agent ran on all but Windows NT, 98, ME and of course Linux and Mac OS X. The FCS console ran on a Vista-based Dell Latitude notebook.

Subnet 2 contained three Web servers (Microsoft IIS, Netscape Enterprise Server and Apache), three e-mail servers (Exchange, Notes and Sendmail), two file servers (Windows 2003 Advanced Server and NetWare) and two database servers (Oracle 8i and Microsoft SQL Server).

Finally, Subnet 3 had Web servers that contained the malware instances and which sported “bad guy” IP addresses and URLs. Systems on the first two subnets accessed the third subnet as if it were the real Internet.

Client and server machines started off in a pristine state for each test. Our clients and servers attempted to download malware from the simulated "Internet." We noted how well FCS identified malware, removed the malware and, before its removal, blocked attempts by the malware to send data back to the source. We gauged success or failure by examining each machine for malware after each test.

We looked for running malware processes, new program files (EXE, DLL or OCX, possibly marked with the “Hidden” attribute) new directories and Registry and Start Menu changes. We focused a good deal of our evaluation on Management Console’s ease of administration and its reports. We tested Security Agents for reliable no-crash behavior and ease of deployment.


< Return to main test
  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed