IronPort, others try to catch e-mail-borne viruses early

Opinion
Mar 10, 20052 mins

* IronPort’s approach to catching viruses early

One of the key problems in fighting viruses is that no matter how often you update virus signatures, there is always a lag time between the introduction of a new virus and the introduction of anti-virus vendors’ defenses against it. That leaves networks vulnerable to attack for the several hours or more that it takes to issue a new signature.

One method to get around this problem is offered by IronPort Systems. The company’s Virus Outbreak Filters use information from the company’s SenderBase offering to look for suspicious activity that might indicate the presence of a new virus. Suspected messages are then quarantined as a new signature is developed. Once the signature is ready, messages in the quarantine are then run through normal virus scanners.

IronPort recently said its Virus Outbreak Filters were able to detect variants of the Bagle virus more than 41 hours before a signature was developed. Other vendors are offering similar capabilities.

Of course, shortening the length of time between the outbreak of a new virus and the creation of a signature to defeat it is a goal for all anti-virus vendors. Kaspersky Labs is working toward minimizing the window of vulnerability to just 18 minutes, for example. Complicating the issue is that some new viruses are becoming harder to detect, spreading very slowly in an effort by their authors to evade detection.

The bottom line is that fighting viruses is very much a game of cat-and-mouse. A combination of good anti-virus systems, coupled with systems that quarantine suspect messages, is a best practice for any organization.