* A look at what Symantec calls generic exploit blocking
endif; ?>Symantec is pushing a new way for users to detect abnormalities in network behavior and warn security managers of such malicious actions.
This week’s Technology Update takes a look at what Symantec calls generic exploit blocking. According to our Tech Update authors (rclyde@symantec.com and cnachenberg@symantec.com), generic exploit blocking analyzes the targeted vulnerable software rather than the attacking viruses.
The goal of generic exploit blocking is to characterize a system vulnerability and then build a signature that can detect and block all potential attacks against that vulnerability. The resulting vulnerability signature is not targeted at a specific threat but at all exploits that are capable of compromising the vulnerability, our authors state.
Our authors go on to say that proactive technologies such as generic exploit blocking will not replace traditional reactive signature-based techniques for detecting viruses and worms. Rather, generic exploit blocking provides powerful complementary capabilities to protect a vulnerability from any future attack weeks or months before an exploiting worm or virus is created.
For more on this Technology Update see: https://www.nwfusion.com/news/tech/2004/083004techupdate.html




