Do Macintosh machines need AV?
My answer: Forget the OS. Do users download and install arbitrary code/applications? (don’t forget, this includes browser plug-ins as well). If so, I don’t care if you are running Macintosh, Linux, or Windows the answer is you need protection from malware, including signature-based mechanisms (historically referred to as AV…). Just like [...]
Entries Tagged as 'Beyond Anti-Virus'
Yes, Macs are Vulnerable Too.
September 25th, 2009 · 6 Comments
Tags: Beyond Anti-Virus · Endpoint Protection Platform
We Have a Quorum: Blacklists Aren’t Cutting it.
September 14th, 2009 · 7 Comments
Symantec recently announced the latest release of its consumer protection technology which includes a new malware technology code-named “Quorum”. Essentially the technology uses visibility (or lack thereof) of behavior of executable code across a community to aid in the determination if a given piece of code is “good” or “bad”. We are working on our [...]
Tags: Beyond Anti-Virus · Endpoint Protection Platform · Next-generation Security Infrastructure
Security No-Brainer #8: Run Users As Standard User
August 13th, 2009 · 1 Comment
Mostly for legacy reasons, many of us continue to run users with administrative privileges on their Windows workstations.
Running as standard user reduces exposure to malware by preventing users from updating protected parts of the file system and registry or accessing sensitive Windows operations. An analysis by BeyondTrust showed that 92% of the critical Windows vulnerabilities [...]
Tags: Beyond Anti-Virus · Endpoint Protection Platform
Security Thought for Tuesday: Cloud Computing Should be a More Secure Model
August 11th, 2009 · 8 Comments
A computing paradigm based on the exchange and execution of arbitrary code is inherently risky.Yet, that’s pretty much the foundation of what we do today with personal computers. Consider that this model is the primary reason we pay billions of dollars to AV vendors to scan our machines for known malicious executable code. Consider that [...]
Tags: Application Security · Beyond Anti-Virus · Cloud · Information Security
Should AV be Free?
June 23rd, 2009 · 5 Comments
I saw today on this website that Microsoft has released the beta offering of its free consumer-oriented antivirus/antispyware protection solution called Microsoft Security Essentials (MSE – previously code-named “Morro”). The offering is available to the first 75,000 visitors to the site starting today. Gartner’s full analysis and advice for clients will be available shortly, but [...]
Tags: Beyond Anti-Virus · Endpoint Protection Platform · Microsoft Security
Stop Paying for Anti-Spyware
May 18th, 2009 · 1 Comment
I had a conversation with a client last week where their incumbent antivirus provider was trying to charge them separately for antispyware capabilities in addition to their antivirus solution.
Sigh. I thought we put this issue to rest years ago.
In 2005, I wrote ”How to Get Free Anti-spyware (or Antivirus) Protection” so I was a [...]
Tags: Beyond Anti-Virus · Endpoint Protection Platform
Security No-Brainer #4: EV-Certificates for ISVs
May 1st, 2009 · 2 Comments
Let me summarize my security no-brainers to date:
The first was in reference to a global, industry-wide effort to create a shareable, standards-based application whitelist database built directly from feeds from ISVs.
The second was in reference to the use of whitelisting in the hypervisor/VMM (especially the “parent” or Dom0 partition) layer to prevent the execution of [...]
Tags: Application Security · Beyond Anti-Virus
Attackers are Moving up the Stack. So Should We.
April 15th, 2009 · 1 Comment
I had an interesting discussion with a client this week. They were trying to understand how several recent outbreaks of malware had gotten past their existing defenses.
In reviewing their architecture, it became clear that while they had an established process for patching Windows and Office, they hadn’t yet extended the process up the stack to [...]
Tags: Application Security · Beyond Anti-Virus
Whitelisting, Meet Virtualization. Virtualization, Meet Whitelisting.
April 10th, 2009 · 10 Comments
As I have discussed, x86 hardware virtualization creates a new IT platform that must be securely maintained (e.g. patch, configuration and vulnerability management) like any other IT platform we are responsible for. This layer is extremely sensitive as a compromise of this layer puts all of the hosted VMs at risk.
I’ve also discussed the foundational [...]
Tags: Beyond Anti-Virus · Virtualization Security
We Need a Global Industry-wide Application Whitelist
April 3rd, 2009 · 9 Comments
My previous post on whitelisting has generated a lot of comments. Buried in the comment stream, I made this statement:
I look forward to the time (hopefully soon) when an industry consortium or worldwide standards effort brings together legitimate ISVs to create a shareable whitelist for all to use.
Whitelisting is foundational to any information security protection [...]