Neil MacDonald

A Member of the Gartner Blog Network

Neil MacDonald header image 4

Entries Tagged as 'Beyond Anti-Virus'

Yes, Macs are Vulnerable Too.

September 25th, 2009 · 6 Comments

Do Macintosh machines need AV?
My answer: Forget the OS. Do users download and install arbitrary code/applications? (don’t forget, this includes browser plug-ins as well). If so, I don’t care if you are running Macintosh, Linux, or Windows the answer is you need protection from malware, including signature-based mechanisms (historically referred to as AV…). Just like [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform

We Have a Quorum: Blacklists Aren’t Cutting it.

September 14th, 2009 · 7 Comments

Symantec recently announced the latest release of its consumer protection technology which includes a new malware technology code-named “Quorum”. Essentially the technology uses visibility (or lack thereof) of behavior of executable code across a community to aid in the determination if a given piece of code is “good” or “bad”. We are working on our [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform · Next-generation Security Infrastructure

Security No-Brainer #8: Run Users As Standard User

August 13th, 2009 · 1 Comment

Mostly for legacy reasons, many of us continue to run users with administrative privileges on their Windows workstations.
Running as standard user reduces exposure to malware by preventing users from updating protected parts of the file system and registry or accessing sensitive Windows operations. An analysis by BeyondTrust showed that 92% of the critical Windows vulnerabilities [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform

Security Thought for Tuesday: Cloud Computing Should be a More Secure Model

August 11th, 2009 · 8 Comments

A computing paradigm based on the exchange and execution of arbitrary code is inherently risky.Yet, that’s pretty much the foundation of what we do today with personal computers. Consider that this model is the primary reason we pay billions of dollars to AV vendors to scan our machines for known malicious executable code. Consider that [...]

[Read more →]

Tags: Application Security · Beyond Anti-Virus · Cloud · Information Security

Should AV be Free?

June 23rd, 2009 · 5 Comments

I saw today on this website that Microsoft has released the beta offering of its free consumer-oriented antivirus/antispyware protection solution called Microsoft Security Essentials (MSE – previously code-named “Morro”). The offering is available to the first 75,000 visitors to the site starting today. Gartner’s full analysis and advice for clients will be available shortly, but [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform · Microsoft Security

Stop Paying for Anti-Spyware

May 18th, 2009 · 1 Comment

I had a conversation with a client last week where their incumbent antivirus provider was trying to charge them separately for antispyware capabilities in addition to their antivirus solution.
Sigh. I thought we put this issue to rest years ago.
In 2005, I wrote ”How to Get Free Anti-spyware (or Antivirus) Protection” so I was a [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform

Security No-Brainer #4: EV-Certificates for ISVs

May 1st, 2009 · 2 Comments

Let me summarize my security no-brainers to date:
The first was in reference to a global, industry-wide effort to create a shareable, standards-based application whitelist database built directly from feeds from ISVs.
The second was in reference to the use of whitelisting in the hypervisor/VMM (especially the “parent” or Dom0 partition) layer to prevent the execution of [...]

[Read more →]

Tags: Application Security · Beyond Anti-Virus

Attackers are Moving up the Stack. So Should We.

April 15th, 2009 · 1 Comment

I had an interesting discussion with a client this week. They were trying to understand how several recent outbreaks of malware had gotten past their existing defenses.
In reviewing their architecture, it became clear that while they had an established process for patching Windows and Office, they hadn’t yet extended the process up the stack to [...]

[Read more →]

Tags: Application Security · Beyond Anti-Virus

Whitelisting, Meet Virtualization. Virtualization, Meet Whitelisting.

April 10th, 2009 · 10 Comments

As I have discussed, x86 hardware virtualization creates a new IT platform that must be securely maintained (e.g. patch, configuration and vulnerability management) like any other IT platform we are responsible for. This layer is extremely sensitive as a compromise of this layer puts all of the hosted VMs at risk.
I’ve also discussed the foundational [...]

[Read more →]

Tags: Beyond Anti-Virus · Virtualization Security

We Need a Global Industry-wide Application Whitelist

April 3rd, 2009 · 9 Comments

My previous post on whitelisting has generated a lot of comments. Buried in the comment stream, I made this statement:
I look forward to the time (hopefully soon) when an industry consortium or worldwide standards effort brings together legitimate ISVs to create a shareable whitelist for all to use.

Whitelisting is foundational to any information security protection [...]

[Read more →]

Tags: Beyond Anti-Virus · Endpoint Protection Platform