Showing posts with label Anti-Virus. Show all posts
Showing posts with label Anti-Virus. Show all posts

Wednesday, March 3, 2010

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

New M86 Security Labs Report Finds 60% of Malicious URLs Pass Unnoticed Through Anti-Virus Scanners and URL Filtering: M86 Security

I'm really not surprised by these findings. The number one and biggest problem with any security software like you're typical Internet Security Suite is it's a 'Reactive' technology. This means its always behind the curve never in front of it. This means the best you can hope for in terms of detection rates is 98-99% but never with 100% certainty.

Whenever I talk with users and explain this fact they are always shocked. Why is this so surprising to people? Vulnerabilities exist because code is written by humans; therefore you will always have mistakes in code creating the smallest openings for exploitation. Security software is written by humans therefore it will never be perfect and because its a reactive technology it will never catch the latest and greatest zero day exploit.

However security software vendors can help by implementing one small change. Stop marketing their tools as the best and only tool for a safe and secure Internet experience because such marketing hype creates a false sense of security leading everyday users to believe they can do no wrong. Such false sense of security makes people complacent and not think about security. I wish government would wake up and force vendors to disclose such details. We have labeling laws for everything else why don't we have it for software or security appliances. Users should know what they're getting up front before they're taken in by all the hype and spin.

In fact I don't believe things will change anytime soon but only get worse. That is until users wake up from la-la land and become aware their actions have consequences. Ultimately the security fight will not get any better until users take responsibility for their actions and actually think about email, attachments, web sites and general computer best practices.

Until that day security software will fall farther behind and a new sucker will be born every nanosecond. We've all been taught lessons by our parents 'don't talk to strangers' type stuff. Why is it so hard for people to learn similar lessons when it comes to computers and Internet safety?

Thursday, July 9, 2009

CA Internet Security Suite 2009 Trashes Windows System Files

CA Internet Security Suite 2009 trashed Windows XP SP3 System files following a recent signature update. Signatures version 6604 seems to be falsely identifying several Windows system files and placing them in quarantine. Many home, home office and small business users have reported the following files were affected; (This list is not comprehensive, these are the most commonly reported quarantined files)

  • c:\windows\system32\net.exe
  • c:\windows\system32\netsh.exe
  • c:\windows\system32\reg.exe
Community Forums lit up like a Christmas tree however CA was slow to respond or acknowledge there was a false positive problem. Late Thursday afternoon a notice was posted on CA's Virus Signature Update site indicating there was a problem, urging users to follow these steps in resolving this situation.

Community Forum users stepped up to the plate indicating this situation to be a false positive problem and suggesting short term fixes one of which was to disable Real Time Anti Virus Scan which seemed to be the culprit in this fiasco. Short term or not disabling any Anti Virus is a recipe for disaster. However in this case because CA was dragging its heels this fix was the best solution at the time. CA should take a page from it user Community and step up to the plate quicker with solid answers when users ask questions. Many users were frustrated and vented their frustration and disappointment in CA's handling of this situation. Amongst the tidal wave of forum posts users were trying all sorts of solutions thinking this was a real virus threat. Some went to the extreme of restoring entire systems to previous image backups only to be back in the same spot after updating CA signature file version 6604. Others not so quick on the trigger took time to investigate in detail before attempting such drastic measures. But in any case scenarios like these waste everyone's time, effort and in some cases data as many reported blue screens or problems booting after CA Anti-Virus happily quarantined Windows System files.

Situations like this prove several things;
1. Disaster strikes when you don't have a good backup.
2. Quality Assurance Cycles are way too short or non existent
3. Windows users have been conditioned to eradicate anything when they see the words VIRUS and INFECTED. not giving the process much scrutiny before proceeding to restore from backup.

#1 is easy to fix... BACKUP regularly. Disk is cheap there is no excuse.
#2 is harder to control by users but hopefully CA has learned something from this situation. If not someone most certainly got fired today.
#3 False Positives do happen people; they've been with us since the very first Anti-Virus snake oil sales man conned you into buying his software many years ago. Unfortunately this is today's reality in the Windows universe. However please scrutinize and be informed before doing anything drastic.

For CA today was a BAD day, for us mortals Today was just another day in the Windows-verse hopefully none of you have lost much data but cheer up tomorrow is another day.