Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Top security suites fail exploit tests

12 suites get 'F'; Only Symantec's detects more than 3% of real attacks

October 13, 2008 12:00 PM ET

Active Comments
Jaqui says: bad idea, trust only that someone is out to screw you over, maybe. trust anything that gives false information? never....
Raj - IT in Atlanta, GA says: Well written article. I would have thought that the "big" names in home PC security would have a clue about...


Computerworld - Security software suites don't protect users from real-world exploits, a bug-tracking company charged today after launching 300 test attacks against a dozen programs, including popular software from McAfee Inc., Symantec Corp. and Trend Micro Inc.

"The Internet security suites are marketing themselves as the one solution users need to be safe online," said Thomas Kristensen, chief technology officer at Secunia Inc., which ran the tests. "In our opinion, that's just not true."

Secunia sicced hundreds of vulnerability exploits -- some proof-of-concept code that triggered a vulnerability, others that included payloads -- on 12 suites, including Symantec's Norton Internet Security 2009, Microsoft Corp.'s Windows Live OneCare, AVG Technologies' Internet Security 8.0 and McAfee's Internet Security Suite 2009. The attack code was delivered by files of various formats, including Office documents and malformed images, and by malicious Web sites that triggered browser and ActiveX bugs. The target was a Windows XP SP2 machine missing "certain patches and with a number of vulnerable programs," according to Secunia.

While Symantec's Norton Internet Security 2009 took top honors, it detected only 64 out of 300 exploits, or just 21% of the total. Even so, that beat most rivals by substantial margins. Trend Micro's Internet Security 2008, for example, detected only 2.3% of the exploits, while McAfee's Internet Security Suite 2009 identified 2% and Microsoft's OneCare spotted just 1.8% of the exploits.

The reason why current security suites had such trouble detecting the 300 exploits, Kristensen explained, is that antivirus software vendors are geared toward cranking out signatures for hacker payloads: the worms, Trojan horses and spyware that are identified in the wild, given names and then spotted by adding a new detection "fingerprint" to the software.

"They don't focus on detecting vulnerabilities, they focus on detecting the payload," Kristensen said. "But the problem with detecting the payload is that you're always behind [the hackers]. It's easy for the bad guys to create a new payload that's not detected by the scanning mechanisms and current signatures."

In order to craft a signature for a specific payload, security companies must first capture a sample, analyze the malware and write a detection fingerprint. Then they must push that new signature to users. The process, said Kristensen can take hours at best and then must be repeated as soon as a new piece of malware is bundled with an exploit.

But by looking for vulnerability exploits rather than for payloads, argued Kristensen, security software could stop multiple pieces of malware with just one signature -- a more efficient defense in the long run.

"If there's a vulnerability in [Microsoft] Office and someone is exploiting that in an Office document, you'll be able to block that attack with just one signature," he said, no matter how many different payloads hackers may try to load into a vulnerable PC. "It's a much better way, we think, even though it's somewhat more time-consuming to come up with a vulnerability signature."

Although Secunia sells its vulnerability research and proof-of-concept exploits to legitimate security vendors, Kristensen maintained that was not the reason why the company tested the 12 suites. Instead, he said, the take-away should be to patch, patch promptly and patch all software, not just the operating system.

"Security software alone isn't sufficient" to protect a PC, Kristensen said. "People need to patch all their programs. Patching is absolutely necessary, and not just the main programs, but third-party software as well."

Secunia has posted a paper that describes its suite-testing procedure and lists results on its site (download PDF).



Jump to comments

Secunia

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

What People Are Saying

White Papers & Webcasts

Share our Strength
Download Now  

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...