Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Trend Micro CEO: hackers hitting AV infrastructure

October 23, 2009 06:28 PM ET

IDG News Service - It's become an all-too-common scam: A legitimate Web site pops up a window that looks just like a real security warning. It says there's something wrong with the computer, and click here to fix it. A few clicks later, the victim is paying out US$40 for some bogus software, called rogue antivirus.

Rogue AV scams have become a big problem in recent months, but according to Trend Micro CEO Eva Chen, it's part of a more sinister, strategic attack on the antivirus industry in general. Criminals "can fake any other application. Why do they fake AV?" she asks.

According to her, a lot of today's security problems are designed not only to steal information from victims, but to undermine the credibility of companies like Trend Micro itself.

One way hackers have done this is by changing the way their software is put together each time they attack, forcing the AV vendors to bloat up their products with hundreds of thousands of new detection signatures.

In response, Trend was one of the first companies to push reputation-based technology into its antivirus products, developing its Smart Protection Network to identify and block not just viruses themselves, but also the malicious Web sites that are used to distribute malware.

Since 2004 Chen has served as CEO of the company she co-founded in 1988. She dropped by IDG News Service offices in San Francisco this week to answer a few questions. The following is an edited transcript of her interview.

IDG News Service: Microsoft has done a good job of making Windows more secure, but are Windows users better off today than they were five years ago?

Eva Chen: If Microsoft thinks it's secure enough, why do they bother to come up with MS Security Essentials for a free download on the side? With so much social engineered malware it actually has nothing to do with whether Windows itself is secure or not. It's the user's behavior. Plus there are so many applications -- either the browser or other applications' vulnerability, not just Windows.

IDGNS: It almost sounds like you're saying that things are worse?

Chen: Yes I would say so. …It has nothing to do with whether Windows is secure or not. It's just that the whole environment is much more unsafe. Hackers are making more money. And with the economic downturn, the criminal rate is going up, and therefore [there is] more cybercrime.

IDGNS: People say that conventional antivirus has not been up to the task and maybe even takes the wrong approach.

Chen: Actually I was the first one to say that. Last year I said the antivirus industry sucks. We were all competing on something that was irrelevant: our detection rates. You're at 100 percent detection rate this minute, the next minute it's down to 70 percent. What's the point of that competition?


Reprinted with permission from

IDG.net
Story copyright 2009 International Data Group. All rights reserved.

Jump to comments

Trend Micro

Additional Resources

Microsoft
Here are some of the key reasons why you would want to run Unified Access Gateway with DirectAccess.
Microsoft
Review how one energy firm tightened protection and simplified IT work using business-ready security solutions.
Sybase
In this white paper, IDC analyzes the role of next-generation mobile enterprise platforms as organizations seek a more strategic deployment of mobile solutions.

Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs