ANTI-VIRUSES

Antivirus is biggest security expense

Spending on security software across Europe will top ₏2.4bn (£1.65bn) this year, with antivirus continuing to form the largest slice of the pie. Antivirus will account for more than 50 percent of the total security software revenue market in 2007, according to the calculations by analyst Gartner. Organisations are getting more sophisticated in the way they choose security products, and technical evaluations are now common practice, the analyst said. Customers also want to deal with a smaller number of vendors that can supply products that work well together.

Gartner principal research analyst Ruggero Contu said traditionally the security software market has been dominated by “best-of-needs” vendors, but the market is now starting to see a gradual consolidation around fewer players.
However, Contu added that security is becoming more complex and difficult for a single vendor to handle. “Customers require products that integrate with their security architecture rather than disconnected point solutions,” he said in a statement.

Leopard hacked to run on PCs

The cat and mouse game between hackers and Apple takes another move, with news that Apple’s new Leopard operating system has already been succesfully installed on Windows PCs. The OSx86 Scene forum has released details of how Windows users can migrate to Apple’s new OS, without investing in new hardware – even though installing Leopard on an PC may be counter to Apple’s terms and conditions.

The forum is offering full instructions on how to install the system, including screenshots of the installation process.

Not all the features of Leopard function with the patch – WiFi, support, for example, is reportedly inoperable. Historically, Apple’s likely next move will be to track down and act against those behind the hack.

The move to make Leopard work on a PC is just the latest in Apple’s continual struggle with the hacker community.

Also this weekend a crew of hackers unleased Jailbreak Me (www.jailbreakme.com), an online service iPod touch and iPhone users can navigate to in order to break into these devices in order to install applications on them.

Apple has encountered similar trials each time it releases a new version of its operating system, as PC-using hackers want the OS, but not necessarily the Mac.

Apple as yet hasn’t allowed virtualisation software developers to create ways in which Mac OS X can be run on an Intel-based Windows machine, though this weekend’s Leopard news shows it’s possible.

McAfee buys ScanAlert in potential $75 million deal

McAfee has announced that it will acquire certification vendor ScanAlert in a deal potentially worth $75 million. McAfee will pay $51 million up front for the Napa, Calif.-based company, as well as $24 million if performance targets are met. The acquisition is McAfee’s second in weeks. The company acquired encryption provider SafeBoot for $350 million on Oct. 8 to boost its enterprise data security offerings.

Dave DeWalt, McAfee president and chief executive officer, said today that the acquisition will help to make e-commerce safer.

“Consumers are expected to spend nearly $160 billion dollars this year on products and services online, providing personal credit card information to e-commerce websites, many of which have traditionally been under-protected,” he said in a news release.

ScanAlert, best known for its Hacker Safe certification, has a customer list that includes the American Red Cross, Guess, Petco, Toshiba and Warner Brothers.

ScanAlert will be integrated into the Santa Clara, Calif.-based anti-virus vendor’s Web Security Group, and will be led cooperatively by Ken Leonard, ScanAlert chief executive officer, and Tim Dowling, a McAfee vice president.

“The mission of the Web Security Group is to bring transparency to the web so that consumers can distinguish between the safe neighborhoods and the dark alleys,” said Dowling. “We already know from numerous studies that consumer confidence is eroding, and as a result, tens of millions of dollars are left unspent online.”

A McAfee representative could not immediately be reached for comment.

John Pescatore, Gartner vice president and senior fellow, told SCMagazineUS.com today that McAfee has been unpredictable in its acquisitions of smaller companies.

“The only common thing its done is acquire relatively small companies,” he said. “They’re not doing the Symantec thing of buying the large security companies.”

Symantec snares Vontu for $350 million

Symantec has plunged into the data-loss protection (DLP) market via the acquisition route, announcing on Monday that it has agreed to purchase partner Vontu for $350 million. The acquisition, rumored for several weeks, further validates the hot DLP sector, where a number of large players, including EMC and Websense, already have snatched up similar companies. Symantec took a similar approach. “The big guys are gulping these companies up, basically,” Chenxi Wang, the principal security and risk management analyst for Forrester Research, told SCMagazineUS.com today.

Wang said she believes the addition of Vontu’s DLP software, which is used to control the flow of sensitive information across corporate networks, is a smart move for Symantec.

“That piece of their content security strategy is now more comprehensive, and that’s important for them strategically,” she said.

The DLP arena is “a hot market, and the average customer is looking” at data-loss protection software, she said. “Strategically, this market can grow, and also Vontu has a good reputation.”

Several factors led to the acquisition, said Ken Schneider, chief technology officer and a fellow in the security and data management group at Symantec.

“We saw Vontu as head and shoulders” above the other vendors in the DLP market, he told SCMagazineUS.com today. In addition, Symantec had already integrated Vontu technology into its SMS 8300 appliance that prevents emails and instant messages with sensitive data from leaving the network.

The acquisition is “all about protecting data and answering three simple questions for chief information security officers: Where is my confidential information stored in the organization, how is it being used, and how do I prevent it from being lost?” Steve Roop, Symantec’s vice president of marketing and products, told SCMagazineUS.com today.

The Vontu acquisition will also give Symantec better traction in the so-called “e-discovery” arena, Roop said.

“Vontu’s discovery capabilities can reach into Symantec archival and backup and content repositories and help companies comply with the new rules of e-discovery,” he said.

The DLP niche has become a growing star within the broader IT security market, expanding to about 35 to 40 vendors. Some experts, such as Nick Selby of The 451 Group, have said the plethora of solutions do very little to differentiate themselves from each other.

But all hope to grab a piece of the growing compliance-driven needs of customers in heavily regulated industries — most notably, financial services, say experts.

Vontu was one the largest remaining independent developers of DLP software, which has been hyped as one of the few available ways to protect against insider threats. Insider threats can lead to the theft of data customer records or valuable intellectual property by employees, business partners or malware attacks.

In addition to the Symantec-Vontu deal, other acquisitions in the DLP market so far this year include EMC’s purchase of Tablus in August for an unknown amount, Websense’s buy of PortAuthority for $90 million in January and Raytheon’s acquisition of Oakley Networks for an undisclosed amount in September.

Not surprising, reaction to the Symantec-Vontu deal was mixed. Symantec competitor McAfee, for instance, went on the offensive.

“Even with its acquisition of Vontu, Symantec still doesn’t compare to McAfee as a data-protection vendor,” Vimal Solanki, senior director of product marketing at McAfee, said in a prepared statement. “McAfee was the first major security vendor to offer DLP (with the recently announced SafeBoot acquisition).”

So did Websense: “Though Symantec claims the acquisition of Vontu is strategic, given its past history with acquisitions, it is likely that the level of focus on the technology will decline and future innovation slow, which may force Symantec to rely on their size rather than a best-in-class technology to sell the DLP solution,” the company said in a prepared statement.

Tizor, which offers database monitoring tools, took another tack.

“Symantec’s acquisition of Vontu validates the heightened importance of protecting data in today’s enterprises,” said Bill Bartow, vice president of product management at Tizor. “It makes sense that the big security players would take a strong interest in data leakage because that’s what the enterprise market has been focused on in recent months.”

Anti-spyware demo revealed as malware in disguise

A strain of malware disguised as anti-spyware has become the latest double-agent in multi-step “convergence” crime online. The scam, which prompts users to download malware by posing as an anti-spyware demo, has proliferated dramatically. Reported incidences of its distribution have increased by 1,000 percent in the last month, according to Don Jackson, senior analyst at SecureWorks.

Jackson believes the scam is being hosted by hackers using Russian Business Network services (RBN), an illegal ISP responsible for hosting a significant amount of malicious and criminal content on the web.

The scam reportedly lures users browsing “a legitimate, high-traffic website where a legitimate-appearing ad is hosted,” claims Jackson.

A spokesperson for MessageLabs said the scam is similar to any other involving adware: “These things are coming off legitimate websites with material linked back to a disreputable source,” the spokesperson said.

The malicious link from the advertisement then initiates a pop-up warning to users about a false security threat and prompts them to download a demo anti-spyware package, which they can then purchase; giving hackers immediate credit card details and a delivery method for a trojan such as Zlob, said SecureWorks’ Jackson.

He suggested that the benefits of these types of scams for the hacker come through the on-selling opportunities for credit card information and selling access to infected computers.

Jackson also pointed out that while these scams present multiple benefits for hackers, they also rely on “a high degree of collaboration among a number of internet criminals for the full ‘supply chain’ to benefit to the greatest possible extent from the scam.”

“What we’re seeing a lot of is the convergence of attacks and groups of cybercriminals working closely together, there’s a network of bad guys out there,” said MessageLabs’ spokesperson.

“Everyone’s using each others technology, so the spyware guys will use spam tech to get out the spyware, which collects info for the spammers.”

SecureWorks’ Jackson claimed that these attacks are operating in a “grey area” of the law, as providing demos of anti-spyware software isn’t regarded as a criminal offence.

Despite the threats posed by such attacks, some experts believe that these increasingly complex scams present evidence that the security industry is winning the battle against malware writers: “The fact that it sounds complicated can be taken as a sign that we’re beginning to do very well,” said Paul Ducklin, head of technology at security firm Sophos.

Symantec and Microsoft co-operate on security

Antivirus specialist Symantec has joined a security organisation alongside Microsoft, despite having previously come to very public blows with the software giant over its willingness to share security information on Vista. Announced at the RSA Conference Europe 2007 on Tuesday, Symantec and Microsoft will join the Software Assurance Forum for Excellence in Code (SafeCode), which claims to be a not-for-profit organisation aimed at increasing trust around IT. Other members include EMC, SAP and Juniper Networks.

Commenting on questions about the recent argument between his company and Microsoft over Vista application programming interfaces (APIs), Ilias Chantzos, Symantec’s government relations manager for EMEA, said that the two organisations would co-operate in SafeCode in order to benefit customers.

“We have a multi-faced relationship with Microsoft and we are keen to work with them. That will ultimately benefit our customers. I see this relationship as complimentary rather than competitive,” Chantzos said.

Last year, security companies, including Symantec and McAfee, complained that Microsoft had locked them out of the Windows kernel. The security vendors claimed that a kernel shield developed by Microsoft, called “PatchGuard” and intended to stop hackers attacking 64-bit versions of Vista, blocked their security products too.

Microsoft eventually agreed to provide security companies with access to the 64-bit APIs but didn’t actually provide access until two months after it had officially relented.

Microsoft had long maintained that a complete lock on the kernel would provide the best operating-system security and stability, but it made concessions in response to antitrust concerns raised by officials in Europe and Korea.

SafeCode is being headed up by cybersecurity expert Paul Kurtz, who was one of the founding members of the Cyber Security Industry Alliance (CSIA) and a former White House National Security Council and Homeland Security Council member under Presidents Bush and Clinton.

Kurtz claimed that the organisation is the first global industry-led body aimed at the development and delivery of more secure and reliable hardware software and services.

“Where are the best practices? Everyone talks about them, but how do you find them? SafeCode is going to bring those best practices into one place so that government, consumers and businesses can make best use of them,” said Kurtz.

Kurtz added that SafeCode will be assembling an advisory group of government leaders and critical infrastructure operators from around the world to help with its mission.

The organisation will be funded via a $50,000 (ÂŁ24,000) membership fee levied on each of the members, Kurtz added.

“We want to be seen as an organisation that government and industry can turn to and say: ‘Can you help us with this?’,” said Kurtz.

Linux systems rank high on spam sender list

Linux systems are five times more likely than Windows machines to be used to send spam, according to a Symantec report that highlights the part that Linux plays in the growing spam problem.

The findings were published in Symantec’s MessageLabs Intelligence Report for April, published on Friday. The company used a technique called ‘passive fingerprinting’ to identify the operating system of a spam-sending machine, then calculated the ratio of spam from a given operating system compared with its market share.

Linux systems originated 5.14 percent of spam, compared with 92.65 percent for Microsoft Windows systems. But Linux only has 1.03 percent of the operating system market share, as opposed to 91.58 percent for Windows, according to Symantec. (For the market share figures, Symantec used research from Net Applications.)

“By calculating a ratio of spam from a given operating system compared to the market share, we can get a ‘spam index’, which shows — relative to its market share — the likelihood that a particular computer is sending spam, based on its operating system,” Symantec said in the report.

The resulting calculation gave Linux a “spam index” of 4.99, compared with an index of 1.01 for Windows.

“In the current spam climate, this index shows that relative to its market share, any given Linux machine is five times more likely to be sending spam than any given Windows machine,” the company said.

The figures do not necessarily show that Linux is being disproportionately targeted by spammers, or that it is less secure than Windows, but rather seem to be related to the fact that Linux is disporportionately used to run email relay systems, according to Symantec.

In some cases, the problem seems to be that such relays have been set up without following basic anti-spam precautions, according to Mat Nisbet, a malware data analyst with Symantec.

Nisbet said he investigated the originating IP addresses of a random selection of spam from Linux systems. In most cases, he found the spam came from a machine running an open-source mail transfer agent such as Postfix or Sendmail that had been left open to relaying email from third parties.

“This suggests that one reason there is so much spam from Linux could be that many companies that have implemented their own mail servers and are using open-source software to keep down costs have not realised that leaving port 25 open to the internet also leaves them open to abuse,” Nisbet said in a Friday blog post.

Organisations looking to use Linux as a mail server need to make sure they know how to set it up securely, he added.

“Make sure that the systems are correctly set up to restrict access on port 25 to only authorised users (for example, attached to the local network, or through VPN),” he wrote.

Another factor that could be skewing the statistics is that some ISPs force all their users’ mail to go through their own hosts, which are often run on Linux systems, Nisbet said.

“This means that a lot of botnet traffic which we would normally identify as something else, instead appears to be coming from Linux,” he wrote.

Symantec study misses the point over Linux spam

The latest MessageLabs Intelligence Report from Symantec Hosted Services is filled with interesting and useful information regarding the current state of malware and e-mail borne threats as well as the trends over time. Of particular interest to me is the assertion in the report that “any given Linux machine is five times more likely to be sending spam than any given Windows machine.”

I am generally one of the first to point out that the security risks associated with the Windows operating system are often exaggerated, or at least that the relative threat level is a function of market share, and that if Linux or Mac OS X had 90 percent market share those systems would be at least as vulnerable, and at least as targeted by malicious attack as Windows is now. That said, saying that Linux is five times more likely to distribute spam than Windows seemed like skewed math for the sake of sensationalism.

I checked with other malware security experts to gather some additional insight on the issue of Linux as a purveyor of spam. What I found was a consensus regarding the root cause behind the metrics, and ultimately that Linux may, in fact, be an inordinate source of spam messages.

Tyler Reguly, lead research engineer for nCircle, told me “I actually find the report rather odd, and also question their methods for remote fingerprinting. If they were using passive fingerprinting on mail coming into their server, they wouldn’t necessarily have an accurate fingerprint of the host sending the mail. They could instead be fingerprinting a mail server with an open relay, or an ISP “smarthost”. They also acknowledged that much of the Linux attributed spam could be coming from direct marketing emails… these would most likely be mailed out through a proper mail server (which is quite likely to be running Linux).”

A security researcher from FireEye emailed to say “We wouldn’t be surprised if these Linux boxes just have TCP port 25 open and are being abused as open SMTP relays. The malware is doing this to hide the locations of the infected (Windows) machine. Modern malware is designed to maintain long term control over systems since the primary cost of building these malware infrastructures is the time and energy needed to “acquire” infected systems.”

Andrew Brandt, lead threat research analyst at Webroot, also found the report potentially suspect “The Spam Index feature in the report appears to overemphasise a problem which may have little to do with any inherent issue or vulnerability with a particular operating system. The spam index seems odd with no context; we don’t know whether there’s any kind of active infection on a machine running a particular operating system.”

The best free antivirus programs

Free antivirus started life nearly two decades ago as security’s poor relation, little more than a way of ensnaring users with limited features that would give them an excuse to upgrade to paid-for software later on. A number of software vendors built their marketing on such products, even if the bigger brands were sometimes too sniffy to dare offering something as lowly as a ‘free’ product.

Then the Internet happened, the browser became the dominant application, and websites emerged as a major means of distributing what became known more generically as ‘malware’. Malware included old-fashioned viruses, but also mass-distribution worms, Trojans (a major new class of program), and a cluster of applications designated as ‘spyware’.

Suddenly, the threat wasn’t just good coding it was bad coding too, with the industrialisation of malware that could exploit software vulnerabilities in the OS, in apps, and especially in browsers and browser plug-ins.

Paid-for AV products found themselves doing a lot more work at a lot more layers of the software stack, and diversified into today’s suites that do everything imaginable, including encryption, firewalling, backup, spam filtering, browser trace deletion, parental control, IM and P2P control, web, file and app monitoring, and all before old-style hard disk scanning is even mentioned.

The problem for security companies is that many pieces of this security jigsaw are at least partially done by free programs, starting with browsers, now secured using layers of settings and URL checking. A reasonable two-way firewall comes with Windows 7 (Vista’s is one-way), and of course the basic AV is handled by free utilities that many users swear by.

The fascinating thing about ‘free’ is how much users get without having to reach for the credit card. But how much is really enough security and which features does the average user need and perhaps not need?

The firewall

Firewalling is a complex issue, and in principle will de done by a gateway device such as a wireless router. In truth these are often complex to configure and understand, leaving most users relying on a desktop firewall that monitors traffic in and out of a PC. Windows 7 ships with a perfectly serviceable one included and the numerous free choices are also excellent to the extent that it’s hard to see why anyone would pay for one.

Frankly, we wouldn’t see a huge point in using a third-party firewall-only product unless you’re still using Windows XP, in which case look to ZoneAlarm or Comodo (which includes optional antivirus), both of which are easy to use, and do what they say on the tin. Whichever product, watch out that is doesn’t hit CPU. And that the Windows version is turned off before installation.

Patching

This tends to be an ignored aspect of security. Windows performs its own update once a month at least, as will individual programs, but out-of-date software, unpatched against known security issues is still a major problem, especially on systems that are not used every day.

A number of free programs exist to examine applications for out-of-date versions, perhaps the best of which is Secunia’s Personal Software Inspector (PSI).

Browser plug-ins

Browser security is much improved but still far from infallible, which is why plug-ins have appeared to address specific problems. There are hundreds of these, nay thousands, and each one s specific to a different browser.

Noscript (Firefox)

Noscript is a Firefox extension that stops Javascript (a major target for security flaws) from running without permission, blocking exploits such as clickjacking and XSS; whitelisting feature lets the user select named sites that can run scripts. Can be a bit intrusive but worth it for the security-conscious.

Trusteer Rapport

Installs in all major browsers and verifies using a small green icon that a website is genuine using built-in lists or those added by the user. For partners sites – banks say – it can also encrypt the keyboard to website communication for secure login, though only small number of sites are covered for this. Even when not using this feature, is a useful and non-intrusive shield against website spoofing.

LastPass

An absolute must and by far the best browser-based secure password store out there. As well as acting as a database of web-based passwords (and a replacement to having them stored insecurely by browsers), it automates logins, stores form data, and has plenty of control over how to treat different sites in a more or less automated way. Can be access from anywhere by any PC using a single master password.

The free antivirus scanner

A basic malware scanner downloads signature files every day which it uses to perform retrospective scans of hard disks for bad files at defined intervals. It will also offer some level of realtime protection against the incursions of rogue software and spam attachments, often by complementing browser security settings. It will also usually monitor for dodgy URLs, though again this is done by browsers and, with lesser reliability, by search engines themselves.

Microsoft Security Essentials

Microsoft dabbled with paid-for security then threw in the towel and came up with this free gem only last year. It has garnered good scores in tests (that is about the same as paid-for products for basic antivirus scanning), uses little in the way of resources, and is extremely simple to configure and use. Basic, yes, but not cut-down in terms of the core features which are file scanning, realtime process monitoring. Will scan inside archives and removable drives, but use in conjunction with browser security add-ons because it does not monitor URLs or watch what’s coming in via email. No frills.

AVG Antivirus Free Edition

The granddad of free, AVG is probably the most popular unpaid antivirus program going. Very similar to the Microsoft product with the addition of an optional browser link-scanner and the ability to create a rescue disk. Not as light on resources as Security Essentials but still more than capable.

Panda Cloud Antivirus (PAV)

A bit of an untested option at present but a curious one. Panda runs in small footprint ideal perhaps for netbook users, thanks its makers claim to its part-signature, part cloud-based intelligence.
It has a lot of features free programs tend to lack. It scans email (inbound and outbound attachments), IM and web browsing, claims to block rogue scripts, and protects against vulnerabilities (although which ones will obviously depend on the remote database), all of which are launched in an on-demand way. It also has an optional firewall and can create a rescue disk.

If Panda Cloud has a problem it is lack of feedback and no scheduled scanning which might bother some. Apart from the occasional update request, it’s barely noticeable, even when browsing websites other programs would take issue with. It did, however, prove its worth against one fairly common Trojan, while the beta version suffered a single false positive.

Conclusion

The best antivirus program from these for light use of resources is Microsoft Security Essentials, the best for features-at-no-cost undoubtedly Panda Cloud Antivirus. The cloud client-server model is an interesting direction others will surely follow in the near future. How does Panda offer a free product tied to an expensive datacentre? Presumably, the malware it detects through the consumer products help it improve the paid-for business version.

More widely, it is clear that stumping up £30-£50 ($47-$70) for a full suite is not necessarily the best option for users even if they are happy to throw money at the security problem. The suite will do everything – a good recent example is Kaspersky’s Pure which includes encryption, backup and parental control – but not necessarily as well as separate programs. Suites tend to be more complex, more resource-heavy, and inevitably elements of each are mediocre.

Any one of these and other free antivirus programs (BitDefender, Avast!, ESET) will do a perfectly good job when complemented with a secure password database, judicious use of encryption, and browser controls.

Back to Top