PDA

View Full Version : Life After AV: If Anti-Virus is Obsolete, What Comes Next?


Technodrome
July 8th, 2002, 11:00 PM
Link to source article: http://online.securityfocus.com/infocus/1604

-{ Quote: "In a previous article, Past Its Prime: Is Anti-Virus Scanning Obsolete?, I discussed the reasons why I believe that anti-virus scanning as we now know it is obsolete and must be replaced. In this article, I will address what I believe will be its replacement - behavioral blocking - including what is currently available, and how behavioral blocking needs to function for it to successfully defeat malicious code.

Before briefly reviewing the available products, I will define what I mean by behavioral blocking. When I use the term, I am referring to a technology that has the ability to run suspect programs in multiple virtual operating systems, determine precisely what the code does and then...

.
.
." }-

UNICRON
July 9th, 2002, 12:14 AM
Good read. I'd say what we need most is user education (badly), and for people to not run there computers under the administative account. Those two things would reduce the problems 100 fold.

FanJ
July 9th, 2002, 04:56 PM
Yep, very interesting read!!!
Something to read again; thanks TD !

I was glad he mentioned Integrity Checkers, although I have to read that part again.....

root
July 9th, 2002, 10:55 PM
A couple of years ago there was a French Anti Virus program, that used behaviour blocking. It had no database, instead it looked for virus type behaviour. I used it for a while and found several articles that said it was a technology whose time had not yet come.
I lost track of it after a couple of years. For the life of me I cannot remember the name of that program, but it did work to some extent.
Anybody know what I'm talking about and if its still around?
Also, I am a beta tester for m@ildefense, by In defense and it works great. I guess I don't know what technology its using, but it is not database. There's no updating to it.