<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>CoreTrace WhiteSpace&#187; CoreTrace WhiteSpace</title>
	<atom:link href="http://www.coretraceblogs.com/tag/antivirus-software/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.coretraceblogs.com</link>
	<description>The Application Whitelisting and Security Weblog</description>
	<lastBuildDate>Fri, 27 Jan 2012 17:47:15 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.9.1</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>NSS test demonstrates 86% anti-virus fails to protect against Operation Aurora variants</title>
		<link>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/</link>
		<comments>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/#comments</comments>
		<pubDate>Tue, 16 Mar 2010 07:22:51 +0000</pubDate>
		<dc:creator>Toney Jennings</dc:creator>
				<category><![CDATA[rational transition to whitelisting]]></category>
		<category><![CDATA[antivirus software]]></category>
		<category><![CDATA[AV software]]></category>
		<category><![CDATA[cyber attacks]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[malware variants]]></category>

		<guid isPermaLink="false">http://www.coretraceblogs.com/?p=1377</guid>
		<description><![CDATA[A recent study by NSS Labs revealed just how ineffective some of today&#8217;s top anti-virus software solutions are at stopping one of the most highly profiled and successful cyber attacks of 2010. According to the article, &#8220;More Anti-Virus Fail,&#8221; NSS Labs created variants of the Operation Aurora attack to see how many AV products caught [...]]]></description>
			<content:encoded><![CDATA[<p>A recent study by NSS Labs revealed just how ineffective some of today&#8217;s top anti-virus software solutions are at stopping one of the most highly profiled and successful cyber attacks of 2010. According to the article, <a href="http://www.informationweek.com/blog/main/archives/2010/03/more_antivirus.html;jsessionid=54UXHSZ5K3DPBQE1GHRSKH4ATMY32JVN">&#8220;More Anti-Virus Fail,&#8221;</a> NSS Labs created variants of the Operation Aurora attack to see how many AV products caught the malicious code. The result: Only one out of the seven products tested correctly thwarted multiple exploits and malicious code payloads.</p>
</p>
<p>This says a lot about the current state of the AV industry. With so many new viruses and malware variants successfully bypassing security solutions, it is time to shift our way of thinking about how to protect our networks from new and unknown forms of malware and viruses.</p>
<p>With <a href="http://www.v3.co.uk/v3/news/2259467/fbi-reports-online-crime-losses">online crime losses doubling in 2009</a>, we simply can&#8217;t afford to rely solely on AV software to protect our critical infrastructures from the countless number of malware variants out there. If these solutions are already losing the battle against highly visible malware, I can’t imagine the success rate of stopping unknown attacks would be any better.</p>
<p>As an example of how the industry currently looks at these problems, NSS Labs&#8217; CTO, Vikram Phatak, said: <em>&#8220;There are many ways to possibly exploit a vulnerability, and rather than focusing on every attack method, vendors need to focus on [shielding] the vulnerability itself.&#8221;</em></p>
<p>Vikram is correct in pointing out that you can&#8217;t defend against every attack method, but focusing on protecting against exploitation of the vulnerability is reactive, and a failure as well. This still leaves companies open to newly discovered vulnerabilities, relies on reactive patching and security system updates, and will ultimately fall on its face. We need to completely rethink our approach to endpoint security that begins with a foundation of whitelisting that would defeat new malware completely independently of the vulnerability or attack.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.coretraceblogs.com/2010-03/nss-test-demonstrates-86-anti-virus-fails-to-protect-against-operation-aurora-variants/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

