10/27/2008

prevx has its own blacklist of insecure securitytools

It was remarkable to see that HIDS - process and code controller software Prevx that says it discovers anything that ain't normal so low in the list of the number of new bad binaries that were found on that honeypot (see previous post).

len03003

There are some things clear from this test

the free versions (Avira and AVG) aren't worse than the paid ones

Some products do better in this test than with other samples. Alhtough it is not clear what constitutes a securitytool and what is malware. It all depends on how you categorize it. Some of my tools on my computer are for me securitytools but are in such analysis counted as malware.

And if you go to this page, you will see that silent bankers malware that intercept your online banking details many times not detected or not all of them. Although it is clear they don't stay long undetected, but a transfer of money doesn't take days online....

If you are targeted, you are dead, point final. Nothing is good enough to protect you 100% anymore. So if there are things that you want absolutely not endangered, it shouldn't be on your network or it should be superprotected and seperated on your network. And networkdefense and monitoring is human work with eyes on all these logs and connections and changing states of machines and dataflows. It should be clear that there is no automatic defense anymore that is capable of defending the most important goods in your network against the newest handmade adapted malware - as the latest microsoft exploit has shown.

13:08 | Permalink | Comments (0) | Email this | |  del.icio.us | | Digg! Digg |  Facebook

Post a comment