Main | Forecasting Crowd Behavior »
Wednesday
Jun242009

Experts dropping AV, now what?

virus_1.jpg

I was pretty happy to see the CSO article about experts dropping anti-virus posted today. Signature-only detection techniques are nearly ineffective today and will continue to get worse (see my post on polymorphism here.) It's good to see press coverage around this issue and some examples of how security veterans are protecting their systems without AV.

However, the article indicates that only "Security Experts" should take this step. Why?? If anti-virus is not effective why should it be the solution pushed on the non-technical users? I'm guessing these security experts are using manual tweaks and other techniques that are not easy to scale. Fair enough, but if you are responsible for security of a user population you *need* to educate yourself on alternative endpoint security options. The endpoint is critical to protecting your environment and is probably where you can get the biggest ROSI right now. And there are plenty of advanced endpoint security solutions (like behavioral HIPS) that are widely deployed and operationally scalable.

 

PrintView Printer Friendly Version

EmailEmail Article to Friend

Reader Comments (1)

I'd like to add commentary mostly due to the fact I like to support your cause here at Exultium!

I for one feel that the commentary is rhetorical at best and may never really get employed if in fact applied. Bottom line, A/V vendors are more Mal-Ware and Spy-ware prevention tools that Virus blockers than ever. Keyloggers, Bot-nets, and Spy-ware are king when it comes to end-point threats and Symantec and McAfee have more than 700% more signatures every week in this concentration than Viruses no doubt. Secondly, many organizations are thinking green and going virtual. With Citrix and VM Ware getting folks to evalutate the virtualization of the desktop in addition to the server environment, it very well may deem appropriate to eliminate all end-point security with a dummy terminal in the end. That is, if the company is no in the market of engineering or design of technology. Healthcare, retail, hospitality, manufacturing and education for sure woudl benefit immesly from the elimination of end-point security technologies and replacing their application heavy PC's with stripped OS end-points that save no data locally- and gain all access to applications and data from the virtual server it resides on in the data center. This also addresses the challenge of Data Loss prevention and end-point encryption, two very expensive and front of moind topics for all Corporations in the next two quarters for sure. The mass state breach law has been extended three times now, and it's sure to be enforced in full by this March at this point- the time has come, and there is teeth in this regulation!

Why even think about end-point security when the most optimal position in thin computing? No need for encryption on the end-point, HIPS, or desktop lockdown strategies. Save your money, and FTE resources! It's 1985 all over again people!

September 27, 2009 | Unregistered CommenterMark Tremblay

PostPost a New Comment

Enter your information below to add a new comment.

My response is on my own website »
Author Email (optional):
Author URL (optional):
Post:
 
Some HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>