About Me

Joe Telafici

Joe Telafici

Read More

Feeds & Podcasts

Blogs

Meet the Bloggers

Archive

Tags

#SecChat $1 million guarantee 12 Scams of Christmas access to live fraud resolution agents Acquisition Alex Thurber Android antivirus Apple botnet Channel Partners cloud security Compliance Consumer counter identity theft credit card fraud and protection credit fraud alerts credit monitoring credit monitoring and resolution critical infrastructure Cyber Security Mom cyberbullying Cybercrime cybermom data breach data center data center security Data Protection Dave DeWalt DLP Email & Web Security embedded encryption Endpoint Protection enterprise facebook fake anti-virus software Family Safety Friday Security Highlights global threat intelligence google government Hacktivism how to talk to kids how to talk to teens identity fraud identity fraud scams identity protection identity protection $1 million guarantee identity protection fraud identity protection surveillance identity surveillance identity theft identity theft expert identity theft fraud identity theft protection identity theft protection product Identity thieves and cybercriminals intel iphone kids online behavior lost wallet protection malware McAfee McAfee Channel McAfee Family Protection McAfee Identity Protection McAfee Initiative to Fight Cybercrime McAfee Labs McAfee security products Mid-Market Mobile mobile malware mobile security monitor credit and personal information Network Security online personal data protection online safety Operation Aurora PCI personal identity theft fraud personal information loss personal information protection phishing privacy proactive identity protection proactive identity surveillance Public Sector restore credit and personal identity Risk and Compliance scam scams scareware security smartphones social media social networking social networks spam Stuxnet twitter vulnerability Web 2.0 work with victim restore identity

Live from VB2006

Thursday, October 12, 2006 at 11:31am by Joe Telafici
Joe Telafici

I’m here at the booth at VB2006 skipping lunch to write some thoughts and observations from lovely Montreal, where the weather, at least today, is very much reminding me of home back at Portland, Oregon .

The conference is a three-day affair again this year, and was preceded by a day of meetings by various industry and user consortia and groups. We began by discussing new testing and certification methodologies designed to go beyond the standard approach of “scan a static collection and count how many were detected.” It’s probably not apparent to most people exactly how much thought, planning, effort and careful interpretation goes into running a scientific, valid, repeatable and meaningful test of a security product.

A big topic seemed to be how to test security products (and behavioral products to a degree) against running malware. Do you exclude rootkits or not (because they can render the measurement techniques invalid)? Do you install the security product after the machine is infected, or do you install it before, but disable the on-access scanner? How do you count legitimate third-party libraries? Harmless images and text files? How do you ensure the malware doesn’t start or stop installing some other piece of code midway through the test? We have our own answers for testing our software, but trying to get agreement among a huge array of vendors is a job I’m glad I don’t have. It probably also explains how bad reviews happen.

Actual talks began late morning yesterday, and were kicked Off by Mikko Hyponnen’s review of malware history from the early days to today. Our own Allysa Myers presented on the possibilities around bot herders using IM to perform command and control functions, and Igor Muttik on scanning of HTTP-borne threats without killing performance. There have been some excellent talks on anti-rootkit techniques, botnet monitoring, some of the subtleties of the spyware landscape and a sort of point-counterpoint discussion of the effectiveness of user education vs. technological solutions. In general, some differences seem apparent generally about the industry this year. There are fewer talks on botnets and rootkit techniques than last year, it seems, and more discussions of behavioral technologies and mobile threats. Spam is also more prominent this year, and this broadening of the technological landscape seems to be paired with a broadening of the vendor and customer organizations represented here this year. It seems so far like the conference is mimicking the malware world today.

Bookmark and Share

Submit your own comments / message for this post

Your email is never published nor shared. Required fields are marked *

 

You may use these HTML tags and attributes: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

Comments (0)