I attended a local security conference in Vancouver this morning. I sat in on a presentation from Rob Slade, a well known anti-virus expert. He gave a presentation on cheap and dirty malware detection.
Essentially, his presentation was based that a few known viruses and malware make up the majority of the attacks on enterprises. His idea was to put at the gateway to the enterprise, a device to filter out the known AV's thus leaving more time for the AV, IDS and IPS systems to process for the more unique malware. This eliminates a lot of processing time spent on knowne existing malware.
He indicated that one Vancouver company is trying this idea out. He didn't yet have the data to support his hypothesis but it sounded like a great idea.
I have blogged this for readers to contact Rob if they are interested in pursuing this idea with him.
Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

del.icio.us