About

This page contains a single entry from the blog posted on August 2, 2007 10:19 AM.

The previous post in this blog was Blue Pill - The attack that won't go away.

The next post in this blog is Attacks on financial institutions customer accounts getting more sophisticated.

Many more can be found on the main index page or by looking through the archives.

« Blue Pill - The attack that won't go away | Main | Attacks on financial institutions customer accounts getting more sophisticated »

Layered defenses get another plug

A former Black Hat today wrote an interesting article in Searchsecurity.com "
Metamorphic malware sets new standard in antivirus evasion". The author, Noah Schiffman, outlines the growing challenge of metamorphic viruses. Read the article as he outlines the general architecture of viruses. At the end he states a great recommendation:

"Protection from any type of metamorphic malware is best addressed by blended threat management platforms using a multi-layered approach. Antivirus software, updated frequently, remote access restrictions and compliance monitoring should be employed at the server and end-user levels. Network and personal firewalls should have any unused service ports shut down. Email servers should employ content filters and file scanning. Finally, any corporate setting should develop, maintain and enforce a well-defined and effective set of security policies. In extreme situations, when dealing with highly sensitive data, extra security measures such as real-time emulation analysis and specialized network segmentation may be considered."

Layered defenses. It's the only way to mitigate risk in today's world.

Guy
www.authenticationworld.com
guy.huntington@authenticationworld.com

TrackBack

TrackBack URL for this entry:
http://www.authenticationworld.com/cgi-bin/blog/mt-tb.cgi/257

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)