Home

software Directory


More
software Articles

WRITERS WANTED! (click-me)

Feature Article:

Parental Internet Control Tips - Choosing Software
The Internet is one of the greatest inventions of all time. Parental Internet Control will protect our loved ones from internet filth like pornography and hate material just a click away. The fact that every stranger in the world has access to your...
...Read More

Free Software for Newbies and Web Developers
Here is some free software tools to help you build your own websites and create web products. Learning new skills is not difficult. It just takes a bit of willingness to give it a go. You will feel great satisfaction knowing that you can do...
...Read More

pcsoftwarebusiness.com

The Risks of Desktop Security Software - Part 1

pcsoftwarebusiness.com       Navigation

This is the second in a series of articles highlighting reasons why we need a new model for anti-virus and security solutions.

Reason #2: the Desktop Security Software Risks

The risks of placing software on the desktop are such that I will be breaking this article into two parts.

Fundamentally we think of having software on our desktops as a good thing. I love downloading or installing new packages and seeing what new creative things people do to the user interface or what they do to make certain aspects of my life easier or more fun.

But there are problems inherent with software that resides on the desktop, especially security software. All developers will know what I mean. First and foremost, desktop software can be reverse engineered. What’s that mean? Have you ever inadvertently double-clicked on a file and had garbage show up or seen something that looks similar to this?



The old hex dump. Programmers will know it well. We actually spend a good deal of time trying to read this stuff. Basically, if there are programs that can (and do) turn instructions like the following

If UserBirthDate < “01/01/1960” then
IsReallyOld = “Yes
Else
IsReallyOld = “No”
End If

into something like the picture above, then the reverse is true: people have developed software that can take that gobbeldy-gook in the picture above and turn it somewhat into the if-statement I wrote out. The reversing software won’t know that I had an item called UserBirthDate, but it will know I was testing for a value of January 1, 1960 and it will be able to say that based on that value I set another item to Yes or No.

So now we install our fool-proof anti-virus software on our desktop (or our firewall for that matter). Well, so too can a virus author. And that virus author or hacker will also have gotten a copy of the latest reverse-engineering software from his local hacking site. He now goes upon his task of reverse-engineering the software and then trying to decipher the results. It’s not easy but it can be done. Unfortunately, vendors know this and understand this as an acceptable risk.

The problem here is that your security software is at risk. If your vendor codes an error, the virus author can and will detect it. For example, if your vendor should exclude a file from scanning, it’s possible the virus author will figure out which file (or type of file) that is and bury his code there. If the vendor excludes files from scanning or heuristics, it’s possible that virus author will figure out a way to corrupt that file.

That being said, there are other risks. As we have said, once software is on the desktop it affords virus authors an opportunity to reverse-engineer security software. The knowledge that reverse-engineering provides is invaluable to a virus author when building his next software attack. Third, virus authors can learn where the anti-virus vendors put there software and put the links to their software (directory folders, registry entries, etc.). This too is invaluable information. In fact, in some ways it teaches people intent on writing malicious software clues as to how to infiltrate the computers’ operating system, where registry entries need to be made to force software to be loaded every time a computer is started, etc.

This information is generally available all over the web and in manuals for operating systems, especially manuals on such subjects as the Windows Registry. But having the software teach you where things belong to be effective is powerful knowledge.

Lastly, and perhaps most significantly, is the issue of forebearance. The anti-virus vendors usually know more about the potential exploits inherent in programs than virus authors but they are bound by the fact that should they try to prevent them before the exploits occur, they could be branded as irresponsible for teaching virus authors about these very exploits.

For example, when Microsoft first released the macro capabilities of Word, anti-virus vendors immediately realized the potential for danger in macros, but they were handcuffed. If they released software that disabled macros before the first macro virus was ever released, they would signal to virus authors the inherent destructive powers of macros. They chose instead to wait, handcuffed by the limitations of desktop software.

Until the Internet there really has been no better medium for delivering virus solutions than desktop software. It was relatively inexpensive to deploy (either market the software and sell it in stores or provide free downloads on bulletin boards and web sites). It is, however, expensive to keep updated in terms of time and effort, even with automated update systems.

The Internet caused several things to happen: by becoming a powerful medium for sharing files, whole families of viruses disappeared practically overnight (boot sector viruses, for example); by becoming the option of choice for sharing files, it was easier to infect a single file and have thousands download it.

A better solution is to place the security software in an offsite appliance of its own making. All Internet, intranet, networking connections flow through the appliance.

Selling off the shelf hardware appliances with built-in security software is better than a desktop software solution but it still suffers –to a lesser extent- from the pratfalls that desktop software falls prey to.

Even better is to create a service that a 3rd party vendor manages in a secure environment. In such an instance both the software and the hardware are away from the prying eyes of the malicious software authors. This further reduces the opportunity for malicious authors to discover the tricks and techniques employed by the security vendors to protect you.

About the Author

Tim Klemmer
CEO, OnceRed LLC
http://www.checkinmyemail.com
Tim Klemmer has spent the better part of 12 years designing and perfecting the first patented behavior-based solution to malicious software.

pcsoftwarebusiness.com

More Reading:


How To Develop Software For Your Business

Integrated Manufacturing Software Profiled by TR Cutler in Time Compression Technologies Magazine

ISO 9000 Software Products

Amara Flash Photo Animation Software supports Ken Burns Motion Effects

Among the Graphic Software Programs I Go for

 
Graphic Artists Academic Software Can Save You Money

Starting a Software Product Company

Software Promotion

Real estate software for Palm PC

How software advances are revolutionizing email marketing tactics

software Home

software Directory

Additional Reading


What The Tax Software Companies Don't Want You To Know
Haven’t done your taxes yet? No problem. Now there is a new way you can use top tax software programs, like TurboTax and H&R Block, to get your taxes done quickly and easily. And the best part is it won’t cost you a thing. The secret is an IRS...
...Read More

Personal Asset Preventive Maintenance Software -
Personal asset preventive maintenance software exists to help people manage and maximize the value of their assets. Common types of personal asset preventive maintenance software deal with taxes and investments. Software that manages other types...
...Read More

The contemporary global marketplace - "IT, Software and Services"
“Had there not been outsourcing and utilization of cheaper resources offshore, average computer users would not have been able to afford the hardware and software that are available to them today.” In this manner, author Robin Sood brushes aside...
...Read More



 

 

Internet Search for: virus, desktop, software

Top Ranked  Results for virus, desktop, software:

Search results in our directory for:
virus, desktop, software
  1. Anti-Virus Software: Is the Cure Worse Than the Disease? - IT ... [Preview]
    Is desktop anti-virus software headed for irrelevancy, or is it on track to endure as a security measure? That question has surfaced repeatedly in recent years. ...

  2. McAfee VirusScan (free download) " TechWeb " Boston University [Preview]
    Home " Desktop Computing & Printing " Virus Protection & Security " ... the latest virus definition updates for your anti-virus software after you install. New viruses are coming ...

  3. Removing a Desktop Virus | eHow.com [Preview]
    If a virus has infected your desktop computer, chances are it will spread and infiltrate ... Antivirus software can effectively remove even the most destructive viruses, and ...

  4. Desktop Security 2010 (DesktopSecurity2010) Virus Removal ... [Preview]
    Desktop Security 2010 is a fake antivirus program. This page provides free help on how to remove Desktop Security 2010.

  5. Networking Security Software Anti Virus Desktop | Business.com [Preview]
    Providers of software applications that protect computer networks. ... Networking Security Software: Anti Virus, Desktop. Home " Directory " ...

  6. Gear Diary | Tag Archive | Desktop Software [Preview]
    Tags: Desktop Software. Some people have no trouble organizing their ... The virus protection software problem forced about a "third of the hospitals in Rhode ...

  7. Anti Virus Software Download Center [Preview]
    We offer anti virus software. ... Home: Anti Virus Software. RAV AntiVirus Desktop 8.6 - Protects the contents of your PC from malicious computer viruses. Although the focus here ...

  8. Linux a Virus Target? [Preview]
    News, views, and articles on using Linux on enterprise and end-user desktops. ... Secure desktop software could eliminate the entire anti-virus industry. ...

  9. McAfee Virex for Macintosh - AntiVirus Protection for Macintosh [Preview]
    McAfee Virex utilizes the award-winning McAfee scan engine for complete, proactive antivirus protection for Macintosh systems.

  10. Antivirus Firewall Software Reviews | Desktop Security Software [Preview]
    We Compare and Review The Best Antivirus Firewall Software Programs. The Right Desktop Security Software Will Keep Your Computer Safe and Free From Viruses, Trojans, ...



 

Copyright    pcsoftwarebusiness.com