while i'm talking about trend micro i might as well mention this post advocating the boycott of their products because of their patent infringement suit against barracuda networks...
apparently there seems to be the idea that trend is trying to attack clamav and it's users through this suit, but i'm sure nothing could be further from the truth...
the fact is that clamav has been openly derided in the av community as inferior technology for years... nobody bothered trying to sue clamav when it was on it's own, and nobody tried when they were gobbled up by sourcefire... it would have been pointless and it would have lended credibility to a technology that has none...
the suit has nothing to do with the scanner technology and everything to do with the application of that technology... if trend has a valid patent (and since they've sued more mainstream av vendors over the same patent it seems like it might be) then people who make products using techniques covered by that patent need to work out a deal with trend... that's just the way patents work... i'm no intellectual property maximalist (heck, i classify DRM as a type of malware) but i recognize the law of the land when i see it...
barracuda isn't being singled out, clamav isn't the focus of some conspiracy by trend, other av vendors have had to deal with exactly the same intellectual property issue and somehow managed to resolve it... barracuda needs to do so as well, and some open source zealots need to get over themselves...
devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...
Showing posts with label clamav. Show all posts
Showing posts with label clamav. Show all posts
Tuesday, June 24, 2008
Saturday, January 05, 2008
everything old is new again
well, it seems like the past is coming back into style again...
there's behavioural detection in anti-virus suites, there's boot sector malware (even though it never really went away, it just died down to background noise levels) in the form of a new MBR stealthkit (anyone want to hazard a guess what this will mean for the wipe and re-install folks? 'cause format doesn't touch the MBR and fdisk isn't necessarily as straightforward as an average user would like), and now there's home made anti-virus signatures?
yup, jose nazario posts to show how to create clam anti-virus signatures for the latest storm trojan emails...
y'know, i remember when more mainstream anti-virus products had virus description languages that were simple enough that arbitrary people could create their own signatures... however, that was back in the early '90s when they were still growing out of being simple string scanners - when handling polymorphism simply meant using wildcard characters in the scan string (the precursor of today's virus signature, composed of a sequence of bytes often in hexadecimal form)...
i can honestly say i was surprised to find out that such an ancient technique could still be used with clamav; and if you think i'm being too critical of clam, look closely at the instructions in the article - those appear to be quite literally scan strings (and apparently no wildcards) in ascii form...
there's behavioural detection in anti-virus suites, there's boot sector malware (even though it never really went away, it just died down to background noise levels) in the form of a new MBR stealthkit (anyone want to hazard a guess what this will mean for the wipe and re-install folks? 'cause format doesn't touch the MBR and fdisk isn't necessarily as straightforward as an average user would like), and now there's home made anti-virus signatures?
yup, jose nazario posts to show how to create clam anti-virus signatures for the latest storm trojan emails...
y'know, i remember when more mainstream anti-virus products had virus description languages that were simple enough that arbitrary people could create their own signatures... however, that was back in the early '90s when they were still growing out of being simple string scanners - when handling polymorphism simply meant using wildcard characters in the scan string (the precursor of today's virus signature, composed of a sequence of bytes often in hexadecimal form)...
i can honestly say i was surprised to find out that such an ancient technique could still be used with clamav; and if you think i'm being too critical of clam, look closely at the instructions in the article - those appear to be quite literally scan strings (and apparently no wildcards) in ascii form...
Tags:
anti-virus,
clamav,
jose nazario
Subscribe to:
Posts (Atom)