ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Worm detector looks out for bad behaviour

Munir Kotadia ZDNet.co.uk

Published: 20 Jan 2004 15:15 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Firewall maker Check Point launched a security appliance on Tuesday that it claims will protect corporate networks from cyberattacks that exploit known vulnerabilities in LAN protocols and applications.

The InterSpect appliance works by having access to a regularly updated database of known vulnerabilities. When packets associated with a particular application start acting suspiciously, the InerSpect appliance takes over, quarantines the affected PC and warns the user that all network access has been temporarily revoked while the computer is being cleaned.

Nick Lowe, Check Point UK's managing director, told ZDNet UK that although companies are used to protecting their network's perimeter, problems occur when malicious code is introduced from the inside -- through an infected notebook PC, for example. Lowe said InterSpect allows a network to be segmented, so high risk areas -- such as a 'touch-down' zone, where lots of notebook users work -- could be quickly blocked off from the rest of the network in case of an outbreak.

"If a laptop infected with a worm is plugged into the touch-down area, InterSpect will physically stop that device from attaching to the corporate network. Instead, it will be connected to another part of the network that gives it access to the services required for fixing and cleaning the PC," said Lowe.

Lowe said that these kinds of safeguards are required because companies want to do a series of checks and tests before they deploy new patches, which gives malicious code writers a chance to exploit vulnerabilities. Lowe gave MSBlast as an example, where the vulnerability was announced in April 2003 and a patch was published in July. The MSBlast worm was released in August of the same year -- and although the vulnerability had been public knowledge for months, signature-based systems were punished. "Until that point, no signature-based system could detect the worm and afterwards, if the worm mutated, they would have to be updated again," he said.

Had InterSpect been available before MSBlast, said Lowe, it would have recognised that the vulnerability Microsoft had earlier published was being exploited. "We are not looking for known bad packets, we are looking for application behaviour that addresses those vulnerabilities. We can conclude it is not natural application behaviour; therefore the packet structure and flow is malicious, so we block it," he said.

Research firm IDC said the security appliance market is showing strong growth, but Check Point is likely to face tough competition from Cisco and NetScreen, who currently dominate with market shares of 27.7 percent and 20.8 percent respectively.

Check Point's InterSpect supports, among others, the CIFS, MS SQL, DCOM, Sun RPC, DCE RPC and HTTP protocols. The product will cost between $9,000 and $39,000 and is available immediately.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
81 out of 154 people found this useful


Company/Topic Alerts

Create a new alert from the list below:










Related Jobs

Behaviour Engineer

Experience in 3D Animation and synthesising physical human behaviour is also beneficial. My client is seeking a candidate to create and optimize ...

JAVA, SML / XSLT, JSP, HTML, Javascript DEVELOPER 40,000 London

Desirable skills include XML RPC, ANT, CVS, Oracle, JSP, HTML, Javascript, swing and Junit The ideal candidate will have a good understanding of ...

Software Engineer! Embedded, C,C++! Linux/Solaris! Protocols! Hants!

You are required to have strong embedded/C/C++ experience with a thorough understanding of Protocols and such as Signalling- SS7/TCP-IP and device ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation