Advertisement
Promo

Security threats Toolkit

Sophos: Protecting the world from The Pentagon

Tom Espiner ZDNet.co.uk

Published: 28 Nov 2005 16:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...connected to the Internet — the perfect hosts for any rogue programs. "Malware can come into the honeypot, but can't get out because of a separate hardware firewall blocking it," says Svajcer.

Honeypots
Typically honeypots are Windows machine running without XP service pack 2 (SP2) or any antivirus software. There is a 50 percent chance of infection within 12 minutes and a 90 percent chance within 40 minutes.

To be able to tackle the large number of files that need to be checked for viruses (more then 2000 a day), Sophos uses different automated techniques to filter and separate known infected files from known clean files, and from files that are not considered "infectious" (some image and data formats and corrupt files).

All files that pass through the initial filtering stage are forwarded to the automated analysis filtering system known at Mentor. All incoming files are also passed through a manual system where a Sophos technician uses various analytic tools to work out how the malware works and how much of a threat it may be. After the malware is identified and another round of testing and analysis done, it is eventually published and Sophos' products are updated to recognise it.

Report directly
As well as the information gleaned from the honeypot system, many Sophos products, such as PureMessage or MailMonitor, also have the capability to report back to the company directly. Should the customer turn on this capability, Sophos will receive raw data at set intervals. This is then crunched through a reader and organised in a way that can be read and understood.

"As we have large bodies of customers and honey traps all over the world, we can ascertain whether there are differences in the type of threats that are attacking different users. This information is useful when trying to establish trends, and it can also help us report useful information to law enforcement authorities, particularly when you combine trend information with that which might be found inside the virus code — we have even seen viruses with a CV inside them." says Svajcer

Rootkits
Some malware is more of a threat than others. Top of the Sophos hit-list right now is installation of rootkits, the proliferation of bots and the ever-present threat of spam.

Rootkits are pieces of software designed to hide other processes or files on a system, so the rootkit and malicious code doesn't appear on the process list. The recent furore over...

For more, click here...

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
236 out of 566 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

1 comment

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters