ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Commercial help for open source security package

Joris Evers CNET News.com

Published: 13 Dec 2005 10:00 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

To plug a hole in its intrusion-prevention software, eEye Digital Security may adopt the Clam AntiVirus project and improve the open source software.

eEye's Blink intrusion-prevention product includes system- and application-level firewalls and protects computers against phishing, spyware and exploitation of known vulnerabilities. "Antivirus is the only missing piece," Ross Brown, eEye's chief operating officer, said in an interview with ZDNet UK's sister site CNET News.com.

Blink is used by about 250 organisations worldwide, including the US Army and the Department of Homeland Security, according to Brown. Some want the product to include antivirus support, so eEye is considering its options, including adopting the Clam AntiVirus project. "It seems like a good marriage for us," he said.

If eEye picks the open source technology, it plans to improve the software. Some eEye developers would work on real-time and file-scanning capabilities, Brown said.

Clam AntiVirus has been adopted in commercial products, such as appliances that scan email for viruses. It is also available as a free virus scanner for Windows, under the ClamWin name.

Clam AntiVirus is fast in offering signatures for new threats, often quicker than commercial competitors including Symantec and McAfee, but it lags in detection capabilities, said Andreas Marx, an antivirus-software expert at the University of Magdeburg in Germany and an authority on testing antivirus software.

"The technology used in Clam AntiVirus is far behind," Marx said. However, they are quite successful, because the scanner is free and the source code is available and portable to any platform."

eEye is still plotting its strategy, deciding between using the open source antivirus technology and licensing a commercial antivirus-scanning engine from a company such as CA, Brown said. "We don't want to sign a contract and pay a bunch of money for something that is a commodity," he said.

Additionally, eEye is also developing its own antivirus technology, which will use a behavioural approach instead of the classic, signature-based approach used by Clam AntiVirus and most commercial products, said eEye cofounder and Chief Hacking Officer Marc Maiffret.

"We'll definitely be adding antivirus functionality to Blink," he said. "Most likely there will be the classic antivirus and the nonsignature-based approach."

Signature-based systems check potentially malicious software against a database of known threats while behavioural systems look at a program's behaviour to determine whether or not it is malicious.

Regardless of if it picks the proprietary or open source route, eEye sees its move as a way to plug a hole in its software, not as a way to push into a new market. "I don't want to get into the antivirus-signature business. Protecting customers from viruses is definitely what we want to do, but it in a smarter, more comprehensive method," said Brown.

Marx recommends against adopting Clam AntiVirus. "I like eEye's products, but adding Clam AntiVirus would be a very bad idea in my eyes. Mixing good software with bad software will create bad software."

That's why eEye wants to improve the Clam AntiVirus product before they adopt it, said eEye's Brown.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
109 out of 223 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Related Jobs

Classic ASP / ASP.NET Develeper. North London. 30,000 - 40,000

Classic ASP with ASP.NET skills developer needed. You will have extensive experience of development in a commercial environment. North London. My ...

Asp web developer needed to migrate to .Net- London

You should have a solid commercial development background in asp and ideally have experience migrating classic over to .net. I am currently working ...

C# Web Developer, Warwickshire, 30-35k + Benefits

You will need to have at strong commercial experience of ASP.Net (preferably C#) and a background with classic ASP, SQL Server and HTML. The ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

2 comments