Home Portal Blog Links
Go Back   Military Forum > Military News and Politics: Sound Off > The Ready Room > Technology and Computers

Technology and Computers Technology, Computers, Webdesign, and more!

Reply
 
LinkBack Thread Tools Display Modes
Old 04-29-2006, 10:17 AM   #1 (permalink)
Marine
MSgt USMC Ret

 
USMCRET6391's Avatar
 
Group:
Lieutenant General

USMCRET6391Marine is USMCRET6391 isimli üyemiz çevrimdışıdır. (Offline)
AKA: Top
Join Date: Aug 2004
Location: San Diego
Posts: 9,545
Threads: 3537
UserID: 69
User Info
United_States  marine_corps  male  taurus  

My current mood: Happy
Reputation +/-Power: 16
Points: 276
USMCRET6391 is a jewel in the roughUSMCRET6391 is a jewel in the roughUSMCRET6391 is a jewel in the rough
USMCRET6391Marine is USMCRET6391 isimli üyemiz çevrimdışıdır. (Offline)  

Security tool aims to stop drive-by installs

By Joris Evers
Staff Writer, CNET News.com
Published: April 28, 2006, 4:07 PM PDT

Veterans of antispyware specialist PestPatrol have developed a new tool that throws up roadblocks for so-called drive-by installs of malicious code onto vulnerable PCs.

The tool, called SocketShield, monitors Internet traffic as it enters a PC and takes action based on a blacklist of known bad Web sites and vulnerability signatures, Roger Thompson, chief technology officer at Exploit Prevention Labs, said in an interview Friday. "Before you can open a poisoned page and get infected, we can stop it," he said.

Exploit Prevention Labs is a new company, founded by Thompson and Bob Bales, two former executives at PestPatrol, an early antispyware company that CA (formerly Computer Associates International) bought two years ago.

SocketShield is aimed at shielding Windows users against what's known as drive-by installs, the surreptitious installation of malicious software as people surf the Web. Cybercrooks often exploit security holes in Windows, Web browsers and other applications in order to drop spyware, adware, Trojan horses, bots and other software onto the computers of unwitting people. Recent examples include the Windows Meta File flaw and the CreateTextRange bug.

The new tool can provide protection in the time between the publication of a security flaw and the release of a patch by the maker of the flawed software, said Michael Cherry, an analyst at Directions on Microsoft.

"It will always take Microsoft and other software vendors time to patch vulnerabilities," he said. "Having the ability to protect systems while waiting for a patch from the software vendor or while waiting to get the patch distributed would be valuable."

The SocketShield client software is updated continuously with information on known bad Web sites and vulnerability signatures. The vulnerability signature approach is similar to antivirus software; SocketShield checks potentially malicious Web sites against a database of known security exploits.

SocketShield is designed to work alongside other security applications such as antivirus, antispyware and firewall software, Thompson said. "We are providing something they are not," he said. "We're another layer of protection and have done a huge amount of work to make sure we're compatible."

While SocketShield may look a lot like standard intrusion prevention software, it is not, Thompson said. Instead, it is task-focused security software, he said. "Intrusion prevention software tries to be all things to all people and detect things generically so you don't have to patch," he said. "I reckon that is wrong-headed."

A trial, or beta, version of SocketShield for Windows XP, Windows 2000 and Windows 2003 is available at no cost. Exploit Prevention Labs plans to launch a first official version of the tool in early June. That version will cost $29.95 per year. Volume discounts are available. The company also plans to license its technology to third parties.

If you'd like to try it, download it here

-Top
USMCRET6391 isimli üyemiz çevrimdışıdır. (Offline)  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote

Sponsored Links

» Support the Site!

Military Gear - Military Ltd Gear - Infantrymen Gear - Ranger Gear - Single Servicemen
Reply

Tags
aims, driveby, installs, security, stop, tool



Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



New To The Site? Need Information?

 

Powered by vBulletin® Version 3.8.0 Alpha 2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd., SEO by vBSEO 3.1.0
Designed by MilitaryDesign.Com
MilitaryLtd.com, GoInfantry.Com, Infantrymen.Net, Infantrymen's Military Forum are © 2000-2008 MilitaryLtd.Com. All Rights Reserved.
Any copying, redistribution or retransmission of any of the contents or images without express written consent is expressly prohibited.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253