lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <3FFD8005.32443.2AB7D801@localhost>
From: nick at virus-l.demon.co.uk (Nick FitzGerald)
Subject: Show me the Virrii!

"fastfood@...usnet.com.au" <fastfood@...usnet.com.au> wrote:

> >Antivirus Software Turned Upside Down
> >by Jason Coombs (jasonc@...ence.org)
> [...]
> >Restricting the execution of code by a CPU to a 
> >small list of known good programs that the owner of the computer chooses
> >to trust would basically kill the antivirus industry.
> [...]
> 
> Cisco have a new product that does just this - Cisco Security Agent.
> http://www.cisco.com/en/US/products/sw/secursw/ps5057/
> 
> Thoughts, comments?

I have no direct experience with using the product, but from the 
various descriptions in the Cisco white-papers covering these product 
families it seems they use _only_ traditional system hardening and 
behaviour detection, analysis and blocking (or reversing) technologies. 
In fact, in places these papers specifically states things such as:

   Cisco Security Agent does not rely on, or even contain, signatures.

If we accept that Cisco knows how its products work then the Security 
Agent products cannot include whitelisting such as Jason's code, as 
this is still fundamentally signature based.


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ