Worm.com

Guide to Spyware and AntiVirus Information

You are currently browsing the Worm.com weblog archives for the day Thursday, January 25th, 2007.

 

January 2007
M T W T F S S
« Dec   Feb »
1234567
891011121314
15161718192021
22232425262728
293031  

Sponsors

Archive for January 25th, 2007

CHARLOTTE, N.C. — Calyptix Security has successfully protected its customers from a new email virus widely known as the Storm Trojan, without reliance on static signatures.

Calyptix Security utilizes DyVax, the company’s patent-pending signature-less inspection engine, exclusively packaged with Calyptix Security’s AccessEnforcer brand product line. Using the most recent version of its DyVax software, version 1.3, released on January 9, 2007, Calyptix Security was immediately able to identify and quarantine all variants of the virus so that no damage could be done to the user’s workstation or the larger network.

Trend Micro reports capturing variants of the Storm Trojan as early as January 17, 2007. Initial signature solutions were first made available by leading anti-virus vendors beginning January 18, 2007. Subsequently, those vendors have continued to update their signatures upon discovery of new variants. Some customers of leading anti-virus vendors did not receive updated signatures until as late as January 22, 2007.

Conversely, Calyptix Security’s customers were protected well before the first variant of the Trojan was discovered without any need for signature updates.

The rapid rate at which the Storm Trojan swept across the world has demonstrated the significant challenges facing the security industry’s long standing reactionary approach and reliance on developing static signatures after the discovery of new threats.

Variants of the Storm Trojan provide subject lines with alarming announcements or "greeting card" messages to entice recipients into opening the message to activate the Trojan. The Trojan then compromises the host by installing a program onto the user’s computer which it retrieves from websites under the control of the author of the malware. Once compromised, these computers can be used to generate spam and other malicious traffic. Variants of the Trojan captured by Calyptix Security’s customers have used numerous provocative subjects including:

* My Eye on You

* First Nuclear Act of Terrorism!

* Happy World Religion Day!

* Russian Missile shot down USA Satellite

* Saddam Hussein safe and sound!

* The commander of a U.S. nuclear submarine lunch [sic] the rocket by mistake

Calyptix Security has ranked the Storm Trojan as having high damage and distribution potential and anticipates a resulting surge in spam and other malicious traffic. Aliases of this virus include TROJ_SMALL.EDW (Trend Micro), Trojan.Peacomm (Symantec), Downloader-BAI (McAfee), CME-711 (Common Malware Enumeration), and Small.DAM (F-Secure).

DyVax was developed and refined by Dr. Yuliang Zheng, a leading international authority in cryptography and network security, and Dr. Lawrence Teo, a widely published expert in Internet security and open source technology. DyVax was created as a cornerstone for building a scalable, world-wide Internet Defense Force. In laboratory testing, DyVax has proven more successful than the leading commercial and open source anti-virus solutions.

For additional information on how DyVax achieves zero-day threat protection, please visit http://www.calyptix.com/dyvax.

About Calyptix Security Corporation

Founded in 2002, Calyptix Security Corporation is a developer of Unified Threat Management (UTM) security solutions for the needs of small and medium size businesses. Calyptix Security has rapidly commercialized its premier product line, AccessEnforcer, an all-in-one appliance that deploys DyVax, the company’s proprietary algorithm and inspection engine to dynamically filter network traffic from true zero-day threats without reliance on signatures. Calyptix Security is headquartered in Charlotte, NC. For more information, please visit the Calyptix Security website at www.calyptix.com or call 704.971.8989.

COPYRIGHT 2007 Business Wire
COPYRIGHT 2008 Gale, Cengage Learning

Information provided by: Findarticles.com

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • TwitThis

CORE NEWS FACTS

--  On Friday, January 19, 2007, spammers unleashed a malicious program,
    dubbed "Storm," which has infected hundreds of thousands of PCs worldwide.
--  The outbreak contained imitation news subject lines such as "Saddam
    Hussein Alive" and "Chinese missile shot down USA aircraft." It prompted
    users to open a virus infected file for more details on the news. Once
    installed, the virus opens a backdoor that remote hackers can use to take
    over the computer. Hackers can use these infected PCs to send spam, host
    spyware, and install key loggers and screen scrapers.
--  The "Storm" worm is the largest outbreak in the last twelve months.
--  IronPort Virus Outbreak Filters™ stopped over 300,000 viral messages,
    prior to traditional anti-virus signature availability, saving IronPort®
    customers over $15.4M in associated IT costs in less than four hours.
    

QUOTES

David Mayer, Product Manager, IronPort:

--  "It is precisely because of virus outbreaks like this that customers
    choose IronPort to protect them.  In fact, over 70 percent of our customers
    today consider IronPort Virus Outbreak Filters (in addition to signature-
    based solutions) a must-have part of their virus defense.  By detecting new
    outbreaks in real time, and dynamically responding to prevent suspicious
    traffic from entering the network, we ensure customer uptime and business
    continuity for hundreds of Fortune 500 companies, ISPs, small- and medium-
    sized companies, and universities worldwide."
    

Brandon Moreno, Senior Exchange Engineer at ACS Application Management
Services, a technology services company:

--  "Without IronPort Virus Outbreak Filters, we would have never been
    able to get a handle on the 'Storm' virus.  As soon as the virus broke,
    IronPort stopped over 2000 infected messages from entering our network.
    Had this outbreak passed through to our corporate users, we would have
    spent an immeasurable amount of time and money in clean-up.  With IronPort
    Virus Outbreak Filters stopping threats before they hit our network, the
    solution easily pays for itself."
    

About IronPort Virus Outbreak Filters

A proven preventive solution, IronPort Virus Outbreak Filters provide a
critical first layer of defense against new outbreaks — hours before
signatures used by traditional anti-virus solutions are in place. Real
world results show an average lead time over reactive anti-virus solutions
of 14 hours, along with an extremely high catch rate and near-zero
misclassifications. Integrated into the IronPort C-Series(TM) email
security appliances, IronPort Virus Outbreak Filters perform a threat
assessment of inbound and outbound messages, and quarantine suspicious
messages temporarily. Messages are automatically released once signatures
from traditional anti-virus vendors are deployed.

About IronPort Systems

IronPort Systems Inc., headquartered in San Bruno, California, is a leading
provider of anti-spam, anti-virus and anti-spyware appliances for
organizations ranging from small businesses to the Global 2000. IronPort
appliances utilize SenderBase®, the world’s largest email and Web threat
detection network and database. IronPort products are innovative and
easy-to-use — providing breakthrough performance and playing a
mission-critical role in a company’s network infrastructure. To learn more
about IronPort Systems products and services, please visit:
http://www.ironport.com/ .

Copyright © 2007 IronPort Systems, Inc. All rights reserved. IronPort,
the IronPort logo and SenderBase are registered trademarks of IronPort
Systems, Inc. All other trademarks are the property of IronPort Systems,
Inc. or their respective owners. While every effort is made to ensure the
information given is accurate, IronPort does not accept liability for any
errors or mistakes which may arise. Specifications and other information in
this document may be subject to change without notice.

Image Available: http://www.marketwire.com/mw/frame_mw?attachid=410353

Contact:
Liz Landis
IronPort Systems
415-828-4801
Email Contact

Margo Livadariu
IronPort systems
415-516-3516
Email Contact

Information provided by: Findarticles.com

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • TwitThis

Antivirus-vendor comparison tests also unveiled

BAKERSFIELD, Calif. — Lightspeed Systems, developer of innovative and integrated security software products for K-12 school networks, today made public its web content, program and virus databases. The searchable "Lightspeed Archive" may be accessed at www.erating.com. Because Lightspeed Systems downloads the entire Internet to its army of servers monthly, the Archive is the largest and most current database of web sites, programs, and viruses that is publicly available on the Internet.

Viruses, spyware, key loggers, Trojans, hacker tools and other threats are listed in the Virus Archive. Details of each threat include the most common alternate names, where and when it was found on the web, and a Google search link to learn more about the virus. The vast database of viruses was systematically collected from web sites, customers, and other antivirus researchers.

In addition, the results of Lightspeed Systems’ antivirus vendor comparison tests may be viewed. As part of Lightspeed Systems’ software quality check, its antivirus solution is compared against other antivirus vendors’ products. Rob McCarthy, Lightspeed Systems CTO, explains, "If Lightspeed Systems is the only antivirus vendor that identifies a given file as virus infected, then we check that file again and again to make sure we are not over blocking good programs or documents." Of course, the tests also reveal what threats Lightspeed found that the other antivirus products did not detect. These antivirus comparison tests are compiled weekly in a chart and displayed along with a full explanation of the test procedure.

As for web sites, the Web Archive shows how each is placed into one of over 100 categories using sophisticated algorithms that analyze content and internal links. With thousands of new sites added every day and all sites re-analyzed during Lightspeed Systems’ monthly Internet download, it is the most current and accurate resource for determining web site content and classification.

Finally, the Program Archive contains information about non-malicious software such as games, file-sharing software, media down-loaders and other categories that network administrators may be interested in controlling. This ever-growing list also includes current software updates and business applications so administrators can be confident that installed software is legitimate.

Joel Heinrichs, Lightspeed Systems CEO, comments, "The Lightspeed Archive is a powerful tool for both TTC customers and non-customers. Such relevant information concerning network security has never been so current, nor so readily available."

About Lightspeed Systems

Lightspeed Systems, Inc. develops network security software to ensure CIPA compliance and provide total traffic control to educational IT professionals through a single interface. TTC is deployed in approximately 600 school districts throughout the U.S. and protects over 4 million end users from the dangers of the Internet. The company has been developing software for over 20 years to provide leading-edge networking software for a worldwide customer base of education and corporate organizations. Lightspeed Systems maintains their corporate headquarters at: 1800 19th Street, Bakersfield, California. Telephone: (661) 716-7600. Web site: http://www.lightspeedsystems.com.

COPYRIGHT 2007 Business Wire
COPYRIGHT 2008 Gale, Cengage Learning

Information provided by: Findarticles.com

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • TwitThis

green.ch, provider of
comprehensive Internet and telephony services to Swiss businesses and
consumers, has deployed the industry’s most accurate anti-spam,
anti-phishing and anti-virus solution. With its subscriber base growing to
exceed 200K mailboxes, the service provider has added Cloudmark Authority™
solutions to its Bizanga IMP edge infrastructure to ensure subscribers
receive complete protection against inbound and outbound messaging threats.

Spam currently accounts for more than 90% of all email worldwide, and
fraudulent phishing attacks that elicit subscribers’ financial information
continue to rise dramatically across Europe. Cloudmark estimates the
attacks on European banking brands alone increased almost 300% within a
span of several months in 2006. (See “As Predicted, Cloudmark Sees Dramatic
Rise in Phishing Attacks on European Banks,” December 18, 2006.) To combat
these threats that jeopardize subscriber privacy, green.ch has decided to
further enhance its Bizanga edge messaging security solution by deploying
Cloudmark Authority. Cloudmark Authority is able to stop highly targeted
and transient phishing attacks much more quickly than traditional
solutions. Unlike traditional solutions that rely on static rules or
volume pattern recognition techniques, Cloudmark uses intelligent message
fingerprinting and real time updates from the world’s largest threat
detection network to identify existing and emerging spam, phishing, and
viruses.

After evaluating Cloudmark’s performance in rigorous trials, the service
provider elected to roll out the Authority solution and quickly realized
both higher filtering accuracy and resource savings. Beni Frei, CTO at
green.ch, says, “After implementing Cloudmark, we noticed a significant
reduction in abusive messages impacting our subscribers and mail
infrastructure. We’re impressed both by Cloudmark’s accuracy and the
inherent resource efficiency of their solution.”

Facing a massive service problem from targeted attacks on its e-mail
infrastructure, green.ch had previously installed Bizanga IMP clusters to
secure and manage its inbound and outbound e-mail traffic. “Bizanga has
provided us with the tool to continue our leadership in e-mail services to
the Swiss market,” Beni Frei notes. Because of this initial deployment,
green.ch lowered its total cost of ownership (TCO), boosted its service
uptime and received a positive return on investment (ROI) in less than a
year. The installed Bizanga infrastructure made it possible to deploy
Cloudmark within minutes, immediately enhancing green.ch’s services to its
customers.

Bizanga’s unique flexibility and scalability allowed green.ch to instantly
add Cloudmark and other best-of-breed messaging applications without
changing its messaging architecture. VP Sales EMEA of Bizanga, Serge Dugas,
says, “The speed and efficiency of the test and roll-out prove that
green.ch can provide immediate solutions to any of its messaging problems
using its Bizanga installation. By further using the workflow policies of
the IMP, green.ch has the flexibility to react to any requirements posed by
its customers and the market.”

Cloudmark VP of Sales EMEA Paul Averill says green.ch’s commitment to
providing maximum privacy and security to their subscribers presents a
strong competitive advantage. “green.ch continues to rapidly attract new
customers and keep existing customers loyal by offering enhanced mail
services,” says Averill. “With the current volume of spam representing a
major annoyance, and phishing posing real financial threats, green.ch is
taking the lead among Swiss providers in protecting its customer base.”

About Cloudmark Authority™

Repeatedly proven in service provider trials as the industry’s most
accurate and efficient messaging anti-abuse solution, Cloudmark Authority
uniquely leverages intelligent message fingerprinting and the world’s
largest threat detection network to block spam, phishing, viruses, and
mutated threats significantly faster than rules or heuristics-based legacy
solutions. Where legacy solutions may require witnessing a sufficient
volume of abuse to begin blocking, Authority can act as soon as a threat,
even a highly targeted phishing attack, has been identified by and
corroborated by the Cloudmark Global Threat Network and Trust Evaluation
System. Once an abusive message has been fingerprinted, any mutation of
this threat will be blocked in real time. This early detection is critical
in stopping polymorphic and advanced virus attacks from causing widespread
damage.

In addition, Authority was architected for service provider environments
that demand efficient processing of large volumes of messages. Unlike
traditional solutions that use processing-intensive rule sets, Authority
performs scanning of messages for all forms of abuse using an in-memory
cache of verified fingerprints that is updated every minute. Cloudmark’s
approach enables wire-speed processing while only utilizing one-tenth of
the system resources of traditional rules-based solutions while combining
anti-spam, anti-phishing and anti-virus protection on a single platform to
maximize efficiency.

Information provided by: Findarticles.com

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • TwitThis

SAN FRANCISCO and SAN MATEO, California, January 25 /PRNewswire/ —

green.ch, provider of comprehensive Internet and telephony services to Swiss businesses and consumers, has deployed the industry’s most accurate anti-spam, anti-phishing and anti-virus solution. With its subscriber base growing to exceed 200K mailboxes, the service provider has added Cloudmark Authority(TM) solutions to its Bizanga IMP edge infrastructure to ensure subscribers receive complete protection against inbound and outbound messaging threats.

Spam currently accounts for more than 90% of all email …

Read the rest of this article with a Free Trial at HighBeam Research.

Information provided by: Findarticles.com

Share and Enjoy:
  • Digg
  • Sphinn
  • del.icio.us
  • Facebook
  • Mixx
  • Google
  • Reddit
  • Slashdot
  • Spurl
  • Technorati
  • TwitThis