Virus Makers Gain the Upper Hand Through Ultra-Fast Propagation      
Written by zhangyuan   
February 21, 2008 14:02
The premier global market intelligence and advisory firm in the information technology and telecommunications industries, International Data Corporation (IDC) has published a new White Paper titled "Zero-Hour Virus Protection: Defending Against the Unknown" (August 2005), which investigates a persistent problem in the anti-virus (AV) industry -- how to provide immediate protection from emerging outbreaks, in the hours before signatures are available.

The study reviews Malware trends, and evaluates the capacity of various approaches to provide reliable protection: the classic signature-based approach, proactive approach (heuristics and sandboxing) and the new Zero-Hour(TM) approach that uses network based outbreak detection for identifying new viruses in real time.

Early-Hour Vulnerability Window: Signature-Based Methods Leave Users Unprotected

The study confirms that although almost all enterprises have AV solutions in place, none are entirely safe from viruses. According to IDC, the vast majority of large companies are still suffering from virus, Trojan and worm attacks that infiltrate their network defenses.

"The growing effectiveness of malware can be explained by its dynamic nature. Malware writers have realized that organizations' reliance on signature-based anti-virus products creates a significant window of vulnerability, and are targeting it in various ways," said Dan Yachin, IDC's Research Director for EMEA Emerging Technologies. "The problem of signature-based AV solutions lies in their reactive nature. Given their lengthy development cycles, signatures developed against new, rapidly propagating attacks cannot prevent mass infection in the first hours. Emerging technologies such as Commtouch's Zero-Hour Virus Protection could have an important role in mitigating those risks."

Commtouch Closes the Early-Hour Vulnerability Gap

Commtouch's Zero-Hour(TM) solution was developed using the Recurrent Pattern Detection(TM) (RPD) platform, which is integrated by about 30 leading providers of anti-spam and anti-virus software, firewall and email security appliances, and managed service providers.

The Zero-Hour solution analyzes massive amounts of email (SMTP) traffic in real-time, using data collected at different key points over the Internet to achieve a representative sample of worldwide traffic. In a fully automated process, it analyzes patterns of malware outbreaks, to identify new outbreaks as soon as they are distributed (usually long before their first instances reach the protected organization). Unlike most proactive AV technologies, Commtouch Zero-Hour is a high-performance engine with extremely low CPU requirements.

"Aimed at detecting mass outbreak indicators, Zero-Hour is differentiated from other proactive virus detection technologies by several advantages. First and foremost is the immediate and accurate detection of new outbreaks" stated Yachin. "In a 6-month trial in a live ISP environment, this solution demonstrated signature-independent, new virus detection and blocking of well over 90%. This performance is especially impressive considering that common proactive solutions such as heuristic-based ones hardly exceed the 30% mark."

"With viruses increasingly targeting the early hour window of vulnerability, no security vendor can afford to rely solely on signatures. We believe we have the solution for AV vendors as well as AV integrators," said Oren Drori, director of product marketing at Commtouch.

About Commtouch

Commtouch Software Ltd. (Nasdaq:CTCH) is dedicated to protecting and preserving the integrity of the world's most important communications tool -- email. Commtouch has 14 years of experience developing messaging software, and is a global developer and provider of proprietary anti-spam and Zero-Hour(TM) virus protection solutions. Using core technologies including RPD(TM)-Recurrent Pattern Detection, the Commtouch Detection Center analyzes 1.5 billion email messages per month to identify new spam and malware outbreaks within minutes of their introduction into the Internet. Integrated by about 30 OEM partners, Commtouch technology protects thousands of organizations, with tens of millions of users in 100 countries. Commtouch is headquartered in Netanya, Israel and has a subsidiary in Mountain View, CA.

This press release contains forward-looking statements, including projections about our business, within the meaning of Section 27A of the Securities Act of 1933 and Section 21E of the Securities Exchange Act of 1934. For example, statements in the future tense, and statements including words such as "expect," "plan," "estimate," anticipate," or "believe" are forward-looking statements. These statements are based on information available to us at the time of the release; we assume no obligation to update any of them. The statements in this release are not guarantees of future performance and actual results could differ materially from our current expectations as a result of numerous factors, including business conditions and growth or deterioration in the Internet market, commerce and the general economy, both domestic as well as international; fewer than expected new-partner relationships; fewer than expected license agreements resulting from Commtouch's exclusive rights to market DCC; competitive factors including pricing pressures; technological developments, and products offered by competitors; the ability of our OEM partners to successfully penetrate markets with products integrated with Commtouch technology; a slower than expected acceptance rate for real time AV solutions in general and the Commtouch Zero Hour(TM) Virus Protection product in particular; availability of qualified staff for expansion; technological difficulties and resource constraints encountered in developing new products, such as the Zero Hour solution; and the failure of Commtouch to meet The NASDAQ SmallCap Market's listing standards in the future; as well as those risks described in the text of this press release and the company's Annual Reports on Form 20-F and reports on Form 6-K.

Tags: Spyware Doctor, Spyware Removers, downloads, software, trial, free, free Spyware Doctor download, computer doctor, secure pc, spyware protection

German : Virus Entscheidungsträger die Oberhand gewinnen durch ultra-schnelle Vermehrung
French : Virus décideurs prennent l'avantage par ultra-rapide propagation
Japanese : ウイルスメーカーの利得は、上部の手による超高速伝搬