Mostrando entradas con la etiqueta Malware. Mostrar todas las entradas
Mostrando entradas con la etiqueta Malware. Mostrar todas las entradas

jueves, 21 de junio de 2012

Bromium's Tiny Prisons for Malware

Computer security relies on a simple principle: Keep the bad stuff out. This might mean using clever gear to monitor your network. Or it might take the form of antivirus software that keeps nasty worms from burrowing into a PC. But if heinous code does get through, there’s little to do other than find a place to cry.

A startup called Bromium flips traditional logic on its head—and lets attackers right inside the castle walls. When users run Bromium’s software, which will be available later this year, every time they open an e-mail attachment or a browser tab or another application, it creates a temporary, virtual compartment to house the task. Like a nurse observing a quarantined patient, the software watches the cordoned-off code. If it senses misbehavior—such as malware trying to exploit a security hole in Adobe Reader—it dissolves the compartment before damage can be done to the rest of the computer. “The bad guys will always get in,” says Simon Crosby, the co-founder and chief technology officer at Bromium. “It’s about limiting what they can do.”

Like Crosby, a number of the top executives at Bromium came from XenSource, a big-brained startup that did pioneering work in the software virtualization field now dominated by VMware (VMW). The software maker Citrix Systems (CTXS) bought XenSource for $500 million in 2007. Crosby and his co-founders formed Bromium—a name they say simply sounded cool and wasn’t taken—in 2010 in Sunnyvale, Calif. The startup has raised about $36 million from top-tier investors.

One of them is Intel (INTC). In recent years the chipmaker has started including special security technology in its products. Intel’s hardware-based bodyguards create much stronger barriers against attacks than software and can prevent, say, a malicious application from reading and remembering users’ keystrokes as they enter passwords. Bromium’s software, in essence, manages the functions in these new Intel chips.

David Johnson, an analyst with Forrester Research (FORR), says traditional security measures are “beginning to break down” as attackers grow ever more sophisticated. “New exploits regularly elude traditional antivirus and anti-malware and can be notoriously difficult to eradicate,” he says. “Bromium’s approach is unique because it addresses security by essentially assuming that any [application] is compromised at any time and then limiting the effects of it or the damage a given attack can do.”

It also helps that Bromium is lean. Most PCs contain about 100 million lines of code. Every day, hackers look for vulnerabilities to exploit in that mind-bogglingly large set. Bromium kept its application small to avoid the same problem. “Bromium has about 100,000 lines of code, so it’s much easier to harden and secure that,” says Paul Burns, the president of industry analyst Neovise. Burns calls Bromium’s approach “very innovative” but adds that “we’re going to need a bit more time to see the impact.”

Crosby says Bromium’s solution is practical because it doesn’t require users to be hypervigilant, always worrying about what they click on and downloading security updates. “We’re gullible,” he says. “This is about building computing systems that let humans do what they want to do.”

The bottom line: Bromium has raised $36 million to build security software that makes use of new Intel chip capabilities.


View the original article here

jueves, 2 de junio de 2011

Symantec CEO Says Apple, Google Applications Are Malware Targets

By Aaron Ricadela and Adam Satariano

(Bloomberg) -- Symantec Corp. Chief Executive Officer Enrique Salem said downloadable applications for smartphones and tablets represent a new front in the fight against computer threats.

Applications available from Apple Inc.'s App Store and Google Inc.'s Android Market are vulnerable to attacks by hackers who want information housed on handsets and tablet computers, Salem said in an interview yesterday at Bloomberg's San Francisco office. Apple's store boasts more than 350,000 applications, while Android Market has more than 200,000.

"It's very hard to completely vet everything," Salem said. "It's early in mobile security."

Symantec, the largest maker of security software, may spend as much as $860 million more on acquisitions this year to help it expand in mobile, he said. The company also seeks targets in cloud services, or the delivery of computing over the Internet, and virtualization, software that helps servers run more efficiently, Salem said, reiterating remarks he made May 26.

The company is shifting its focus as demand surges for smartphones, tablets and cloud computing, while businesses and consumers curtail personal computer purchases.

Salem told analysts at the May 26 meeting in New York that Symantec would spend as much as $1.25 billion on acquisitions in the fiscal year that began in April. Included in that total is $390 million Symantec spent on Clearwell Systems, which specializes in electronic legal research.

Symantec, based in Mountain View, California, slid 53 cents, or 2.7 percent, to $19.02 in Nasdaq Stock Market trading yesterday. It had climbed 14 percent this year before today.

For Apple users, the threats don't end with mobile devices. Mac laptops and desktops will increasingly be the target of malware as they gain popularity, Salem said. Symantec's software has long secured PCs running Microsoft's Windows software.

Tom Neumayr, a spokesman for Apple, had no immediate comment. Gina Weakley, a spokeswoman for Google, didn't immediately respond to a request for comment. Apple vets applications before they're sold through its store.

Apple has been trying to combat malicious software targeting Mac users in the past month. The malware, posing as an antivirus program called "MacDefender," tries to trick people in to thinking they have a virus. The scam encourages users to download fake security software.

"Its ultimate goal is to get the user's credit card information which may be used for fraudulent purposes," Apple said in a May 24 message to users about how to avoid and remove the software from their machines.

In the market for cloud computing, Symantec is building programs to help companies' information technology departments safeguard applications from Salesforce.com Inc. and other Web-delivered software, including SuccessFactors Inc. and possibly Workday Inc., according to Salem.

Symantec is also close to delivering software that can scan servers running virtualization software from VMware Inc. and Microsoft Corp. more efficiently, Salem said.

Symantec, in a May 11 report, forecast higher revenue than analysts predicted, buoyed by demand for data-backup software and the effect of a weaker dollar on overseas sales.

With assistance from Emily Chang and Cory Johnson in San Francisco. Ricadela is a reporter for Bloomberg News. Satariano is a reporter for Bloomberg News.


View the original article here