Symantec Tries its hand at SMTP zero day protection

| | Comments (0) | TrackBacks (0)

Protection against the zero day attack has been a buzzword in anti-malware software marketing. Its an important thing to have. You can't run a business while waiting multiple days for virus definitions to be released covering the latest attack.

Symantec Mail Security for SMTP 5.0 is an new email gateway solution that attempts to provide such protection. It combines Brightmail antispam technology with Symantec antivirus and content filtering.

http://www.securitypipeline.com/185303122?CID=rssfeed_pl_scp

One key new feature is zero-day protection against threats, which uses information on emerging exploits gathered from Symantec’s network of more than 3 million e-mail addresses. When a suspicious e-mail arrives at the server, this feature can be configured to automatically strip off and quarantine the attachment until a virus definition is released, or simply delete the message, said Caccia.

Many vendors are attempting to enable zero- day threat protection by adding multiple virus engines in order to maximize detection, but that doesn’t offer the same level of protection as Symantec’s new offering, said Tom MacArthur, principal of Storbase, a solution provider in Waltham, Mass.

“Although you get some incremental benefit from the [former] approach, it’s always better if you can catch viruses early on,” MacArthur said.

Hopefully there will be a bakeoff between this product and those that use multiple engines. It will be interesting to hear more about this approach. I wonder if it is using technology similar to the Real Time Threat Protection Service they just bought when they purchased IMLogic.

Neither approach is going to get 100% of the viruses. They are each vulnerable to targeted attacks. Message Labs on the otherhand uses a heuristic scanner (Skeptic) in addition to three scan engines. Even targeted attacks will have a difficult time penetrating this defense.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: Symantec Tries its hand at SMTP zero day protection.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/158

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on April 18, 2006 10:32 AM.

Did you know... was the previous entry in this blog.

It takes too long to patch is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.23-en