<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
>

<channel>
	<title>The Security Catalyst<title>&#187; anti-virus</title>
</title>
	<atom:link href="http://www.securitycatalyst.com/tag/anti-virus/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securitycatalyst.com</link>
	<description>Michael Santarcangelo delivers Awareness that Works™</description>
	<lastBuildDate>Wed, 01 Sep 2010 14:21:48 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
<!-- podcast_generator="Blubrry PowerPress/1.0.9" mode="advanced" entry="normal" -->
	<itunes:summary>Michael J. Santarcangelo, II is a human catalyst. An expert who speaks on information protection â including compliance, privacy and awareness â Michael energizes and inspires his audiences to change the way they protect information. His passion and approach gets results that change behaviors. 

As the voice of optimism in an industry of doomsayers, Michael has recently completed his first book, Into the Breach (www.intothebreach.com), which provides the wisdom and answers executives need to defend their organization against breaches while discovering how to increase revenue, protect the bottom line and efficiently manage people, information and risk.

In this podcast series, Michael shares ideas, research and strategies for your success. 
</itunes:summary>
	<itunes:author>Michael Santarcangelo | The Security Catalyst</itunes:author>
	<itunes:explicit>clean</itunes:explicit>
	<itunes:image href="http://www.securitycatalyst.com/tsc_icon.png" />
	<itunes:owner>
		<itunes:name>Michael Santarcangelo | The Security Catalyst</itunes:name>
		<itunes:email>michael@securitycatalyst.com</itunes:email>
	</itunes:owner>
	<managingEditor>michael@securitycatalyst.com (Michael Santarcangelo | The Security Catalyst)</managingEditor>
	<copyright>Copyright 2009 The Security Catalyst. All Rights Reserved. </copyright>
	<itunes:subtitle>A catalyst for engaging, empowering and enabling individuals; turn insiders into allies who reduce business risk!</itunes:subtitle>
	<itunes:keywords>security, risk, privacy, compliance, breach, awareness, training, catalyst, confidentiality, integrity, availability, cissp, cism, cisa, cpp</itunes:keywords>
	<image>
		<title>The Security Catalyst&lt;title&gt;&#187; anti-virus&lt;/title&gt;
</title>
		<url>http://www.securitycatalyst.com/wp-content/plugins/powerpress/rss_default.jpg</url>
		<link>http://www.securitycatalyst.com</link>
	</image>
	<itunes:category text="Business">
		<itunes:category text="Management &amp; Marketing" />
	</itunes:category>
	<itunes:category text="Technology" />
	<itunes:category text="Education" />
		<item>
		<title>When Burning Buildings Become Blasé</title>
		<link>http://www.securitycatalyst.com/when-burning-buildings-become-blase/</link>
		<comments>http://www.securitycatalyst.com/when-burning-buildings-become-blase/#comments</comments>
		<pubDate>Thu, 04 Dec 2008 21:39:51 +0000</pubDate>
		<dc:creator>Michael Starks</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[anti-virus]]></category>
		<category><![CDATA[virus]]></category>

		<guid isPermaLink="false">http://www.securitycatalyst.com/blog/?p=599</guid>
		<description><![CDATA[by Michael Starks Imagine if a building on every street started on fire every day.  They are small fires, which cause relatively little damage, and are usually quickly extinguished by the sprinkler system.  Every once in awhile, the entire house burns down because the sprinkler system hasn&#8217;t been updated in over a year.  Now imagine [...]


No related posts.]]></description>
			<content:encoded><![CDATA[<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwhen-burning-buildings-become-blase%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwhen-burning-buildings-become-blase%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<p><!--StartFragment--></p>
<p class="MsoNormal"><strong><a href="http://www.securitycatalyst.com/wp-content/uploads/2008/12/fire.jpg"><img class="alignleft size-full wp-image-971" title="fire" src="http://www.securitycatalyst.com/wp-content/uploads/2008/12/fire.jpg" alt="fire" width="150" height="150" /></a>by Michael Starks</strong></p>
<p class="MsoNormal">Imagine if a building on every street started on fire every day.<span>  </span>They are small fires, which cause relatively little damage, and are usually quickly extinguished by the sprinkler system.<span>  </span>Every once in awhile, the entire house burns down because the sprinkler system hasn&#8217;t been updated in over a year.<span>  </span>Now imagine that people have come to believe that this is normal and expected, that as long as you keep your sprinkler system updated, you should be OK. And if the sprinkler system does its job, the fires aren&#8217;t a problem.</p>
<p class="MsoNormal">While analogies are never perfect, this is the basic situation we have today with viruses and anti-virus software.<span>  </span>Billions of dollars are spent in defending against viruses, with software ranging from simple desktop scanners to multi-tired, enterprise class anti-virus defense ecosystems.<span>  </span>When they catch viruses and other forms of malware, we judge them to be successful.<span>  </span>We run reports with nice graphs to show management, and as long as the viruses are being caught, we feel our information is safe.</p>
<p class="MsoNormal">While few dispute that anti-virus software is a necessity in a modern computing environment (particularly, one which contains Microsoft Windows), fewer still frame anti-virus in the proper context.<span>  </span>How many look at the number of viruses caught, juxtapose them with the effectiveness of the software in catching viruses, and make a plan to reduce the number of viruses detected?<span>  </span>In other words, how many ensure the anti-virus software is working as intended, then work to reduce the infection rate?</p>
<p class="MsoNormal">Viruses and other malware are not simple problems to solve, but there are solutions to reducing the number of infections that do not depend on the use of anti-virus software.<span>  </span>Among them:</p>
<p class="MsoNormal">-Reducing the rights a user has to run and install software.<span>  </span>Do your users run with Administrator rights by default?<span>  </span>Why?<span>  </span>If they&#8217;re not changing network settings, installing software and looking at logs on a regular basis, most people don&#8217;t need these rights as a part of their normal job.</p>
<p class="MsoNormal">-Educating users about safe computing.<span>  </span>When a virus is detected, do you interview the user in an attempt to determine how the infection occurred?<span>  </span>Viruses, at least for now, are not spontaneous phenomena.<span>  </span>Something happens for that infection to take root.<span>  </span>Usually, unsafe computing behavior is involved.</p>
<p class="MsoNormal">-Educating users about appropriate use.<span>  </span>Are your users installing personal software or games (see #1), connecting to untrusted networks or surfing to personal web sites?<span>  </span>To what extent are you willing to allow for these activities versus the cost of increased virus rates?</p>
<p class="MsoNormal">-Examining the choke points for data entering the network.<span>  </span>While the perimeter is becoming increasingly porous, looking at data flow is critical in determining how infections occur.<span>  </span>Do most occur from drive-by downloads, or are they due to e-mail attachments?<span>  </span>By looking at data flow, protections can be put into place to reduce the chance of viruses entering the network.</p>
<p class="MsoNormal">Notice that all of the points mentioned involve process, education and analysis.<span>  </span>None of them involve spending more money on more defense technology.<span>  </span>While that may at times be the natural outcome of the process, it should not be the first reaction.</p>
<p class="MsoNormal">Anti-virus software isn&#8217;t perfect; in fact, the ability for anti-virus software to detect modern malicious code has been declining in recent years.<span>  </span>While still needed, we need to look our perception of its role in protecting information. Is it our first and only line of defense or is it an alarm that something else has failed?<span>  </span>By shifting our thinking to the root causes of infections, and by focusing on solutions to those problems, we can reframe anti-virus software as primarily IDS, rather than IPS.<span>  </span>We can set goals for increasing the effectiveness of preventing malicious code, while simultaneously reducing the number of detections found.<span>  </span></p>
<p class="MsoNormal">Virus infections are an anomaly that we have been trained to accept as normal.<span>  </span>By shifting our thinking towards anti-virus as a rarely activated sprinkler system, we&#8217;ll go a lot further towards keeping our information safe.</p>
<p class="MsoNormal"><!--StartFragment--><span><em>Michael is an Information Security Professional specializing in host-based security, IDS, log analysis and compliance. He believes in applying basic security principles to an ever-changing threat landscape, and is currently exploring the various ways in which human behavior affect the success of security programs.  He is a founding member of the Rochester, NY chapter of ISSA and has served for both ISSA and OWASP. He currently holds the CISSP, GSNA and A+ certifications.  In his spare time, Michael enjoys spending time with his wife and daughter, and listening to early twentieth-century blues.</em></span><!--EndFragment--><em>  </em></p>
<p><!--EndFragment-->
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwhen-burning-buildings-become-blase%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.securitycatalyst.com%2Fwhen-burning-buildings-become-blase%2F&amp;source=catalyst&amp;style=normal&amp;service=bit.ly" height="61" width="50" /><br />
			</a>
		</div>
<div id="facebook_like"><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.securitycatalyst.com%2Fwhen-burning-buildings-become-blase%2F&amp;layout=standard&amp;show_faces=true&amp;width=450&amp;action=like&amp;colorscheme=light&amp;height=80" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:450px; height:80px;" allowTransparency="true"></iframe></div>

<p>No related posts.</p>]]></content:encoded>
			<wfw:commentRss>http://www.securitycatalyst.com/when-burning-buildings-become-blase/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
