Skip to Content
The Myths of Security
book

The Myths of Security

by John Viega
June 2009
Beginner
260 pages
5h 40m
English
O'Reilly Media, Inc.
Content preview from The Myths of Security

Chapter 39. What AV Companies Should Be Doing (AV 2.0)

I’ve talked a lot about what’s wrong with traditional AV systems that makes them work so poorly. Now I’m going to share my vision of what security vendors should be doing, which we’ll call AV 2.0 (even though we’re all sick of Whatever 2.0). I’ve been working toward this vision for a bit under three years now, primarily at McAfee. While no AV vendor is all the way there yet, the big ones are starting to move in the right direction.

AV vendors traditionally have kept a big blacklist of bad programs. Instead, AV vendors should keep a master list of programs, and for each one, keep track of whether it’s good, bad, or undetermined (the vendor doesn’t have enough information to say).

There’s not much reason to have big signature files on machines, or even to check traditional signatures. Instead, right before the computer runs a program, the AV software can ask the AV vendor, “Is this program safe to run?”

Now the AV vendors have to become a lot better at detection. To that end, the endpoint AV software should collect information about the programs people put on their machines, such as things like:

  • Where are files installed?

  • Which software vendor “signed” it?

  • What registry keys and other resources do programs use?

  • What other programs do programs install?

  • What things do programs delete?

  • Do programs do anything suspicious, such as keylogging?

This kind of information doesn’t need to be sent for every program. Generally, it should be sent just ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Security Policies and Implementation Issues, 3rd Edition

Security Policies and Implementation Issues, 3rd Edition

Robert Johnson, Chuck Easttom
A Leader's Guide to Cybersecurity

A Leader's Guide to Cybersecurity

Thomas J. Parenty, Jack J. Domet
The Human Factor in AI-Based Decision-Making

The Human Factor in AI-Based Decision-Making

Philip Meissner, Christoph Keding

Publisher Resources

ISBN: 9780596803957Errata Page