[__ ____ __] napisal(a):
[Charset ISO-8859-1 unsupported, filtering to ASCII...]
> Dave Dyer wrote:
> > Why do you think it will never happen? I think it's inevitable.  
> > I pay for virus protection; there's real money to be made providing 
> > a better service.
> 
> I don't think you can, by any means, compare your proposition to an 
> antivirus solution. The complexities of protecting a person from 
> protecting their own ignorance, not in a demeaning sense, are so 
> multifaceted. It would literally be impossible to stay on top of every 
> single threat, and to cross-network all that information.

Hm... exploiting this vulnerability is a well-defined form of attack that
can (and probably will) be included in databases uses by IDS'es. I think
that is the key point of the "Norton, Mcafee etc." proposition - to put this
attack into such a database.
The problem for the author of this proposition is that these Norton, Mcafee
etc. products are not - and probably never will be - IDS'es (Intrusion
Detection Systems). They are in fact very simple tools - they search for
known signatures of specific malware (virus/trojan/spyware) files and
connection attempts from/to known "blacklisted" Internet addresses. They can
also block specific ports and/or applications from Internet access,
providing you a firewall functionality (again, this is a very simple
firewall - I'm not sure if it's even stateful, or is it only a simple packet
filter). However, realtime analysis of incoming packets and detection of
possible attack patterns is far beyond their capabilities.
If you want a real IDS, think about spending ten or twenty times the amount
of money you are currently paying for anti-virus protection. Maybe such a
device (since it's almost always a separate piece of hardware, not simply
an application you can install on your computer) will protect you from
similar vulnerabilities instantly from the moment they become known (and -
of course - are included in the database, and "pushed" by the manufacturer
to all devices).
Regards,
   Jaroslaw Rafa
   [EMAIL PROTECTED]
-- 
Spam, wirusy, spyware... masz do6f? Jest alternatywa!
http://www.firefox.pl/   ---   http://www.thunderbird.pl/
Szybciej. #atwiej. Bezpieczniej. Internet tak jak lubisz.
_______________________________________________
VNC-List mailing list
[email protected]
To remove yourself from the list visit:
http://www.realvnc.com/mailman/listinfo/vnc-list

Reply via email to