Norton 2010 to tackle polymorphism

Technology

The 2010 versions of Symantec's Norton consumer security products have been designed to tackle a technique that's been used to get malware onto large numbers of computers.

A piece of malware known as Clampi or Clomp (among other names) is doing the rounds at present. As many as one million Windows-based PCs are thought to be infected.

This should be particularly worrying for users as it grabs credentials for online banks and other money-related sites such as casinos.

One of the sneaky things about Clampi is that it ensures that identical files aren't delivered to all computers. According to PC Tools' ThreatFire Research team, three-quarters of all Clampi executables are unique.

Such polymorphism makes it difficult to perform signature-based detection of Clampi. It can sometimes be spotted indirectly by recognising the packer used in any particular example, and behavioural detection can also be successful.

For example, Sophos detects the way Clampi injects code into Internet Explorer, and recognises the PsExec utility (installed by Clampi, but which also has legitimate uses) as a potentially unwanted application.

But a feature that's new to the forthcoming Norton 2010 products should be able to stop such polymorphic attacks before the code is installed.

Symantec is introducing reputation to the fight against malware. The basic idea is that if you are one of the first few people among the company's millions of users to run a particular application, then unless you are a software developer there's a good chance that it is polymorphic malware. So when Norton 2010 sees a very rarely detected application trying to run, it will suggest that at the very least you delay the operation until more information is available.



SPONSORED PRESS RELEASES

Websense Security Labs Reports ‘User Trust’ Targeted Attacks; Over 1 in 10 ‘Top Search’ Results Categorised as Malware; Increased Focus on Web 2.0
Websense, Inc. today revealed the findings from its bi-annual research report: Websense Security Labs, State of Internet Security, Q3-Q4 2009.

Featured IT jobs

A varied DBA role that involves multitasking in a dynamic software development environment dealing with challenging customer needs on a daily basis.
Skills Tags:   Linux  Oracle  UAT
A position has just become available for experienced Program/Project Manager to join a large organisation on a major Data Centre upgrade....
Skills Tags:   SAP
URGENT! Experienced BDM needed for senior sales role in Melbourne - must have ITSM consultancy sales experience.
Skills Tags:   C  Development  EDI  IT
CRITICAL INCIDENT COORDINATOR - 24 x 7 shifts - 3 month CONTRACT ONLY...
Skills Tags:   Excel  IT  ITIL  Management  Reporting

Editors Picks

Stories you may have missed 

What iTWire offers for free

E - mail News SMS Headlines Desktop Alerts News Feeds Job Alerts Technology Events Press-Releases