|
Analysts argue that virus alerts lack standards
By Dan Verton (IDG) -- The "Klez.E" worm, a new variant of a well-known threat, reared its ugly head last week -- and fizzled. But that didn't stop the antivirus vendor community from pelting users with a series of dire warnings and alerts that offered no consensus on the real threat (see story). As a result, users, analysts and even executives in the antivirus industry said it's high time that a standard reporting and risk rating procedure is established. In an open letter to the Anti-Virus Information Exchange Network, Kenneth Bechtel, founder and anti-virus researcher with Team Anti-Virus, urged the antivirus vendor community to provide a more accurate description of their alert levels. "While we recognize there is no possibility of having a unified threat scale developed overnight, we would greatly appreciate if you could add a short text description to your alert levels," wrote Bechtel. "Trying to figure out if level 2 is a great danger or low danger can be confusing if you only have the e-mail to go on."
"I disregard [the vendor] classification schemes," said Keith Morgan, chief of information security at Terradon Communications Group LLC, a Nitro, West Virginia-based content management company. "I go by what I see in the wild." The lack of consensus and standard threat-rating procedures for virus outbreaks was highlighted last week, when six of the major antivirus vendors issued six different threat levels for the Klez.E worm. All six vendors that issued warnings acknowledged the need for a standard warning system. "It's very difficult to come up with a single reporting mechanism," said Joe Hartman, director of North American antivirus research at Cupertino, California-based Trend Micro Inc. "It really depends on where your customer base is. It would benefit all of us if we could agree on one way." "Our [ratings] are customer-centric, because that's who we're protecting," said Vincent Gullotta, a vice president at McAfee Anti-Virus Emergency Response Team, a division of Network Associates Inc. "We look at prevalence -- what our customers are reporting to us -- which is 60 percent to 70 percent of a risk assessment." "Most vendors use the same criteria, but every vendor has pockets or areas where their customer base is located," said Steven Sundermeier, a product manager at Central Command Inc. in Medina, Ohio. "Each company has a different view of the world," said Vincent Weafer, senior director of security response at Cupertino-based Symantec Corp. "That's why we try to have ratings based on the virus itself." But Sophos Inc. in Lynnfield, Massachusetts, has abandoned threat ratings altogether, said Chris Wraight, a technology consultant at the company. "Our style is not to hype it and scare clients into buying more antivirus software," said Wraight. "When we issue an alert, we state explicitly how many reports we've had from our customer base." In the end, "you probably want to sign on to multiple security news lists," said Sundermeier. Having multiple alerts will assure a more accurate picture, he explained. "When attempting to put a finger on the real risk of a virus, it is important to review at least three major vendors' Web sites," said analyst David Bass at PricewaterhouseCoopers in New York. "A user or administrator should not jump to conclusions based on information on any one vendor's site." |
|
||||||||||||||||||||||||||||||||
|
RELATED STORIES:
Product: SecurityFocus's ARIS Predictor
October 14, 2001 Concern raised over virus warnings August 1, 2001 Internet worm disguised as security alert July 17, 2001 RELATED IDG.net STORIES:
 Klez.e worm threat appears to be contained
(Computerworld)  Klez.e worm set to trigger tomorrow (Computerworld)  Survey: Virus problem grew in 2001, will grow in future (ITWorld.com)  Antivirus firms warn of file deletions (ITWorld.com)  Are wireless viruses looming? (PCWorld.com)  Multitasking viruses expected (PCWorld.com)  Top 10 viruses for December 2001 (CIO)  Stand by for more nasty Web attacks in 2002 (InfoWorld.com) RELATED SITES:
 Anti-Virus Information Exchange Network
 McAfee.com Corp.  Symantec Corp. Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.
TECHNOLOGY TOP STORIES:
Report: SUVs pose danger to cars New telemarketer tool trumps TeleZapper Terra Lycos logs $2.2B loss AOL to offer song downloads Microsoft seeks fiscal fountain of youth (More) |
||||||||||||||||||||||||||||||||||
| Back to the top |
© 2003 Cable News Network LP, LLLP.
A Time Warner Company. All Rights Reserved. Terms under which this service is provided to you. Read our privacy guidelines. Contact us. |