SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Government >> Registration

Engineer questions security of antivirus software

Engineer questions security of antivirus software

By:  Robert McMillan  On: 23 Nov 2007 For: ComputerWorld Canada Creator

Thierry Zoller, a German based security engineer, is questioning if the software we're using to protect ourselves from online attacks is becoming a liability. For the past two years, Zoller, a security engineer for n.runs AG, has taken a close look at the way antivirus software inspects e-mail traffic.

Thierry Zoller, a German based security engineer, is questioning if the software we're using to protect ourselves from online attacks is becoming a liability. For the past two years, Zoller, a security engineer for n.runs AG, has taken a close look at the way antivirus software inspects e-mail traffic, and he thinks companies that try to improve security by checking data with more than one antivirus engine may actually be making things worse.

Why? Because bugs in the "parser" software used to examine different file formats can easily be exploited by attackers, so increasing your use of antivirus software increases the chances that you could be successfully attacked.

Antivirus software must open and inspect data in hundreds, if not thousands, of file formats. One bug in the software that does this can lead to a serious security breach.

Zoller and his colleague Sergio Alvarez have been looking into this issue for the past two years and they've found more than 80 parser bugs in antivirus software, most of which have not yet been patched.

The flaws they've found affect every major antivirus vendor, and many of them could allow attackers to run unauthorized code on a victim's system, Zoller said.

"People think that putting one AV engine after another is somehow defense in depth. They think that if one engine doesn't catch the worm, the other will catch it," he said. "You haven't decreased your attack surface; you've increased it, because every AV engine has bugs."

Although attackers have exploited parsing bugs in browsers for years now, with some success, Zoller believes that because antivirus software runs everywhere, and often with greater administrative rights than the browser, these flaws could lead to even greater problems in the future.

The bottom line, he says, is that Antivirus software is broken. "One e-mail and boom, you're gone," he said.

Research into parsing bugs has been spurred by a heightened focus in recent years on "fuzzing" software, which is used by researchers to flood software with a barrage of invalid data in order to see if the product can be made to crash. This is often the first step toward discovering a way of running unauthorized software on a victim's machine.

A parsing bug in the way the Safari browser processed .tiff graphic files was used recently to circumvent Apple's strict controls over what software may be installed on the iPhone.

Zoller says he has been criticized by his peers in the security industry for "questioning the very glue that holds IT security all together," but he believes that by bringing this issue to the forefront, the industry will be forced to address a very real security problem.

Between 2002 and 2005, nearly half of the vulnerabilities that were discovered in antivirus software were remotely exploitable, meaning that attackers could launch their attacks from anywhere on the Internet. Nowadays, that percentage is close to 80 percent, he said.

Zoller's company sees a business opportunity here. N.runs, based in Oberursel, Germany, is building a product, code-named ParsingSafe, that will help protect antivirus software from the kind of parsing attacks that he has documented.

Russ Cooper, a senior scientist with Verizon Business, had some criticism for the work of n.runs. "The research almost appears to be goading criminals into 'getting better' at attacking vulnerabilities ... hardly helpful," he said via instant message. "There's no doubt that the list of vulnerabilities they have already published in security products looks daunting. However, historically, we have not seen this type of vulnerability exploited."

Though Cooper agrees that antivirus file parsing vulnerabilities do pose a risk, he said there are several reasons they have not yet been the focus of widespread criminal attacks. For one, criminals are already being effective enough with their current tactics, such as sending malicious e-mail attachments. A second reason is that security software tends to get more scrutiny, meaning that any vulnerability that was being exploited would be quickly patched, and that any criminal involved in an exploit would be more likely to be caught.

Security vendors have long known about vulnerabilities in their software, said Marc Maiffret, chief technology officer with eEye digital security. "Security software is just as vulnerable as any other software," he said via instant message. "We all hire the same developers that went to the same colleges as Microsoft and learned the same bad habits."

Related content:

Cyberterrorism threat to public sector IT

Government overconfident on security, says analyst

Embedded security


Sign up for our Newsletters












Print |  Views: 333   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Robert McMillan Robert McMillan is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Inside the black market 'bug trade'
Inside the black market 'bug trade'We’ve all heard about the war on drugs, but what about the war on software vulnerabilities? David Rice, author of Geekonomics: The Real Cost of Insecure Software, explains
Zero-day attack tops list of IT concerns
Zero-day attack tops list of IT concernsEnterprise companies say they lack the resources to proactively defend against an emerging breed of exploit, based on a recent survey. Experts offer tips on how to tackle the beast
Security's new reality
Security's new realityIn its annual review of the worst security problems this year, the SANS Institute cited zero-day (software flaw that has no patch) attacks and human gullibility in falling victim to phishing scams or other social engineering tricks as among the most dismal trends of 2006.
More efficient Norton AntiVirus for PC gamers only?
symantec corp. has announced a new version of norton antivirus software, specifically geared towards pc gamers. the selling point for norton antivirus 2009 gaming edition is that i
blog comments powered by Disqus