Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Anomaly detection is not the best way to prevent virus, worm attacks

Two experts debate the effectiveness of a new security technology.
Face-off By Gil Arbel , Network World , 03/13/2006
  • Share/Email
  • Comment
  • Print
CounterStorm's Gil Arbel

Network behavior anomaly detection does not provide a true security solution against viruses and worms. With the growing sophistication, speed and damage potential of today's virus and worm attacks, companies need a solution that actively defends their networks.


The other side - Arbor Networks' Paul Morville
Forum

The ingredients required to mount a meaningful defense against these new and virulent attacks include speed, accuracy and the ability to actively block attacks from spreading to other machines, systems and networks.

Anomaly detection falls short in these areas and gives users a false sense of security. The approach has three main drawbacks:

  • It is too slow to detect fast-spreading virus and worm attacks. Anomaly-detection vendors, by their own admission, permit attacks to affect a certain percentage of a network. This can translate into hundreds of machines being compromised before an attack is detected. In many cases, whole networks can be infected in a matter of minutes. Anomaly detection relies on network flow data, which is often reported at intervals of 15 to 45 minutes. With that kind of lag, an entire network can be brought down.
  • It produces an enormous number of false positives. Anomalies can occur in a network at any time. Because anomaly detection is looking for an anomalous event rather than an attack, it is frequently plagued by time-consuming false positives. This can result in a "the boy that cried wolf" syndrome: When an actual attack is afoot, no one will respond because of all the previous false positives.
  • It provides marginally effective mitigation techniques, if it provides any. With a high rate of false positives, it is perhaps a blessing that these products do not provide the option of a fully automated containment process. Because of their significant detection latency, anomaly detection response techniques are often geared toward containing widespread outbreaks through zone segmentation. This is equivalent to amputating an entire limb for an infection when a wound could have been treated earlier. A more appropriate response is to immediately and surgically contain the initial infection vector, before propagation can occur, preventing an outbreak in the first place.

Most anomaly-detection products were built for network performance monitoring and diagnostics. They weren't designed to protect the network from zero-day attacks, targeted attacks and worm storms. Anomaly detection systems are unable to mitigate slow, stealthy and sophisticated attacks. Hackers are using this method, essentially spreading an attack over a longer time, to fly under the radar of anomaly-detection engines and other security devices.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comments (2)
Login
Forgot your account info?

hiBy Anonymous on September 5, 2008, 3:48 amgive me pls exact meaning of way to prevent virus pls...pls...pls...

Reply | Read entire comment

Anomaly detection is not the best way to prevent virus, worm attacksBy Anonymous on February 13, 2007, 9:37 pmFor "behaviour" based anomaly detection methods you are absolutely right(protocol anomaly detection on the the other hand works great!). Because security is a more...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed