Home > Security Channel Tips > Information Security Threats > Antivirus software patch management
Security Channel Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

INFORMATION SECURITY THREATS

Antivirus software patch management


Tony Bradley
03.20.2007
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Value-added resellers (VARs) and security consultants can use these common tools and techniques to ensure that customers' computers remain protected from antivirus software vulnerabilities. This tip originally appeared on SearchWindowsSecurity.com.

One of the best-known threats to desktop and personal computers is the computer virus. Viruses -- and their malware cousins, worms and Trojans -- are ubiquitous threats to anyone using a computer. It makes sense then that antivirus software is probably the most commonly used security application on desktop and personal computers.

What happens, though, if the antivirus software itself is flawed? What if the very virus or worm that your antivirus software is supposed to defend against is actually targeting a flaw in the antivirus software to circumvent your security efforts? Obviously, that would be a problem.

The major antivirus vendors, including Computer Associates, McAfee, Sophos, Symantec and Trend Micro, have all been impacted by flaws or vulnerabilities in their applications. Flaws in their applications could allow malicious code to bypass the antivirus scanning in some way or cause a denial-of-service condition for the program. To ensure that your computer remains protected, you have to make sure your antivirus software remains patched and fully functional.

You can follow vulnerability announcements from third-party sources such as Secunia or Bugtraq, or you can use announcement and n...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Antimalware Strategies and Techniques
How to recession-proof your information security business
Malware removal without antivirus software
Email filtering: Choosing a content filtering tool for your customer
Polymorphic malware attacks and in-line scanning
Use hosted email filtering for virus protection
Re-route virus traffic to the bit bucket
Content filtering: An integrated approach
How to use an ISA Server as an SMTP filter
Filter URLs to reduce information security threats
Use egress filtering to prevent DoS attacks

Information Security Threats
Mitigating zero-day vulnerabilities in customers' environments
Getting to know the NERC CIP standards
UTM appliances bundle security, give VARs multiple revenue streams
Remote vulnerability scanning: Process, roles and responsibilities
Data breach prevention techniques: Helping customers avoid data breaches
Full disk encryption: A hot opportunity for VARs
Top security tips for solutions providers
Common injection attacks
Checklist: Five steps to assessing a customer's antivirus protection
Polymorphic malware attacks and in-line scanning

Platform Security
Channel Checklist: Windows Vista security
An introduction to penetration testing and its legal implications for VARs and consultants
Penetration testing reconnaissance -- Footprinting, scanning and enumerating
Penetration testing -- Big bad bugs
Penetration testing -- Securing wireless access points
Network penetration testing: Ethical hacking tools and techniques
Penetration testing -- Social engineering, IDS and honey pots
Windows security administration using command-line tools
Windows Vista BitLocker basics and advanced techniques
Microsoft Windows Vista firewall enhancements

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


otification services from the vendor of your antivirus software. Below are links you can use to find out more about staying informed about security concerns and patch releases for the major antivirus vendors:

In smaller organizations, you can simply set up user software to automatically download updates from the vendor sites. Larger organizations may use enterprise management software such as Trend Micro's OfficeScan server or McAfee's ePolicy Orchestrator that allows administrators to test and configure updates prior to deploying them down to users.

About the author
Tony Bradley is a consultant and writer with a focus on network security, antivirus and incident response. He is the About.com Guide for Internet / Network Security, providing a broad range of information security tips, advice, reviews and information. Tony also contributes frequently to other industry publications.

This tip originally appeared on SearchWindowsSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurityChannel.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersBlogsEvents
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2006 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts