McAfee Beefs Up VirusScan Security
Updated antivirus software for businesses adds intrusion prevention features.
Paul Roberts, IDG News Service
Antivirus software company McAfee is unveiling a new version of its VirusScan Enterprise software that contains so-called "intrusion prevention" features, the company says this week.
The intrusion protection features are designed to protect computers from attacks such as buffer overflows, which are often used by viruses, worms and malicious hackers to compromise vulnerable Microsoft Windows machines.
VirusScan Enterprise 8.0i integrates intrusion prevention services and firewall technology with antivirus software to protect personal computers and file servers from new malicious code outbreaks automatically. The new version of VirusScan also has features to manage new malicious code outbreaks, limiting the damage they cause, McAfee says.
The announcement comes as antivirus software makers and networking equipment vendors look for ways to harden machines against possible compromise and crack down on a host of threats, from spam and spyware to bogus Web pages used in phishing scams.
The new version of VirusScan incorporates host IPS technology from McAfee's acquisition of Entercept Security Technologies in April 2003. The Entercept technology allows VirusScan to spot malicious code used to exploit vulnerabilities in the Windows operating system and Microsoft applications like Internet Explorer, Outlook and Microsoft Office, says John Bedrick, group marketing manager for systems security at McAfee.
Periodic Updates
The product requires periodic updates from McAfee, but Bedrick is reluctant to call the IPS updates "signatures," for fear of lumping them in with the frequent antivirus updates that are required when new worms and viruses appear.
For example, VirusScan 8.0i spots malicious code that tries to exploit a known vulnerability in older versions of a Windows component called the Local Security Authority Subsystem Service (or LSASS). The recent Sasser and Gaobot worms spread by compromising machines using vulnerable versions of LSASS. VirusScan 8.0i protects Windows machines from any of those threats. However, unlike antivirus software, it does not require a new "signature" for each worm that targeted LSASS, Bedrick says.
The new features are part of Protection-in-Depth, a McAfee program intended to provide many layers of defense against malicious computer activity, McAfee says.
While IPS features in VirusScan improves that product's ability to spot malicious computer code, the new features do not turn VirusScan into a full-fledged IPS product. Instead, McAfee added a small set of IPS features that will provide the maximum protection to users while creating the minimum of "noise" such as blocking valid traffic, Bedrick says.
Whereas a comprehensive IPS product like Entercept's prevent buffer overflows of any kind, VirusScan 8.0i limits buffer overflow protection to the 30 or so Windows applications and services that most McAfee customers use, he says.
"The idea was to pick the applications and services that were the most commonly exploited," he says.
In doing so, McAfee had to strike a careful balance between making VirusScan more proactive and turning it into a nuisance for users, he says.
Larger Push
The release of VirusScan 8.0i is part of a larger push into the IPS arena at McAfee. In June the company, formerly Network Associates, announced new versions of two intrusion prevention products, IntruShield and Entercept, that it said will make it easier to protect corporate networks from so-called "zero day" attacks, attempts to break in to networks using previously unknown vulnerabilities.
The company has more announcements planned for future releases that will enhance the ability of its products to spot malicious code before it can infect a customer network. Future features may include wizards and rules for configuring proactive security, he says.
McAfee VirusScan 8.0i is not sold as a stand-alone product, but is sold in suites, such as McAfee Total Virus Defense, with other McAfee products. The product is available for free to existing customers with valid support agreements, and to new customers through McAfee and its partners, McAfee says.
With HP wireless printers, you could have printed this from any room in the house. Live wirelessly. Print wirelessly.
Windows Home Server
Related Antivirus and Security Articles
- 15 Tech Secrets for the Serious Road Warrior Use these smart mobile tech tricks to create your own wireless hotspot out of a phone or laptop in a pinch, protect your laptop from grab-and-dash thieves, and communicate with anyone anywhere.
- PasswordWallet Update Released PasswordWallet has been updated, fixing several bugs with the application and adding German localization.
- ScreenFlow Update Fixes Conflict With WireTap Mac OS X screen recording application, ScreenFlow, has been updated fixing several issues with the application.
- Microsoft Kills OneCare to Offer Freebie; So Long, Norton Bundling a security app with the operating system is good news for users and bad news for standalone security suites.
- Can Two Security Suites Co-Exist? Bob Carne wants to use Trend Micro Internet Security as added spyware protection, along with Norton 360. They don't play well together.
Best Prices on Security Software
Internet Security 2009Price: $21.00
Norton Internet Security 2009Price: $19.95
Internet Security 2009Price: $24.95
Norton 360 2.0 ( PC)Price: $35.95
Internet Security 2008 - 3-User (Full Product, PC)Price: $11.19
Norton Internet Security 2008Price: $13.50
- PC World Webcast: Going Green Wondering how to make your business greener? These tips will help your business save money, and save the environment.
- A Windows Vista FAQ Corporate customers are deploying Windows Vista now, and Dell Services wants to help you understand the features of the new OS and how to plan your Windows Vista deployment.




