Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: virus checking
From: Pavel Galynin <pgalynin @ chipnet . cz>
Date: Thu, 27 Feb 1997 11:58:21 +0100
To: Ron DuFresne <dufresne @ parka . winternet . com>
Cc: Todd Graham Lewis <lists @ reflections . mindspring . com>, Lance and Christine <lance @ pfi . com>, firewalls @ GreatCircle . COM
References: <Pine . GSO . 3 . 95q . 970227171355 . 13248A-100000 @ parka . winternet . com>

Ron DuFresne wrote:
> 
> On Thu, 27 Feb 1997, Pavel Galynin wrote:
> 
> > --------------------------- cut ----------------------------------------
> > > > I don't think the virus filters come close to being worth the cost.
> > > >
> > >
> > > Every organization I have worked with found that the best way to handle
> > > the issue of viri is at the desktop workstation.
> > >
> > It is the most efficient way, efficience/cost ratiowise, but it is not
> > perfect and leaves HUGE scurity holes.
> 
> Agreed it's not perfect, but is at this time the most viable solution
> available. 
Are you familiar with Unix desktop anti-virus soft? i'm not, but I 
assume that with Unix high-level programming required for portability 
and impossibility to write ASM progs. This leaves you undefended and 
dressed-down in front of a polymorphic. I would be scared to even think 
about what would happen if a virus was designed for a specific Unix 
brand and platform...
> Sure, one can scan at the wall/gateway, but, that's more
> imperfect a solution at this point in time, not to mention the possible
> bottlenecking that can most likely ensue.  But as for this leaving "HUGE
> scurity holes", I'd certainly like to see you clarify that statement a 
>tad
Well, I don't know of any virii that use protected mode, but if there 
were ( there could be by now ), circumventing Unix memory protection 
would be very easy with some use of Appendix H and the likes 
instructions.
> OK, so you're a Ph.D.  Just don't touch anything.
Just lookin' :))
					Paul.


Follow-Ups:
References:
Indexed By Date Previous: Re: virus checking
From: harley @ icrf . icnet . uk
Next: Re: [FW] Re: virus checking
From: Pavel Galynin <pgalynin @ chipnet . cz>
Indexed By Thread Previous: Re: virus checking
From: Ron DuFresne <dufresne @ parka . winternet . com>
Next: Re: virus checking
From: blymn @ awadi . com . au (Brett Lymn)

Google
 
Search Internet Search www.greatcircle.com