Over 800 Vulnerabilities in Anti-Virus Software -- Reaction to the McAfee Statement
Oberursel, Germany (PRWEB) July 23, 2008 -- During the past few months, specialists from the n.runs AG, along with other security experts, have discovered approximately 800 vulnerabilities in anti-virus products. The conclusion: contrary to their actual function, the products open the door to attackers, enable them to penetrate company networks and infect them with destructive code. The positioning of anti-virus software in central areas of the company now poses an accordingly high security risk.
The tests performed by the consulting company and solutions developer n.runs have indicated that every virus scanner currently on the market immediately revealed up to several highly critical vulnerabilities. These then pave the way for Denial of Service (DoS) attacks and enable the infiltration of destructive code -- past the security solution into the network. With that, anti-virus solutions actually allow the very thing they should instead prevent.
In this context, n.runs was able to make out so-called "parsing" as one of the main causes of this boomerang effect. The principle functions as follows: virus scanners must recognise as many "Malware" applications as possible -- and thereby comprehend and process a large number of file formats. In order to be able to interpret the formats, an application must partition the corresponding file into blocks and structures. This separation of data into analysable individual parts is called "parsing". Mistaken assumptions in the course of programming the parsing code create constellations which enable the infiltration and subsequent running of programme code.
As a reaction McAfee posted an statement to their Avert blog, which tries to negate some of the statements given in the original n.runs Press-release, this represents a short summary of our response to the McAfee Statement on AV Vulnerabilities. For the complete response see: Response to McAfee Statement (PDF) (http://www.nruns.com/_downloads/PR-08-02_Reaction_to_McAfee_statement.pdf)
Ryan Permeh (McAfee) wrote: "The ZDNet posting includes scary graphs to frighten users of security products."
n.runs would like to clarify the statistics those graphs are based on were gathered using an independent database from Secunia and National Vulnerability Database, ZDnet has not produced them. Secunia and the National Vulnerability Database are trusted and respected aggregators of security vulnerabilities and advisories and provided the database to these statistics. Let us emphasize that the intention was not to scare as the statement from McAfee implies, but to put independent facts in addition to those from n.runs on the table. The statistics show a vendor independent view on AV vulnerabilities.
"One of the conclusions drawn by N.Runs is that having AV in your environment makes you less secure than not having it at all."
n.runs would like to emphasize this is clearly not what n.runs believes. We are convinced that AV software is necessary and a requirement for today's security defense. What n.runs believes is that multiple engines increase the chance of parsing bugs to occur. Let us show what we mean by using an example based on an Email setup (Detection rates are examples, attack surface in this case is represented by the number of formats supported, # of vulnerabilities per format is an estimate based on our audits).
Reaction to Statement (http://www.nruns.com/_downloads/PR-08-02_Reaction_to_McAfee_statement.pdf)
E-mail is being routed through all three engines, the detection rate increases as does the remotely reachable attack surface.
n.runs firmly believes that the use of AV software or even multiple AV software is a requirement as of today, but that the inherent bugs of AV Software need to be taken into account when designing your perimeter and internal security defense. The rising number of available formats, cryptors, packers combined with the intrinsic market pressure in the AV field (release early, release often) has not helped AV Vendors to increase code quality over the years, as the very same statistics and our experience over the years have clearly indicated (more on this later).We are convinced that AV vendors should focus on doing what AV vendors do best : Recognize malware, aps-AV takes care of the rest.
"In addition, McAfee has not seen any evidence of any of the vulnerabilities reported by N.Runs being exploited to attack our products in real world environments."
This is due to the fact that n.runs reports these vulnerabilities in order to protect our own and McAfee customers. Our vulnerability notification policy is rigid and strict, advisories included no details as to how the vulnerability was found or how it could be exploited.In our view, the bigger concern are those vulnerabilities not found and published by us, especially as black-market prices for AV-vulnerabilities are on the rise. n.runs is aware of two publicly documented incidents where AV software (running on E-mail servers) was the remote entry vector to internal networks. n.runs also believes that security is a process aimed at being proactive and not solely a process in reaction to events or bugs. Statements such as "McAfee has not seen any evidence" can be deceptive.
For instance, Immunity explained in great detail how they penetrated an Enterprise over AV software on an MTA and used it to covertly shuffle data in and out over weeks. They further explain why they choose AV Software and not a web server or client-side exploits. The attack was done in a similar way to how a professional attacker would proceed., They replicated the existing infrastructure and searched for exploitable conditions and they found one. We do think this backs up our views of the actual threat posed by vulnerabilities in AV software.
The logic that bugs are fixed when they are found is no argument against a professional attacker for the sole reason that these professional and/or military style attackers rarely use known flaws. If the paradigm you follow is -- "we protect against what is known" (quite common in the AV industry) then you are doing no favor to those who demand protection against professional attackers.
"Our numbers seemed to have peaked in 2005, which is contrary to the trending that the N.Runs reports."
n.runs finds it astounding that McAfee comes to this conclusion without taking the vulnerabilities into account that have been reported but where the patch is still pending - and without taking into account the vulnerabilities listed for example on secunia, which are not listed in CVE.
n.runs has the following bugs pending and is aware of at least another DoS bug pending from a independent researcher.
Here is the list of pending McAfee bugs reported by n.runs :
Incident ID: MFE-FW-20060227-01 - Date of receipt: February 27, 2006
Incident ID: MFE-ENG-20070605-01 - Date of receipt: June 5, 2007 (Possible Vuln #15)
Incident ID: MFE-ENG-20070607-01 - Date of receipt: June 7, 2007 (Possible Vuln #18)
Incident ID: MFE-ENG-20070608-01 - Date of receipt: June 7, 2007 (Possible Vuln #23)
Incident ID: MFE-ENG-20070608-02 - Date of receipt: June 7, 2007 (Possible Vuln #25)
Incident ID: MFE-ENG-20070615-01 - Date of receipt: June 15, 2007 (Possible Vuln #27)
Incident ID: MFE-ENG-20070615-02 - Date of receipt: June 15, 2007 (Possible Vuln #28)
Incident ID: MFE-ENG-20071111-01 - Date of receipt: November 11, 2007 (Possible Vuln #36)
Incident ID: MFE-ENG-20071111-02 - Date of receipt: November 11, 2007 (Possible Vuln #37)
Simply adding these pending reports to the graph gives the following result: Statement (http://www.nruns.com/_downloads/PR-08-02_Reaction_to_McAfee_statement.pdf)
n.runs believes this does indeed represent a trend, not to mention these only include problems reported by n.runs, not external researchers or entities nor internal penetration test efforts (which also pose a security threat during the exposure window but are never published).
About n.runs
n.runs AG is a vendor-independent consulting company specializing in the areas of: IT Infrastructure, IT Security and IT Business Consulting. In 2007, n.runs expanded its core business area, which until then had been project based consulting, to include the development of specialized security solutions.
About aps-AV®
n.runs aps-AV® (Application Protection System Anti-Virus) is part of the n.runs aps product line. aps-AV® offers comprehensive E-Mail and Anti-virus protection by implementing the Defense-In-Depth-Principle in a high-secure 3-Tier architecture. aps-AV® not only offers multi-engine protection and the possibility of centralization but encloses the AV engines within a sealed environment. Additionally aps-AV® optimizes the performance of the servers and simplifies the administration of multiple AV engines and resources. For more information please see: http://www.nruns.com/_en/aps/aps-description.pdf
Contact details:
n.runs AG
Nassauer Straße 60
D-61440 Oberursel
Phone: +49 (0) 15155002771
Fax: +49 (0) 6171/699-199
###
Related Articles:
XMicro Has Developed the Latest Technology in Antivirus Solutions, Internet Security, Parental Control, Anti Spam, Spyware Detection and Firewall
XMicro is a Worldwide distributor for security software and antivirus solutions.
New Production Release: The Shield Firewall 5.0 - Uncomplicated Hacker Protection
PCSecurityShield has upgraded its security software products with Vista compatibility and advanced protection features.
Tune Up Your Email Newsletter To Be Compliant With Anti-Spam Filters
In this article we?ll continue talking about how to create a healthy email message and give a few tips how to survive anti-spam filters. Anti-spam filters catch every incoming email before it is delivered into the inbox and review it. They use a scoring system to classify an email as spam or legitimate. These filters (you might have heard about SpamAssassin, SpamProbe, or SpamCombat) look for certain patterns in the message, and assign "spam points" to it based on certain criteria: words, phrases, or even colors.
Finding The Best Anti Spam Solutions
Before you start finding the best anti spam solutions, there are some simple steps that you will have to take care in order to avoid spam. Make sure that you share your email ID with only those whom you know well. For other services, make use of email services that are web based. Beware of spam bots. They are programs that are made to accumulate the email IDs throughout the net for preparing a mailing list. This list is used to send all unsolicited mails to users. Try to use the form of email that do not does not display your address in the webpage code. Install various kinds of anti-virus and other anti-spyware programs. Keep updating the version frequently. Email configuration should be done to disable the features that identify an email ...
Spyware - Has Your Computer Been Infected?
If you download a lot of software from the Internet, especially anything that maybe trial, or free then you may be leaving your computer open to spyware attacks.
How Anti-Spyware Helps
If your computer is behaving oddly, is slowing down, gets hung up in the middle of your work, or is bedeviled with ?pop-ups,? then it is probably infected with spyware.
Windows Spyware Removal
If you own a computer, then chances are you've been affected by spyware. And, if you're like me, there is nothing more frustrating than dealing with annoying pop-ups, having your home page changed or just dealing with a painfully slow computer.
The Move to a New Anti-Virus Model
This is the second in a series of articles highlighting reasons why we need a new model for anti-virus and security solutions.Reason #1: the Basic ModelAnti-virus software vendors still rely on yesterday's methods for solving today's problems: they wait for the next virus to wreak havoc and then produce a solution.
New Spyware Removal Review Site Identifies The Reputable Antispyware
Innovative spyware removal site reveals the truth about antispyware, and how to remove spyware.

