GFI
English Deutsch Français Italiano Nederlands Español
Bedrijf > Nieuws > 2003 > GFI white paper exposes how hackers can el...

GFI white paper exposes how hackers can elude anti-virus software with custom Trojans

Network administrators must add Trojan detection capabilities to their network security arsenal

London, UK, 9 July 2003 – GFI today released a white paper to help network administrators tackle the growing problem of Trojans, which are increasingly being used to steal credit card data, passwords, and other sensitive information, and to launch electronic attacks against targeted organizations. GFI’s latest white paper outlines what Trojans are, why they pose a danger to corporate networks, and how to protect against them. It can be viewed at http://www.gfi.com/whitepapers/network-protection-against-trojans.pdf.

What a Trojan is and why it poses a threat to organizations
A Trojan horse is used to enter a victim's computer undetected, granting the attacker unrestricted access to the data stored on that computer. A Trojan can be a hidden program that runs on the victim’s computer without his knowledge, or it can be 'wrapped' into a legitimate program, meaning that this program includes hidden functions that the victim is unaware of. In the corporate world, Trojans are mainly used to siphon off confidential information (industrial espionage) or to create damage. GFI’s white paper describes the seven main types of Trojan and explains how a network can be infected by a Trojan via an email attachment or a downloaded file.

Why an anti-virus engine does not provide all the protection required
Protection against Trojans is a must. Yet, basic security software such as an anti-virus engine does not provide an adequate safeguard against Trojans: the paper explains that although most virus scanners detect some public/known Trojans, they are unable to scan unknown Trojans. This is because anti-virus software relies mainly on recognizing the "signatures" of each Trojan. Yet, because the source code of many Trojans is easily available, a more advanced hacker can create a new version of a Trojan, the signature of which is unknown to any anti-virus scanner.

“If the person planning to attack you finds out what anti-virus software you use, for example through the automatic disclaimer added to outgoing emails by some anti-virus engines, he will then create a Trojan specifically to bypass your virus scanner engine,” the white paper points out. “Also, apart from failing to detect unknown Trojans, virus scanners do not detect all known Trojans either - most virus vendors do not actively seek new Trojans, and research has shown that virus engines each detect a particular set of Trojans.”

How to protect a network from Trojans
The white paper proposes that to detect Trojans, one must use a multi-level strategy and deploy multiple virus scanners at the gateway, which would increase the percentage of known Trojans caught; and use content security with executable analysis to detect potentially malicious executables, analyze what they might do and prevent unknown Trojans from entering the network.

Detecting unknown Trojans can be done by manually reviewing each incoming executable; yet this is a tedious and time-intensive job, and can be subject to human error. Therefore it is better to automate the process by means of a Trojan and executable analyzer that can intelligently analyze what each executable does and how dangerous it is. A Trojan and executable analyzer disassembles the executable and detects in real time what it might do. It compares these actions to a database of malicious actions and then rates the risk level of the executable. This way, potentially dangerous, unknown or one-off Trojans can be detected.

Gateway protection
Two products that offer comprehensive gateway protection that includes multiple virus engines, content checking and a Trojan and executable scanner, as well as other security features are:

  • GFI MailSecurity for Exchange/SMTP, an email content checking, exploit detection, threats analysis, anti-Trojan and anti-virus solution that removes all types of email-borne threats before they can affect an organization’s email users. More product information and a trial version can be found at http://www.gfi.com/mailsecurity/.
  • GFI DownloadSecurity for ISA Server, that enables administrators to assert control over what files users download from HTTP and FTP sites by content checking and quarantining downloaded files for malicious content, viruses, and Trojans. More product information and a trial version can be found at http://www.gfi.com/dsec/.
Over GFI
GFI is een toonaangevende ontwikkelaar van software voor netwerkbeveiliging, inhoudsbeveiliging en messaging. Dankzij bekroonde technologie, een agressieve prijsstrategie en een sterke focus op MKB-bedrijven helpt GFI bedrijven over de hele wereld om maximale continuïteit en productiviteit te bewerkstelligen. GFI is opgericht in 1992 en heeft kantoren in Malta, Londen, Raleigh, Hong Kong en Adelaide die wereldwijd meer dan 200.000 installaties ondersteunen. GFI is een kanaalgericht bedrijf met meer dan 10.000 partners over de hele wereld. GFI is ook een Microsoft Gold Certified Partner. Meer informatie over GFI is te vinden op http://www.gfi.nl.
 
Alle genoemde product- en bedrijfsnamen zijn mogelijk handelsmerken van hun respectievelijke eigenaren.



 Lees meer over de producten van GFI
>  GFI MailEssentials for Exchange/SMTP
>  GFI MailSecurity for Exchange/SMTP
>  GFI MailArchiver for Exchange
>  GFI FAXmaker for Exchange/SMTP
>  GFI LANguard Network Security Scanner
>  GFI EventsManager
>  GFI EndPointSecurity
>  GFI Network Server Monitor
>  GFI WebMonitor for ISA Server

   © 2008. Alle rechten voorbehouden. GFI Software Home Producten Downloads Ondersteuning Bestellen Site map Over GFI Contact