What I have learned in IT security (so far)
I've worked as a resident consultant for a multinational company for 9 months. Our main product supported was SAV CE 10 which was later migrated to SEP 11. There is also a Symantec Mail security for Microsoft Exchange and have just recently installed Symantec Brightmail Gateway appliance. And this is what I have learned:
Whatever policies and security applications you've installed, someone is bound to bypass them. This company uses a firewall proxy that, as other companies have, blocks the user from visiting non-business related websites. And still when I walk past some users workstations, I can see them browsing social websites, hacking websites (mostly to bypass securities), blogs - sites which are clearly blocked or should be blocked by their proxy firewall. Some would try to bypass or disable any or all the security applications in place, so that they can “work faster”. And I bet that the first thing a user would do after bypassing the security is to put media files on a personal folder. Then enable file sharing. Before you know it, they have a large collection taking up needed disk space which would make you wonder why you can’t push an upgrade due to “insufficient disk space”. Nothing can stop the strong willed.
No matter how you set the scan settings, go to uber paranoid mode, malware can still reach the client. This has been discussed numerous times on the Symantec forums or other AV forums. It doesn't matter how well you implement your AV solution, malwares will still reach your clients. Malwares would need to be downloaded or in cases of USB devices be connected onto the clients PCs first before being scanned. This should explain why, one day, you'll receive hundreds of alerts quarantined, deleted, or cleaned. This is mostly temporary internet files from websites that are compromised or have hidden scripts in them. Other times, it is an executable file in the same folder. You may control the USB access in your company, but if they know how to bypass them, then be on alert. We don’t know where that storage had been. And then there are those clueless users who, out of pure luck, is able to destroy the OS even if everything is protected. I’ll never know what they do out of work, what websites they visit, with the flash drive connected waiting to accept a new malware which will be brought into the office the next day.
To give you a perspective, count the number of respectable AV vendors in the market versus the number of malwares being written. Malwares, a lot of them, are poorly written compared to AVs that we expect to run perfectly when installed. This attention to quality affects the turnaround and is the reason why AV technology is lagging behind (at least not that great of a lead). When AV vendors make an AV solution or upgrade an older one, they have to make sure that everything works well, does what it was designed to do and doesn't destroy your system or reduce productivity. This is being done by skilled programmers, quality control personnel, beta testers and other personnel which costs money. Malware authors and even script kiddies on the other hand, rarely uses any quality testing. Their code is designed to do one thing - create havoc. If their code is designed, for example, to steal user information and because of poorly written code, crashes the PC before completing its task, they’d still consider this as a success. The only thing they need to make sure is the survivability of the malware in the wild. Make it evolve faster that the time it takes for it to be listed on anyone’s definitions. This is as easy as adding a single line to the code.
IT policies are the least enforced company policy. I’m not saying that it isn’t being enforced, but it is not on top of the chain. I bet more people have received sanctions from violation of HR policies more than those that violate IT policies. This could be the reason that some users do what they do. Other reasons could be that users also, in time, tend to forget that the PC they’re using is company property or maybe because of the realization of that that they think they can break it because someone will fix it for free. However you see it, users treat their own computer at home differently than the computer they use at work.
Management will only be concerned about IT security when it is required or is already too late. Protection in general, whether it be a backup solution or a security solution is not on every managements to buy list. Top level management is mainly concerned about making a profit and adding assets to the company. Backup and AV solutions doesn’t generate any income, moreover, they cost the company in terms of licensing and support hence, in accounting terms, a liability. So administrators are left to make do with what they have. If the IT were on top of the list in the annual budget, we’d probably be having the top-of-the-line desktops, servers and all that. But don’t get me wrong here. If they’ve had a computer for quite some time, they are aware of the need for a security solution, but I doubt they’re aware or want to know anything more than what the advertisement or fact-sheet contains – “If it works, good. Otherwise, look elsewhere.” On the bright side, management’s realization on the importance of security grows with the size of the company. Compare the requirements of SMBs to large multinational corporations. Look at the products they claim they can do without because these things costs them.
So in the end, it is still up to the IT team, to be smarter than the end users, to be on alert for new risks and threats, to be able to explain their work to people (which is rather hard considering that technical people are stereotyped to lack interpersonal skills - joke) so that their decisions would be met with open minds. And we should keep our minds open to new information, additional knowledge and anything that would make us wiser. I still consider myself a student even though I've been doing this for a few years now.
Comments
you are very gifted.. many
you are very gifted..
many thanks for the experiences...
Nel Ramos
Thats a true article
This is a reality in the corporate industry, Specially in this "cost-cutting" time. People do forget the importance of security and tend to take security softwares and devices just as granted.
Management tries to cut down the cost of support and they lay of consultant and admins.
Thus mostly it becomes one man show .that is one man has to look at 100s of things that too in the fear that if he does a single mistake he might be laid off.
But people on the other side of the industry are taking advantage of this recession and the major one was Downadup/Conficker.
VMWARE-- SEP 12.1 vs McAfee vs Trend Micro
yeah this is totally
yeah this is totally right
even happened in our company
A true veteran of the
A true veteran of the craft...
you got my vote man..
Management differs what the IT guy thinks about solution package
It is our stand to push for better solutions and tell management why we need them...
Because management would treat it as a cost or expense while we treat is as a valuable life saver...
Persuation is the key plus the right solution package to get the nod of management...
Nel Ramos
I appreciate your vote of
I appreciate your vote of confidence, guys! Thanks!!
In the other company I worked with. I recieved the nickname 'The Virus guy' - they left out the anti- but I guess I'm the go-to guy there when it comes to virus removal. And my present employer (a Symantec reseller) underestimated my skills. Not sure if this is a good thing or bad. :D
“Your most unhappy customers are your greatest source of learning.”
looks like i need to forward
looks like i need to forward this article to my management :)
thanks for the
thanks for the incites...
your experience is valuable..
very informative... hope i
very informative...
hope i could also be as good as you when i am 10 years in the business...
just a new AV engr
thanks...
@zayreetadiosa: I've only
@zayreetadiosa: I've only been in the IT field for roughly 4 years. And AV was one of the first tasks assigned to me. Probably because my employers think that that's the only place where I could do the least amount of damage should anything go wrong - compared to managing production servers. :D
Although, from personal experience. The first virus I've ever encountered was named C brain during the DOS era. Back then, even some tech people thought that computers could get virus from humans! It's true, I was forbidden to play games until my cold was better.
I'm sure you'll be good at what you do in just a couple of months, once you've had your fair share of malwares. Post a thread in the forums for things you don't know.
“Your most unhappy customers are your greatest source of learning.”
Hi Mon.. What do you think
Hi Mon..
What do you think would be the future of Anti-virus?
Thanks.
Nel Ramos
@Nel, that's a pretty tall
@Nel, that's a pretty tall order. :D Give me a nice title and I might blog about it.
“Your most unhappy customers are your greatest source of learning.”
<< Deleted by Moderator >>
<< Deleted by Moderator >>
Hi Mon... Nice article.. hope
Hi Mon...
Nice article..
hope the one you primose would be out soon...
thanks
thanks mon for the good
thanks mon for the good article...
You're welcome. I'll promise
You're welcome. I'll promise to write more articles as soon as:
1. I get my PCworking the way I want it to. I need a new hard drive. :(
2. Plus, claimed my Symantec reward a week ago and just can't put it down. :D
3. After I've finished some personal things to do.
“Your most unhappy customers are your greatest source of learning.”
nice article mon keep up the
nice article mon keep up the good work
Nice work MON...I really
Nice work MON...I really don't understand when will my ( everybody's ) manager will start taking Antivirus seriously..
.
Thanks for taking your time in reading my article. I appreciate the fact that someone reads this.
Int3rn3t: Pass this article along to your manager. :D
“Your most unhappy customers are your greatest source of learning.”
Hahaha... Thats a good one
Hahaha...
Thats a good one Mon...
The managers might hire you in their place...
thanks...
Nel Ramos
Super, u r telling the
Super, u r telling the reality.
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Deja vu
It's happening again, my client is panicking about our implmentation of Symantec security solutions. But, not because of any latest exploit or malware. It's time again for the annual audit and they've decided to look into IT security this time.
“Your most unhappy customers are your greatest source of learning.”
SEP for you is like a
SEP for you is like a cycle... but with a twist...
Specially if that would be in a financial institution or a contact center then they have a great deal to worry about...I hear IT audit is a nightmare...
thanks...
Nel Ramos
Thats cent Percent tru...
Thats cent Percent tru...
Would you like to reply?
Login or Register to post your comment.