Endpoint Protection

 View Only
  • 1.  Why do signature updates (security updates) remove protection for some things?

    Posted Nov 02, 2009 03:54 PM

    For the first time I was reviewing the Security Updates web page (http://www.symantec.com/business/security_response/securityupdates/list.jsp?fid=sep) and noticed that some of the signature updates say "removes coverage for the following vulnerabilities and threats".  Why would Symantec remove the signature for known vulnerabilities?  Is the vulnerability detected by some other component?



  • 2.  RE: Why do signature updates (security updates) remove protection for some things?

    Posted Nov 02, 2009 04:03 PM
    From my understanding its actually like a replace ID what we get in microsoft updates.
    its an appended definitions only.
    something like commulative updates from MS for internet explores in SEP wil replace the same update in August..


  • 3.  RE: Why do signature updates (security updates) remove protection for some things?

    Posted Nov 02, 2009 04:04 PM
    My "guess":

    Sometimes they are no longer needed because they are covered with OS updates or patches, or just aren't found in the wild any more?
    Ping of Death is an example - nothing out in the mainstream is actuallly vulnerable any more so they could remove that (but have not!)
    We keep getting FALSE ALERTS for PoD, and yet there's no OS currently in use that is even vulnerable for the last several years. So technically, even if someone TRIED a PoD against us, it would be futile.