<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>mcwresearch.com &#187; AV sucks</title>
	<atom:link href="http://mcwresearch.com/archives/category/av-sucks/feed" rel="self" type="application/rss+xml" />
	<link>http://mcwresearch.com</link>
	<description>Things I think I've thought about</description>
	<lastBuildDate>Mon, 28 Dec 2009 22:10:04 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>Network worms are still effective</title>
		<link>http://mcwresearch.com/archives/644</link>
		<comments>http://mcwresearch.com/archives/644#comments</comments>
		<pubDate>Wed, 14 Jan 2009 17:08:10 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Worm]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/?p=644</guid>
		<description><![CDATA[A good friend recently emailed me to ask if AV would protect his servers from the Conficker worm and I thought this would be a good opportunity to continue my anti-antivirus tirade. The short answer to the question &#8216;will AV protect me from conficker&#8217; is &#8220;somewhat.&#8221; Here&#8217;s why. Below are the typical phases of a [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/644/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>AV stats</title>
		<link>http://mcwresearch.com/archives/605</link>
		<comments>http://mcwresearch.com/archives/605#comments</comments>
		<pubDate>Mon, 18 Feb 2008 23:30:14 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/605</guid>
		<description><![CDATA[Take &#8216;em for what their worth; this is a collection of events logged from 277 hosts located in 12 different office locations with five unique, central AV servers managed by five different IT departments. The statistics have been collected over 11 days: Number of alerts regarding a failure to open a file: 1253* Number of [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/605/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>The Future of AV?</title>
		<link>http://mcwresearch.com/archives/604</link>
		<comments>http://mcwresearch.com/archives/604#comments</comments>
		<pubDate>Mon, 11 Feb 2008 20:56:20 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/604</guid>
		<description><![CDATA[Last week I struck a cord with a few people when I (once again) complained publicly about the short-comings of AV. I&#8217;ve gone on record claiming the current model is broken, so what do I think will help fix it? Below are some of the ideas I&#8217;ve had for the future of AV. Shim the [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/604/feed</wfw:commentRss>
		<slash:comments>8</slash:comments>
		</item>
		<item>
		<title>AV must innovate or die</title>
		<link>http://mcwresearch.com/archives/603</link>
		<comments>http://mcwresearch.com/archives/603#comments</comments>
		<pubDate>Fri, 08 Feb 2008 15:40:35 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/603</guid>
		<description><![CDATA[One of the things I&#8217;ve been doing with my HIPS software is take a closer look at my AV protection, or lack thereof. I have HIPS on roughly 300 hosts on my network, which is a slice of about 1/5th of my entire host population. I have the HIPS software pulling selected events from the [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/603/feed</wfw:commentRss>
		<slash:comments>5</slash:comments>
		</item>
		<item>
		<title>The conquerer of AV?</title>
		<link>http://mcwresearch.com/archives/602</link>
		<comments>http://mcwresearch.com/archives/602#comments</comments>
		<pubDate>Thu, 07 Feb 2008 21:54:05 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Intrusion Detection/Prevention]]></category>
		<category><![CDATA[A1000]]></category>
		<category><![CDATA[Antivirus]]></category>
		<category><![CDATA[Nemean]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/602</guid>
		<description><![CDATA[CSOonline.com has a good article about some emergent technology (the A1000) designed to create rules dynamically to detect malware. There isn&#8217;t a lot of information on the technology yet but it seems that it does have strong roots in IDS tech, which is exactly what I&#8217;ve been hoping will happen to AV. It sounds like [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/602/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Your AV *still* sucks and you know it&#8230;</title>
		<link>http://mcwresearch.com/archives/591</link>
		<comments>http://mcwresearch.com/archives/591#comments</comments>
		<pubDate>Thu, 03 Jan 2008 16:01:46 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/591</guid>
		<description><![CDATA[I posted an article back in April of &#8217;07 bemoaning the piss-poor performance of current antivirus technology and it looks like the mainstream guys are slowly picking it up as well. According to this article by PCWorld.com, their tests showed that &#8220;the best performer detected only one in four new malware samples.&#8221; Catching 25% of [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/591/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Evaluating malware from a network perspective</title>
		<link>http://mcwresearch.com/archives/469</link>
		<comments>http://mcwresearch.com/archives/469#comments</comments>
		<pubDate>Wed, 02 May 2007 03:55:38 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Intrusion Detection/Prevention]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Botnets]]></category>
		<category><![CDATA[Bots]]></category>
		<category><![CDATA[IPS]]></category>
		<category><![CDATA[IRCBot]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/469</guid>
		<description><![CDATA[A few days ago, my HIPS software blue-screened three separate machines after an update. Fearing a problem with the HIPS software, I disabled it on all three machines while I troubleshot them. Today while looking through my HIPS log like a good sec analyst, I see an interesting event logged on one of the hosts. [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/469/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
		<item>
		<title>Your AV sucks and you know it&#8230;</title>
		<link>http://mcwresearch.com/archives/451</link>
		<comments>http://mcwresearch.com/archives/451#comments</comments>
		<pubDate>Mon, 02 Apr 2007 20:59:19 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/451</guid>
		<description><![CDATA[I&#8217;ve been conscious of the inadequacies of our AV solution for a while now and have dedicated FY08 to fixing that. However, there isn&#8217;t really an easy question to the answer our AV sucks. Do I buy a similar solution from a different vendor? Do I scrap AV altogether and try a completely new approach? [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/451/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
		<item>
		<title>Modern Antivirus Sucks</title>
		<link>http://mcwresearch.com/archives/344</link>
		<comments>http://mcwresearch.com/archives/344#comments</comments>
		<pubDate>Mon, 13 Nov 2006 15:19:12 +0000</pubDate>
		<dc:creator>Michael</dc:creator>
				<category><![CDATA[AV sucks]]></category>
		<category><![CDATA[Rant]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Antivirus]]></category>

		<guid isPermaLink="false">http://mcwresearch.com/archives/344</guid>
		<description><![CDATA[Its about time antivirus software as we know it gets a steroid injection. Anyone who has recently uploaded a suspect file to VirusTotal.com knows that in most cases, only a few of the AV engines produce consistent results. The other day I came some malicious behavior being blocked by my HIPS software. I uploaded the [...]]]></description>
		<wfw:commentRss>http://mcwresearch.com/archives/344/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

