home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!ukma!usenet.ins.cwru.edu!cert!netnews.upenn.edu!netnews.cc.lehigh.edu!news
- From: fc@turing.duq.edu (Fred Cohen)
- Newsgroups: comp.virus
- Subject: Happy anniversary to IT (PC)
- Message-ID: <0004.9211121928.AA09892@barnabas.cert.org>
- Date: 10 Nov 92 11:34:34 GMT
- Sender: virus-l@lehigh.edu
- Lines: 49
- Approved: news@netnews.cc.lehigh.edu
-
- IT has now run for 3 years without any known virus bypassing the
- defenses.
-
- Although we have made improvements over the last 3 years, it is
- somewhat amazing to us that none of the over 1500 new viruses
- discovered in the last 3 years has been able to bypass our version
- from late 1989. Many get part of the way through, and some get to the
- point where the syst is allmost unuseable, but none have gone
- undetected, and none have been unrecoverable!
-
- Generic virus defenses seem to have become reasonably matured..
-
- By the way, unlike the scanner developers, ASP has continued to
- publish the details of how to design a strong generic virus defense.
- AS a result, we have several strong competitors who are always chasing
- us, and always outselling us. The reality is that in this commercial
- world, our software copyrights do not protect us from this, and since
- Patents are too expensive and unstable in the software world of today,
- the ONLY protection that works is the protection of being owned by a
- big rich company. (With the reverse engineering ruling of late, we
- cannot even maintain any trade secrets in our software since or
- competitors are freely allowed to disassemble our software and design
- the same thing over using our methods).
-
- For the above reasons, I daily deal with the problem of providing
- information on how to build better defenses vs. protecting my income
- by keeping our techniquers secret. Unlike those at a University or a
- big company, it directly impacts my income (in a negative way) every
- time I publish a paper on virus defenses. In my opinion, everyone
- should submit their techniques to a refereed journal. The reason is
- simple.
-
- In the scanner world, a 6 month lead time is plenty, and that
- is how long (at a minimum) it takes before your article gets published
- in a journal.
-
- The only problem is the reviewers, who have historically
- published my results (and probably others as well) in non-refereed
- forums before my papers got to press. If the reviewers (who are
- anonymous) don't have the integrity to maintain the confidentiality of
- papers before they are published, the system fall apart pretty
- quickly.
-
- Oh well, I have digressed enough from my happy anniversary
- message. Have a nice malicious-virus-free day.
- FC
-
- p.s. I wish I could edit out the spelling errors before sending these
- mail messages - do you get all the ^h's on your screen too?
-