Home > Security Tips > Security Buyer's Guide > Ain't misbehavin': Security tools watch behavior to stop new threats
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY BUYER'S GUIDE

Ain't misbehavin': Security tools watch behavior to stop new threats


Robert Scheier
11.20.2002
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Who would you rather have screening the fellow passengers on your plane: A security guard who is only checking for the names of known terrorists, or a security guard who is looking for suspicious behavior from anyone?

Ideally, of course, a security guard should watch for both things. And that's the idea behind "behavior-based" security tools, which monitor the actions taken by files (on a server or PC) and packets (on a network) and raise a red flag if those actions look suspicious. The best defense, according to analysts, is a combination of behavior-based security tools and the "signature-based" approach used by most antivirus software. Indeed, a number of host and network-based intrusion-detection systems rely on both signature-based and behavior-based protection.

Sign here

Signature-based tools compare files or packets to a list of "signatures" of specific files or packets known to represent a threat. (Each signature is the specific arrangement of zeros and ones that make up a file.) Behavior-based tools compare the behavior of files or network packets to a list of accepted (or of suspicious) activities and take action (either blocking the activity or generating a warning) if they see a behavior that looks suspicious or is forbidden.

In general, signature-based tools are best at identifying and repelling known threats, while behavior-based are best for fighting new threats that haven't made it onto a list of known threat signatures. Most behavior-based tools come with a standard set of policies for which behaviors are allowed (or are suspicious), while also allowing administrators to create their own policies.

Some behavior-based tools operate on servers or PCs and usually examine calls, or requests, from applications to the operating system and compare them with a list of accepted (or forbidden) behaviors. These include StormWatch 3.0 from Okena Inc. and Harris Corp.'s Stat Neutralizer. Some tools specialize in protecting Web servers, including eEye Digital Security's Secure IIS, Entercept Security Technologies' Web Server Edition (which combines behavior-based and signature-based protection), Pelican Security Ltd.'s WaveBreaker and Sanctum Inc.'s Web AppShield 4.0.

Other behavior-based tools work on networks, examining traffic flow and looking for anomalies such as unusual traffic to or from a certain IP address, a port on a server or an application. They include Lancope Inc.'s StealthWatch appliances and IntruVert Network's IntruShield, which combine signature and behavior-based monitoring.

Some tools span both servers and networks, such as Internet Security Systems Inc.'s RealSecure Protection System. Finjan Software Inc. uses behavior-based monitoring in its SurfinGate tools for e-mail and Web gateways and its SurfinShield software for corporate PCs, but also bundles the McAfee Security signature-based antivirus product into its products.

Ted Doty, director of product management for Okena, claims that behavior-based tools, which run on a PC or server, can find many of the same threats as signature-based antivirus tools. That's because many viruses attempt the same sort of malicious behavior, he says, such as to "open the Outlook address book to send outbound mail to everyone in the address book. If you're intercepting operating system calls, it's very easy to see and prevent" attacks such as this.

Unlike antivirus tools, which look mainly at contents of files, some behavior-based tools can also examine malicious Java scripts or executable files that can be embedded in the HTML stream downloaded by a Web browser.

In a different approach to "behavior-based" security, Authentor Systems Inc. examines users' behavior (such as when, how often or from where they log in) to ensure they are who they say they are.

Neither signature nor behavior-based tools are silver bullets, observers say. Antivirus tools are a useful complement to behavior-based tools, according to Doty, because they can perform follow-up work such as "disinfecting" a system by removing or quarantining the viruses. And while behavior-based security tools are better than signatures are at stopping new threats, says Pete Lindstrom, Research Director at Spire Security, they could keep users from doing legitimate work if they're set to block too many types of behavior. That's why he recommends choosing tools with robust monitoring and logging capabilities so administrators can analyze behavior on the network before they block it.

"In theory, one type of (security tool) without the other would be sufficient," says Lindstrom. But practically speaking, he says, "you need both."

About the author:
Robert L. Scheier writes about security from Boylston, Mass. He can be reached at rscheier@charter.net


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Infrastructure and Network Security,   Tools and Utilities,   Security Buyer's Guide,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Tools and Utilities
Best practices for patch management
Q&A: Advanced intrusion defense
Audio webcast: Advanced intrusion defense
Presentation: Advanced intrusion defense
Intrusion defense
Taking aim
Comparison chart: Target-based NIDS
Vulnerability scanning with Nessus
Network security monitoring
Security product and tool reviews

Security Buyer's Guide
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
Access security with KoolSpan's SecurEdge
NetChk Protect 5.5
Biometrics: Best practices, future trends
2006 Products of the Year: Emerging Technologies
Secure Sphere 2.0
Scan & Deliver: SLAs force service providers and outsources to hit the mark ... or hit the road
Secure remote access: SSH Tectia Manager
Spycatcher Enterprise 3.2
Configuresoft's Enterprise Configuration Manager v4.7

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts