Home > Networking Tips > Network Security > Maximizing the effects of anti-spyware software
Networking Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY

Maximizing the effects of anti-spyware software


Ed Tittel
03.24.2005
Rating: -4.67- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Multilayered security systems stem from one thing: If some protection is good, then more protection may very well be better. That's why installing and maintaining antivirus software in areas where files or messages routinely enter and exit organizations is the right thing to do. This includes installing the software on not only servers and workstations, but also routers, firewalls and gateways.

Internet service providers and other organizations deliberately perform the same kinds of screening and filtering on traffic for the same reason. They use black hole lists, black and white lists and all kinds of other techniques to look for and block unwanted e-mail, viruses, spyware and adware at every opportunity.

Don't go it alone

A recent study by the University of Illinois' Eric Howes on the efficacy of anti-adware software (which covers both adware and spyware) showed that no single package could do the whole job by itself. Howes reported that some anti-adware software he tested in October 2004 was able to detect less than half of a list of adware and spyware items he deliberately introduced onto a test machine, and that even the best of these tools couldn't detect more than 75%.

Howe's results are sobering. But they confirm that no single tool by itself suffices to detect and destroy every adware or spyware item. Given the ferocious rate of new introductions and the high mutation rate on existing adware/spyware items, it's too much of a moving target for any single vendor or software developer to do it all.

Most experts recommend that you install and use only a single package to watch for and block spyware and adware in real time (otherwise, conflicts or instability might result if two real-time monitors started battling for precedence in the bowels of your computer's operating system). But those same experts also recommend that you back up that tool with regular scans using one or more other anti-adware packages, so as to catch with one what the other misses. In fact, many newsgroups and forum postings on this subject regularly mention favorite combinations of packages, among which Webroot Software Inc.'s Spy Sweeper, Patrick Kolla's Spybot -- Search and Destroy, and LavaSoft AB's Ad-Aware SE Personal frequently appear in various combinations.

Interestingly, the highest-ranked package, Giant AntiSpyware, was recently acquired by Microsoft and re-released as Microsoft AntiSpyware (currently available in only a free beta version).

Naturally, I was intrigued to read these report results. I decided to dig into my own PCs to look for evidence of unwanted software, suspicious files and other signs of adware or spyware infestation.

Though my results from the half-dozen machines I use for testing and production purposes are far from conclusive, I was encouraged by the results. Other than a few traces of some drivers for devices no longer installed on a couple of machines and a whole slew of "tracking cookies," my search turned up no evidence of uncaught adware or spyware traces. (My computers are all hooked into the Internet, and all but one machine was already covered by two or more anti-adware packages.)

If you are interested in applying my approach, see my Check IT list on SearchSMB.com. There is a small collection of tools anyone can use to inspect their PCs in great detail for signs of adware, spyware and even some Trojans and viruses. These include trace collection or process reporting tools such as HijackThis, WinTasks Professional and Security TaskManager, as well as trace analysis tools Help2GoDetective and HijackThis Analysis. Keep in mind there is a certain amount of grunt work needed when checking objects, DLL or executable file names that HiJack This or the other programs find.

Internet resource

The easiest way to do this is on the Web. Google is a big help here. Though the analysis tools are helpful, sometimes a certain amount of common sense is also required to figure out what's benign, desirable or suspicious. That said, it's an entirely doable, if time-consuming, task.

But while it's undoubtedly true that no single anti-adware package detects or removes all such malware, it's encouraging that most paired combinations of good anti-adware tools seem to result in systems with few or no traces of uncaught and unwanted software. If you make an anti-adware "buddy system" part of your system setup and maintenance routines, you should be able to avoid encountering the potential ill effects that can occur when something slips through your layers of protection.


Ed Tittel is a full-time freelance writer, trainer, and consultant who specializes in information security, markup languages and networking technologies. He's a regular contributor to numerous TechTarget Web sites, technology editor for Certification Magazine, and he crafts twice-monthly Web content for CramSession called "Must Know News." He's also the author of a Wiley book released in December 2004 entitled The PC Magazine Guide to Fighting Spyware, Viruses, and Malware (ISBN: 0764577697).

Do you have comments on this tip? Let us know.


Rate this Tip
To rate tips, you must be a member of SearchNetworking.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Engineering
How to test LAN switch energy efficiency
Testing LAN switch power consumption: A best practices guide
Desktop virtualization network requirements
Preventing hacker attacks with network behavior analysis IPS
Internal cloud computing on the cheap: Free automated provisioning?
Improved storage performance without adding more disk
Troubleshooting -- 'Network Know-How' Chapter 17
Windows Server 2008 IP routing configuration: Static and dynamic RIPv2
Understand Windows tracert output to troubleshoot network connectivity
Using tracert and TTL to troubleshoot network connectivity problems

Network Security
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
Preventing hacker attacks with network behavior analysis IPS
Rogue access points: Preventing, detecting and handling best practices
The TPM chip: An unexploited resource for network security
Shifting defenses and dynamic perimeters challenge network security
Compliance in a virtualized world: Server virtualization and NAC security
Securing the new network architecture: Security for distributed, dynamic networks
How to configure Windows Server 2008 advanced firewall MMC snap-in
USB storage devices: Two ways to stop the threat to network security

Network Security Monitoring and Analysis
Application-specific network intrusion detection systems emerge
Anomaly-based intrusion protection configuration and installation
How can I calculate perimeter firewall throughput?
How do I find the application on my network that's dropping packets?
Integrating NAC with network security tools
Where can I find a sample security audit report? How can I run my own?
The firewall remains the network traffic cop, but its role is changing
Troubleshooting VLANs: How to monitor 802.1q tagged traffic
Poor data-loss prevention practices almost cost Intel a billion
How can I block my competitor's IP address range from my website?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
deep packet inspection (DPI)  (SearchNetworking.com)
FCAPS  (SearchNetworking.com)
Nessus  (SearchNetworking.com)
netstat  (SearchNetworking.com)
port mirroring  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Networking Solutions for Business

Alcatel-Lucent Network Business Communications Solutions

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2000 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts