Computerworld
Is security software becoming a security risk?
Security researchers believe that file-parsing bugs in security software could become a big problem.
Robert McMillan (IDG News Service)  23 November, 2007 05:34

Is the software we're using to protect ourselves from online attacks becoming a liability?

That's what Thierry Zoller believes. For the past two years, the security engineer for n.runs has taken a close look at the way antivirus software inspects e-mail traffic, and he thinks companies that try to improve security by checking data with more than one antivirus engine may actually be making things worse. Why? Because bugs in the "parser" software used to examine different file formats can easily be exploited by attackers, so increasing your use of antivirus software increases the chances that you could be successfully attacked.

Antivirus software must open and inspect data in hundreds, if not thousands, of file formats. One bug in the software that does this can lead to a serious security breach.

Zoller and his colleague Sergio Alvarez have been looking into this issue for the past two years and they've found more than 80 parser bugs in antivirus software, most of which have not yet been patched.

The flaws they've found affect every major antivirus vendor, and many of them could allow attackers to run unauthorized code on a victim's system, Zoller said.

"People think that putting one AV engine after another is somehow defense in depth. They think that if one engine doesn't catch the worm, the other will catch it," he said. "You haven't decreased your attack surface; you've increased it, because every AV engine has bugs"

Although attackers have exploited parsing bugs in browsers for years now, with some success, Zoller believes that because antivirus software runs everywhere, and often with greater administrative rights than the browser, these flaws could lead to even greater problems in the future.

The bottom line, he says, is that Antivirus software is broken. "One e-mail and boom, you're gone," he said.

Research into parsing bugs has been spurred by a heightened focus in recent years on "fuzzing" software, which is used by researchers to flood software with a barrage of invalid data in order to see if the product can be made to crash. This is often the first step toward discovering a way of running unauthorized software on a victim's machine.

A parsing bug in the way the Safari browser processed .tiff graphic files was used recently to circumvent Apple's strict controls over what software may be installed on the iPhone.

Zoller says he has been criticized by his peers in the security industry for "questioning the very glue that holds IT security all together," but he believes that by bringing this issue to the forefront, the industry will be forced to address a very real security problem.

Between 2002 and 2005, nearly half of the vulnerabilities that were discovered in antivirus software were remotely exploitable, meaning that attackers could launch their attacks from anywhere on the Internet. Nowadays, that percentage is close to 80 percent, he said.

Zoller's company sees a business opportunity here. N.runs, based in Oberursel, Germany, is building a product, code-named ParsingSafe, that will help protect antivirus software from the kind of parsing attacks that he has documented.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Computerworld Community Comments
Whitepaper

Best Practices in Lifecycle Management

This white paper compares solutions from KACE, Altiris, LANDesk, and Microsoft. Read on for best practices, functional solution comparisons and cost comparisons. Determine overall value easily and quickly.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.