RE: [Full-Disclosure] AV Naming Convention

From: Clairmont, Jan M (jan.m.clairmont_at_citigroup.com)
Date: 08/10/04

  • Next message: Todd Towles: "RE: [Full-Disclosure] AV Naming Convention"
    To: <full-disclosure@netsys.com>
    Date: Tue, 10 Aug 2004 14:00:53 -0400
    
    

    IT would be an automated naming based on first time of discovery and reporting, there could be aliases added for the bugger.
    This could be for searching for Mydoom.b Mydoom.c etc. variant rather trying t search for a name like Virus20040908.19:24:31.8843 time stamped variants.

    Similar or equal virus would later be eliminated or archived for
    information. Standard record stamping for a database like Oracle. Maybe Oracle could be persuaded to provide an
    international database, great public service, providing needed
    information to reduce spam, and virus spreading etc.

    Good questions, good answers out there.
    Jan Clairmont
    Firewall Administrator/Consultant

    -----Original Message-----
    From: full-disclosure-admin@lists.netsys.com
    [mailto:full-disclosure-admin@lists.netsys.com]On Behalf Of Randal, Phil
    Sent: Tuesday, August 10, 2004 11:07 AM
    To: full-disclosure@netsys.com
    Subject: RE: [Full-Disclosure] AV Naming Convention

    > I have to agree with Todd, the naming convention is now right
    > useless for the normal population and make keeping up with
    > viruses on a corporate level that much harder. AV companies
    > are always trying to beat the other company and this leads to
    > very little information sharing between the companies on new
    > viruses, etc.
    >
    > Maybe a foundation should be created. This foundation could
    > give a seal of approval to all AV corporations that join in.
    > We are starting to make rules for patch management over at
    > patchmanagment.org. Why couldn't a group work with AV names
    > and the first company that finds and IDs it correctly gets to
    > name it in the foundation. Just a dream, I would guess.

    This completely misses the point. When a new virus is discovered, it is
    essential that there is a RAPID response to the threat. The idead of
    handing the critter over to a committee to decide it's name is, quite
    frankly, plain bonkers. I for one would rather all the antivirus
    vendors came up with their own names if it meant that
    detection/disinfection patterns came out hour earlier.

    Cheers,

    Phil

    ----
    Phil Randal
    Network Engineer
    Herefordshire Council
    Hereford, UK
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html
    

  • Next message: Todd Towles: "RE: [Full-Disclosure] AV Naming Convention"

    Relevant Pages

    • Re: Last Page Encyclopedia of the 20th Century quiz
      ... widely read war correspondent. ... the discovery of the alpha and beta particles. ... Germany). ... poison gas for the first time. ...
      (rec.games.trivia)
    • Re: Equivalent tools.h++
      ... usenet post, in particular when you are asking for help. ... your first time doing this, I'm letting you know in a nice way. ... Sybren, if you're interested, google reveals: ... searching for what you want. ...
      (comp.os.linux.development.apps)
    • Re: Minimum Hardware W2K setup
      ... Before repling the first time, I could not find the Win2k min sys ... requirements by searching the Microsoft site, ... > challenge to revive old machines to work on some late ...
      (microsoft.public.win2000.setup)
    • Re: IISadmpwd in IIS 5.0
      ... Try searching www.microsoft.com/support and maybe www.iisfaq.com ... > next logon then they cannot log back in to change it. ... > password must be changed before logging on the first time. ...
      (microsoft.public.inetserver.iis.security)
    • Counting occurences of a value tied to unique IDs
      ... I've hit a wall on summarizing some GIS data. ... I've tried searching ... this is the first time the ID number has shown up (obviously I must ... this can be done without resorting to a macro. ...
      (microsoft.public.excel)