BankersOnline.com
ComplianceLendingOperationsSecurityMarketingTechnologyeBanking


Learn more about

MEMBERS

Jack Henry



Bankers Systems, Inc.

Alltel Financial

Diebold



















Have a Question?
Looking for a
Product or
Service?

Our Vendor
Advisory Board



  ...an online discussion forum
  eBanking / Technology
  Is virus protection effective?

Post New Topic  Post A Reply
profile | register | preferences | faq | search

UBBFriend: Email This Page to Someone! next newest topic | next oldest topic
Author Topic:   Is virus protection effective?
thoover
Member

Posts: 6
Registered: Apr 2001

posted 04-13-2001 11:53 AM     Click Here to See the Profile for thoover   Click Here to Email thoover     Edit/Delete Message
Have there been any studies as to the effectiveness of virus protection software? It seems that most new viruses come and go by the time the software can be updated. How often are "old" or seasoned viruses circulated and caught?

IP: Logged

Andy Z
Member

Posts: 862
Registered: Oct 2000

posted 04-13-2001 12:37 PM     Click Here to See the Profile for Andy Z   Click Here to Email Andy Z     Edit/Delete Message
Abstinence is the best protection, but that isn't viable in today's environment.

You are correct in that the anti-virus definitions are only updated after the virus is released, but some move slower than others. So by the time you or I update our PCs, we might be able to avoid getting some nasty bug that started on the other side of the world and progressed as the clock advanced and people checked their e-mail.

Also, many hackers out there take an old virus, update it with downloadable programs to add some nasty twist and recirculate it. So the virus definitions you downloaded a month ago may help you out next week.

Pioneer recently sent a CD to thousands of customers. Guess what. It contained a virus.

The important thing is to update both your program and your definition files. Because someone else won't that means these things never quite go away.

------------------
Andy Zavoina
Opinions stated are not necessarily that of my employer.

IP: Logged

Mary Beth Guard
Moderator

Posts: 259
Registered: Oct 2000

posted 07-27-2001 04:39 PM     Click Here to See the Profile for Mary Beth Guard   Click Here to Email Mary Beth Guard     Edit/Delete Message
My answer to that question this week is "Evidently not." We are horrified at the number of emails carrying the W32.Sircam.Worm@mm virus/worm we have received this week from bankers!

It isn't enough to buy virus software. You have to have it configured correctly, run it constantly, update it frequently -- and you have to stay very attuned to what's out there. I used to have my software check for new virus updates every week. In this environment, I've changed it to check once each day. The loss of productivity that results from infection with some of these pieces of malicious code is just too great to risk.

If you do become aware of a particularly widespread virus, it's worthwhile to activate your phone tree to let everyone know what to watch out for. Sending an email that they may open AFTER they've already opened another email carrying the virus won't cut it.

IP: Logged

Mary Beth Guard
Moderator

Posts: 259
Registered: Oct 2000

posted 07-28-2001 09:43 AM     Click Here to See the Profile for Mary Beth Guard   Click Here to Email Mary Beth Guard     Edit/Delete Message
One more thing . . . This latest virus/worm (sircam) is also causing some infected bankers to violate the privacy of their customers. How? The worm appends a random
document from the infected PC to itself and sends this new file via email to addresses grabbed off the infected user's computer (usually, but not always, from their address book). Those files, in some instances, can be related to CUSTOMERS of the bank.

Among the infected emails I have received over the past few days from bankers have been close to a dozen which have had as the subject line things relating to file names like "Loan Memo: Mark Benali" (I altered the name to guard against exposing the customer's privacy a second time). That means I'm seeing Subject lines on the emails that say "Re: Loan request from Lazy O Ranch". If I then put in the domain name from the banker's email address, I can determine which financial institution the sender is with and I now know that Mark Benali has a loan from that bank and that Lazy O Ranch is trying to get one. If they are a community bank, it's likely I could even find their customer through an online search and if I were a con artist, I could say I was calling from the bank to discuss their loan and could social engineer all kinds of private information out of them to commit fraud with.

This is a MAJOR concern, particularly with privacy being the hot button it currently is.
Imagine for example, a banker's address book containing email addresses for everyone in a local civic group and them being sent an email whose subject line reveals that someone they know has an overdraft -- e.g. "Memo re Repeated Overdrafts on Joe Blow's account") or something similarly violative of the customer's financial privacy. A customer whose privacy was violated in that fashion would probably have a good case against the bank grounded on the theory that the bank was negligent in l) failing to maintain adequate virus protection; 2) failing to keep informed about virus threats; 3) failing to deal quickly and decisively with their computers once they became infected.

And if the banker failed to react once he had been informed that his machine was infected, heaven help him if he didn't clean off the virus.

[I got another avalanche of these email infections this morning, so I'm wound up about this issue, obviously, but as an attorney, I cannot stress strongly enough that bankers must deal with this problem!]

IP: Logged

Richard Insley
Member

Posts: 233
Registered: Oct 2000

posted 07-28-2001 08:19 PM     Click Here to See the Profile for Richard Insley   Click Here to Email Richard Insley     Edit/Delete Message
Ditto on multiple copies of W32.Sircam.Worm@mm this week. I just started using Norton's e-mail virus scan this year. Looks like that was a good choice because it picked these things up immediately.

IP: Logged

Dana Turner
Moderator

Posts: 105
Registered: Dec 2000

posted 12-20-2001 08:20 AM     Click Here to See the Profile for Dana Turner   Click Here to Email Dana Turner     Edit/Delete Message
Folks:

This is an update to the original post.

Short of unplugging the computer (which really isn't such a bad idea), subscribe to an industry-standard virus protection program (e.g., Norton, McAfee or OnTrack) that:
1. Notifies you via email when a special alert is issued;
2. Offers 24/7/365 unattended downloads of updated virus signatures and scanning engines; and
3. Has a live technician available via telephone 24/7/365.

The updated virus signatures are designed to work with updated scanning engines -- so get them both. Your IT Manager can configure your system to auto-update signatures and engines during off-peak hours.

As Mary Beth wrote -- do this at least once a day. I average 25-30 emails each day and I receive an average of eight (8) virus-laden messages each week. I've also taken to scanning my computer at least once a day -- and every time my virus checker alerts, even if it tells me that it killed the virus.

------------------
Dana Turner
Security Education Systems
danaturner@bankersonline.com
830-535-6500
Opinions expressed are always those of my employer.

[This message has been edited by Dana Turner (edited 12-20-2001).]

IP: Logged

Todd Taylor
Member

Posts: 2
Registered: Feb 2002

posted 02-04-2002 04:07 PM     Click Here to See the Profile for Todd Taylor   Click Here to Email Todd Taylor     Edit/Delete Message
As mentioned already, updating your virus definitions often will usually help catch viruses before they are sent to you. I recieved the "MyParty" virus via email and watched Norton Anti-Virus destroy it... an hour later, I got an email notifying me of the "MyParty" virus from CERT ;P

In addition to updating your virus definitions, make sure you keep-up with all the service patches on your operating systems and software, especially if you are using a Microsoft operating system (OS) or a Microsoft Office product. Many of the viruses listed above could have been prevented had everyone kept their servers and computers up-to-date... the patches are often released months before the viruses hit.

Just as I have started checking for virus definition updates more frequently, I have also started to check for service patches more frequently. I've been told that Microsoft will start releasing cummulative OS patches on a monthly basis in addition to the individual patches.

Even though checking for these patches and installing them on a lot of machines is very tedious and time consuming, the consequences are too large not to!

------------------
Sincerely,
Todd M. Taylor
Concurrency, Inc.
-Banking Service Provider

IP: Logged

All times are ET(US)

next newest topic | next oldest topic

Administrative Options: Close Topic | Archive/Move | Delete Topic
Post New Topic  Post A Reply
Hop to:

Contact Us | BankersOnline.com


Ultimate Bulletin Board 5.45c