The Channel logo

News

By | John Leyden 17th July 2007 11:34

Norton labels Nasa app as adware

Cupertino, we have a problem

Symantec has updated its anti-virus definition files after a duff update falsely identified two open source packages as adware.

Norton Anti-Virus updates issued on Sunday falsely detected both Filezilla, open source FTP client, and NASA World Wind, an open source virtual globe developed by NASA and others, as the parasitic program Adware-Cpush. An update issued on Monday fixed the problem.

False positives are well known as something of an Achilles heel for signature-based malware detection. Problems crop up regularly.

As the SANS Intitute's Internet Storm Centre notes, the pressure on anti-virus vendors to release signature updates quickly is growing. Inevitably, this means testing, particularly against more unusual software packages, becomes (at best) perfunctory.

If VXers exploited this behaviour it might be possible to create strains of malware that matched the signature of "safe" files. "Manipulating malware to maximise false-positives could be an entertaining (and certainly painful) way to wreak havoc. Some basic research exists on this theory already, though nothing ready for market," SANS researcher John Bambenek writes. ®

comment icon Read 10 comments on this article alert Send corrections

Opinion

Windows 10 on Surface 3

Tim Anderson

It's do-or-die for Microsoft's new operating system on 29 July
Wine Taps by N Wong, Flickr, CC 2.0 License

Simon Sharwood

Clouds sell compute by the glass. On-premises kitmakers want to sell wine-as-a-service

Greg Knieriemen

Privacy, security, information sovereignty, what we all want, right?
Microsoft's Joe Belfiore, speaking at Build 2015

Andrew Orlowski

Redmond devotees may as well have demanded manga desktop wallpaper

Features

Time to pull out the magnifying glass to swot up on those Ts&Cs
Android icon desktop toys
Nice devices, now speak 'enterprise' to me
Standard Form 86 reads like a biography of each intelligence worker
Protestor barricade image via Shutterstock
Breaking through the hardware barricades to a new network state