<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>VentureBeat &#187; AV</title>
	<atom:link href="http://venturebeat.com/tag/av/feed/" rel="self" type="application/rss+xml" />
	<link>http://venturebeat.com</link>
	<description>News About Tech, Money and Innovation</description>
	<lastBuildDate>Wed, 19 Jun 2013 12:18:59 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='venturebeat.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://0.gravatar.com/blavatar/c6d8c27ffa1c5a7f106f97e434437baf?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>VentureBeat &#187; AV</title>
		<link>http://venturebeat.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://venturebeat.com/osd.xml" title="VentureBeat" />
	<atom:link rel='hub' href='http://venturebeat.com/?pushpress=hub'/>
<copyright>Copyright 2013, VentureBeat</copyright>		<item>
		<title>Investor: Symantec and McAfee need to scrap anti-virus roots and pivot</title>
		<link>http://venturebeat.com/2013/02/28/ted-schlein-symantec-mcafee/</link>
		<comments>http://venturebeat.com/2013/02/28/ted-schlein-symantec-mcafee/#comments</comments>
		<pubDate>Thu, 28 Feb 2013 21:02:34 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[anti-virus software]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[botnets]]></category>
		<category><![CDATA[botwalls]]></category>
		<category><![CDATA[firewalls]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=630835</guid>
		<description><![CDATA[<p>Symantec and McAfee need to stop focusing on anti-virus software and start solving bigger problems or they run the risk of becoming obsolete, says KPCB's Ted&#160;Schlein.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=630835&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.files.wordpress.com/2013/02/ted-schlein.jpg" target="_blank"><img class="aligncenter size-full wp-image-630887" alt="Ted Schlein" src="http://venturebeat.files.wordpress.com/2013/02/ted-schlein.jpg?w=655&#038;h=520" width="655" height="520" /></a></p>
<p>Ted Schlein, investor with Kleiner Perkins Caufield and Byers, built one of the first anti-virus products at Symantec. Today, he says the likes of Symantec and McAfee will run out of gas if they don&#8217;t get rid of their anti-virus divisions.</p>
<p>&#8220;They will either need to realize their core anti-virus business is going away and make massive shifts, or they will continue to lose market share,&#8221; said Schlein at the RSA Conference in San Francisco this week. &#8220;You&#8217;ve got to change with the times. You can&#8217;t be static in security,&#8221; he said.</p>
<p>The security community is starting to look down on anti-virus technology simply because such tools don&#8217;t get any better until you get hacked. Traditionally, anti-virus software looks at digital signatures to determine whether or not the file entering your system is malware or safe. But it only learns that bad signature if it has seen it. Any new pieces of malware slip in under the radar.</p>
<p>Companies like Symantec and McAfee are running the risk of becoming irrelevant if they don&#8217;t change course. Both companies dabble in mobile security and are trying to figure out the answer to the bring-your-own-device (BYOD) trend. But Symantec, as Schlein noted, has more pressure to pivot than McAfee, which is owned by Intel. In the end, Intel can decide what to do with McAfee&#8217;s technology &#8212; and employees &#8212; whereas Symantec is still independent.</p>
<p>Other companies have tried behavioral anti-virus techniques, or studying the typical actions a piece of malware performs to stay relevant. For the most part, however, the overall anti-virus market seems to be slowly becoming the kid no one wants to play with.</p>
<p>&#8220;I believe security has to be done from the inside out, not outside in,&#8221; said Schlein.</p>
<p>He also said we should do away with firewalls. In fact, he won&#8217;t invest in any. Instead, he said, we should focus on protecting the information on the inside of the system &#8212; care less about what gets into our systems and more about stopping it from executing once it&#8217;s there.</p>
<p>This is especially important in the days of automated attacks, which Schlein said are some of the scariest threats in the industry today.</p>
<p>Botnets are able to storm your system, they&#8217;re cheap to use, and they don&#8217;t require much heavy lifting on the criminal&#8217;s part. Botnets are a huge threat because they let hackers be fast and more economical in attacks, say against banks, that could lead to big financial gains.</p>
<p>Schlein suggests the industry forget about firewalls and instead build &#8220;botwalls&#8221; that don&#8217;t try to keep the bots at bay but instead break them down once they&#8217;re on the inside.</p>
<p>&#8220;A botwall will be able to figure out these automated attacks,&#8221; he explained. &#8220;You need to look at these automated bots and how they work. You&#8217;re not trying to stop a bot from executing, you&#8217;re trying to stop a bot from being successful.&#8221;</p>
<p><em>Image via Meghan Kelly/VentureBeat</em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=630835&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/02/28/ted-schlein-symantec-mcafee/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/02/ted-schlein.jpg?w=160" /><source url="http://venturebeat.com/2013/02/28/ted-schlein-symantec-mcafee/">Investor: Symantec and McAfee need to scrap anti-virus roots and pivot</source>
		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/02/ted-schlein.jpg" medium="image">
			<media:title type="html">Ted Schlein</media:title>
		</media:content>
	</item>
		<item>
		<title>New malware sleeps its way into financial institutions</title>
		<link>http://venturebeat.com/2013/02/05/fireeye-nap-malware/</link>
		<comments>http://venturebeat.com/2013/02/05/fireeye-nap-malware/#comments</comments>
		<pubDate>Tue, 05 Feb 2013 21:08:10 +0000</pubDate>
		<dc:creator>Meghan Kelly</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[AV]]></category>
		<category><![CDATA[featured]]></category>

		<guid isPermaLink="false">http://venturebeat.com/?p=617339</guid>
		<description><![CDATA[<p>FireEye detected a new malware called Nap that evades antivirus software by going to "sleep." It was found attacking financial institutions and has the power to steal&#160;information.</p>
<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=617339&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://venturebeat.files.wordpress.com/2013/02/nap.jpg" target="_blank"><img class="aligncenter size-full wp-image-617366" alt="Nap" src="http://venturebeat.files.wordpress.com/2013/02/nap.jpg?w=711&#038;h=472" width="711" height="472" /></a></p>
<p><a href="http://blog.fireeye.com/research/2013/02/an-encounter-with-trojan-nap.html" target="_blank" target="_blank">FireEye discovered</a> a new kind of malware today that thwarts antivirus software by, well, taking a nap. Nap, as it&#8217;s called, was found attacking financial institutions and hides hackers&#8217; identities in the same way <a href="http://venturebeat.com/2013/01/31/chinese-hackers-bring-cyberwarfare-to-the-new-york-times/" target="_blank">the<em> New York Times</em>&#8216; hackers</a> stayed anonymous.</p>
<p>Currently, researchers are not sure how it enters your system, but they consider it a &#8220;malicious downloader&#8221; that sneaks in under the radar by putting itself to sleep. That is, many antivirus companies use what is called automated analysis systems. These systems watch a sample of whatever happens to be coming into your computer at that point in time and sees if it needs to quarantine anything. This screening process generally lasts seconds, according to FireEye senior malware researcher Abhishek Singh.</p>
<p>&#8220;Nap stops its execution for 10 minutes. So automated analysis system will time out and will not be able to capture its malicious behavior,&#8221; Singh told VentureBeat in an email.</p>
<p>Once in your system, Nap downloads a file called newbos2.exe that is considered an &#8220;information stealer.&#8221; FireEye found Nap</p>
<p>The malware writers protect themselves in a similar way to that of the attackers behind the New York Times hack. Both use a the Fast Flux method, which hackers use to hide their location by using a number of IP addresses from all over the globe. Singh explained that simply because the IP addresses are coming from locations far away from each other, it takes time to discover which, if any, is the right one.</p>
<p>Singh emphasized, however, that law enforcement has no evidence that the two attacks are connected.</p>
<p><em><a href="http://www.shutterstock.com/pic-109152140/stock-photo-cute-little-girl-having-an-afternoon-nap-in-her-bed.html" target="_blank" target="_blank">Napping child image</a> via <a href="http://www.shutterstock.com/" target="_blank" target="_blank">Shutterstock</a></em></p>
<br />Filed under: <a href='http://venturebeat.com/category/security/'>Security</a>  <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=venturebeat.com&#038;blog=342986&#038;post=617339&#038;subd=venturebeat&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://venturebeat.com/2013/02/05/fireeye-nap-malware/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	<enclosure url="http://venturebeat.files.wordpress.com/2013/02/nap.jpg?w=160" /><source url="http://venturebeat.com/2013/02/05/fireeye-nap-malware/">New malware sleeps its way into financial institutions</source>
		<media:content url="http://1.gravatar.com/avatar/a73335ff3a637d11555a46ba2b112ded?s=96&#38;d=http%3A%2F%2F1.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">mkel31</media:title>
		</media:content>

		<media:content url="http://venturebeat.files.wordpress.com/2013/02/nap.jpg" medium="image">
			<media:title type="html">Nap</media:title>
		</media:content>
	</item>
	</channel>
</rss>
