VIRUS HUNTERS
It has been 12 years since the first real Internet virus scare. On Nov. 2, 1988, Cornell University graduate student Robert Morris unleashed a 'worm' program that used e-mail protocols to propagate itself across the Internet.
By Kevin Jonah
Special to GCN
It has been 12 years since the first real Internet virus scare. On Nov. 2, 1988, Cornell University graduate student Robert Morris unleashed a 'worm' program that used e-mail protocols to propagate itself across the Internet.
It was a sophisticated program, written in C, and its primary effect was to slow Internet e-mail to a crawl.
The Morris worm was a mere sneeze compared with what the latest crop of malicious programs has done to computer systems worldwide in the last two years.
![]() | Computer attacks have come a long way in the last 12 years, but so has antivirus software |
Diagnose the problem
Tips for buyers |
|
Kevin Jonah is a network manager and free-lance technology writer in Maryland.
| Company | Product | Type of product | Detection method | Platforms | Update service | Checks attachments before launch | Detects script files in e-mail | Warning before launching scripts | Deployment tools | Price |
| GFI Fax & Voice USA Cary, N.C. 888-243-4329 www.gfi.com | MailEssentials for Exchange/SMTP | E-mail security, content checking,and antivirus gateway that removes all types of e-mail threats before they are delivered to users. | Content screening | NT, Win 2000 | Automatic | Yes | Yes | Quarantines script files and inline scripts | Deployed at mail server | $275 up for 10 users; government discounts available |
| InDefense Inc. Santa Cruz, Calif. 877-472-3372 www.indefense.com | Achilles' Shield | Behavior-based intrustion detection | Analyzes any unknown code, alerts users of intrusive tendencies, can certify good known code | NT, Win9x, Win 2000 | Not required; upgrades available | Yes | Yes | Yes | Network administration program with log-in scripting | $29 per user, $1,500 for 100 users; $2,500 for 1,000 users |
| Network Associates Inc. Santa Clara, Calif. 888-847-8766 www.nai.com | McAfee Active Virus Defense | Scans for viruses at Internet gateway, groupware server, file server, desktop PC and PDA | Scans for known viruses by signature and by heuristic analysis of the code | NT 4.0, Win9x, Win 2000, WinCE, Palm OS, NetWare, Unix, Linux, MS-DOS Microsoft Exchange, Lotus Domino | Automatic, with options for scheduling and for selecting download locations | Yes; also checks them before they reach recipient | Yes, at the Internet gateway e-mail server | No | Through McAfee ePolicy Orchestrator, or through software deployment tools such as Microsoft SMS | $70 up per seat for 2-year license; $105 up per seat for perpetual license; both prices 50-100 users; discounts for larger volumes |
| Roxio Inc. Milpitas, Calif. 408-259-7694 www.roxio.com | GoBack Enterprise Edition 2.23 | A system undo software package; does not screen for viruses, but can return a system to pre-virus state | No | NT, Win9x, Win 2000, Win Me | Updates on Web site | No | N/A | No | Network installation | $63 for 1 user; $265 for 5; $487 for 10; $2,095 for 50 $3,832 for 100 $14,995 for 1,000 |
| Sophos Inc. Wakefield, Mass. 781-213-3456 www.sophos.com | Sophos Anti-Virus (OS-based) | SWEEP provides on-demand and scheduled virus checking of files on file servers or workstations; InterCheck provides local on-access virus- checking on workstations and server-based on-access virus- checking for networked workstations; Sohpos Anti-Virus Interface allows third-party software developers to integrate their firewalls, gateways and similar applications | Scans for known viruses by signature, using file scanning and pattern recognition | For servers: NT, Win 2000, NetWare, OS/2,Unix, OpenVMS; For clients: Win9x, NT,Win 2000, OS/2, Mac OS, MS-DOS Windows 3.1 | Yes | Yes | No | Will not let a known malicious script run | Via central installation on network and provided admin tool | $1,495 for 50 users |
| Sybari Software Inc. East Northport, N.Y. 631-630-8500 www.sybari.com | Antigen for Exchange; Antigen for Lotus Notes | Mail server virus protection provides mail attachment filering and content checking | Content screening | NT and Win 2000 with Exchange Server 5.0 and up; NT, AIX and Solaris with Lotus Notes | Automatic or on-demand | Yes | Yes | Yes, will quarantine scripts | None (through mail server) | $4,995 for 250 users with a two-year license |
| Symantec Corp. Cupertino, Calif. 408-253-9600 www.symantec.com | Norton AntiVirus Coporate Edition 7.5 | Desktop and server virus detection and prevention; allows administrators to centrally deploy to clients and schedule or manually launch scans; provides centralized event logging | Scans for known viruses by signature, using file scanning and pattern recognition | MS-DOS, Win 3.x, Win9x, NT, Win 2000, NetWare | Scheduled and on-demand | On Notes, Outlook, cc:Mail | Yes | No | Through management console or HTTP intranet deployment | Based on site licensing requirements |
| Trend Micro Inc. Cupertino, Calif. 800-228-5651 www.antivirus.com | Interscan Virus Wall | Internet gateway; stops viruses and other malicious code in SMTP, HTTP and FTP traffic before it gets to servers and users; optional eManager adds spam blocking, content filtering, and e-mail scheduling | Scans for malicious activity using signature pattern matching or behavioral analysis | NT, Solaris, Linux, HP-UX | Scheduled or on-demand updates via the Internet or regular mail | Yes | Yes | No | Managed through browser or Windows-based management console | $725 up for 25 users (GSA) |
| Scan Mail for Exchange; ScanMail for LotusNotes | ScanMail for Exchange detects and cleans viruses from inbound and outbound e-mail on the Exchange server in real time and provides manual and scheduled scans of the informationstore database; ScanMail for Lotus Notes detects and removes viruses hidden in Notes mail, shared databases, and during Notes replication | Scans for malicious activity using signature pattern matching or behavior analysis | NT 4.0 and Win 2000 for Exchange; NT, Solaris, OS/390, AIX and OS/2 for Notes | Scheduled or on-demand via the Internet or regular mail | Yes | Yes | No | Managed through browser or Windows-based management console | $600 up for 25 users (GSA) |





