Risk
7/5/2011
07:29 PM
50%
50%

End-User Security: SMBs Prefer Invisibility

Social media and mutating malware have changed the threat landscape, prompting smaller companies to list education and security users don't notice as top needs, Symantec found during the Endpoint Protection 12 public beta.

Strategic Security Survey: Global Threat, LocalPain
Strategic Security Survey: Global Threat, Local Pain
(click image for larger view and for full slideshow)
IT pros at small and midsize businesses still want an antivirus program, but they don't want their end users to know it's there.

That was among the key takeaways from Symantec's public beta for Endpoint Protection 12, which ended Tuesday with input from roughly 5,500 businesses. Both the flagship and its corresponding Small Business Edition will be fully released on Wednesday. The client-side software platform currently counts around 175 million endpoints on its security watch.

The beta found and fixed some 500 unique defects, according to Hormazd Romer, Symantec's director of product marketing for infrastructure security. Romer said in an interview that performance feedback was paramount--not simply for the sake of speed, but because administrators don't want users complaining that their anti-malware program is bogging them down.

"[Administrators] definitely want to make sure they have the tools and the ability to do things that are transparent to the end user but increase their level of protection and security," Romer said. "[Users] shouldn't even know it's there until something potentially hazardous happens."

Part of that performance comes in the form of silence: Administrators have the option to install and manage SEP 12 in the background, without the user necessarily knowing it's even there. Scans can likewise run without any notifications or other interruptions. The program's latest version blends a mix of Insight reputation database and Sonar behavioral engine and marks a continued evolution from the traditional signature-based approach.

Symantec got a related--if somewhat unexpected--round of feedback from the beta that had nothing to do with feature sets or bugs: SMBs, in particular, asked for more help with educating employees about security risks.

"The SMB customers were often really surprised by how much the threat landscape has changed," Romer said. He listed social media risks and mutating malware as two security issues that aren't well-understood within the walls of some smaller businesses. "What we heard was: Do more with education."

According to Romer, Symantec will be investing more in user education--he wasn't able to offer details, but said such programs would be vendor-neutral.

The performance and education pieces speak to the human element of IT security, particularly as social media-borne attacks and other threats based on user error increase in frequency.

Romer said SMB beta users currently using a competing product also voiced concerns about the costs associated with switching vendors. Starting Wednesday, Symantec will knock 70% off the price tag of a three-year subscription for firms with fewer than 500 employees. Just over half of the beta testers indicated they used a security program from a different provider.

Existing customers should get a smoother upgrade ride than in the past. Romer acknowledged the transition between versions 10 and 11 was rocky for some companies, and the "silent" approach is applicable to the upgrade process as well.

"Quite frankly, four years ago it was a painful process," Romer said, adding that the move to SEP 12 should be much simpler. "The full version upgrade feels just like a maintenance update."

You can't afford to keep operating without redundancy for critical systems--but business units must prioritize before IT begins implementation. Also in the new, all-digital InformationWeek SMB supplement: Avoid the direct-attached storage trap. Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: This is a secure windows pc.
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.