Feeds

Symantec under attack over security patents

Latest virus update debate

  • alert
  • submit to reddit

Protecting against web application threats using SSL

Symantec has stirred up a controversy in the anti-virus community by filing two patents which cover its method for updating anti-virus software and definitions incrementally.

The patents, filed last year but only publicised this week, concern technology which allows users to download only those incremental virus definitions that are new since their last update, thereby saving time and resources.

Symantec said the patents refer to its "micro-definition architecture" system which is integrated into Norton AntiVirus 2001, Norton AntiVirus 2000 and Norton AntiVirus 5.0, as well as Symantec's corporate anti-virus products. Microdefinitions enable LiveUpdate, Symantec's schedulable and automatic update mechanism, to run up to four times faster.

This makes a lot of sense and indeed technology that works in a similar way is included is technology form McAfee and Trend, to name but two other anti-virus vendors.

It's also worth noting that the ability to download files that allow incremental patching of existing running software has been available for many years on Unix and Linux systems - and what Symantec is doing seems only to be "fine-tweaking" this.

In a statement, Symantec said the patents could also be applied to technology involved in the "update general computer readable files, which may include data files, program files, database files, graphics files, or audio files".

Dan Schrader, former chief security analyst at Trend Micro, said the patents are very broadly drawn and he suggested they had been filled in continuance of legal battle between Symantec and McAfee that has been dragging on for almost ten years.

"These are broad sweeping claims but its possible the patents would affect the incremental updates that are used by other vendors," said Shrader. "Patents are normally very broad and through litigation they are whittled down, really this just a continuation of the bad blood between McAfee and Symantec."

Graham Cluley, senior technology consultant at Sophos, said: "I don't believe this will hold water - you can do incremental updates in various ways. The patents don't come to much."

Symantec admits that software updating is old hat but claims that it is patenting technology which takes a different approach to the problem.

For anybody interested in taking a closer look at the patents look up US patent US6052531 for multi-tiered incremental software updating technology and patent US6167407 for backtracked incremental updating. ®

External Links

Symantec's press release on the patents
Symantec's patent

Related stories

Anti-virus becoming less important than content control
Encryption vs anti-virus
Users haven't learned any lessons from the Love Bug
Search engine veteran poo-poos AltaVista patent claims

Reducing the cost and complexity of web vulnerability management

More from The Register

next story
Infosec geniuses hack a Canon PRINTER and install DOOM
Internet of Stuff securo-cockups strike yet again
Apple Pay is a tidy payday for Apple with 0.15% cut, sources say
Cupertino slurps 15 cents from every $100 purchase
Israeli spies rebel over mass-snooping on innocent Palestinians
'Disciplinary treatment will be sharp and clear' vow spy-chiefs
YouTube, Amazon and Yahoo! caught in malvertising mess
Cisco says 'Kyle and Stan' attack is spreading through compromised ad networks
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
Greater dev access to iOS 8 will put us AT RISK from HACKERS
Knocking holes in Apple's walled garden could backfire, says securo-chap
Microsoft to patch ASP.NET mess even if you don't
We know what's good for you, because we made the mess says Redmond
NORKS ban Wi-Fi and satellite internet at embassies
Crackdown on tardy diplomatic sysadmins providing accidental unfiltered internet access
prev story

Whitepapers

Providing a secure and efficient Helpdesk
A single remote control platform for user support is be key to providing an efficient helpdesk. Retain full control over the way in which screen and keystroke data is transmitted.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Security and trust: The backbone of doing business over the internet
Explores the current state of website security and the contributions Symantec is making to help organizations protect critical data and build trust with customers.