Feeds

Symantec under attack over security patents

Latest virus update debate

  • alert
  • submit to reddit

Next gen security for virtualised datacentres

Symantec has stirred up a controversy in the anti-virus community by filing two patents which cover its method for updating anti-virus software and definitions incrementally.

The patents, filed last year but only publicised this week, concern technology which allows users to download only those incremental virus definitions that are new since their last update, thereby saving time and resources.

Symantec said the patents refer to its "micro-definition architecture" system which is integrated into Norton AntiVirus 2001, Norton AntiVirus 2000 and Norton AntiVirus 5.0, as well as Symantec's corporate anti-virus products. Microdefinitions enable LiveUpdate, Symantec's schedulable and automatic update mechanism, to run up to four times faster.

This makes a lot of sense and indeed technology that works in a similar way is included is technology form McAfee and Trend, to name but two other anti-virus vendors.

It's also worth noting that the ability to download files that allow incremental patching of existing running software has been available for many years on Unix and Linux systems - and what Symantec is doing seems only to be "fine-tweaking" this.

In a statement, Symantec said the patents could also be applied to technology involved in the "update general computer readable files, which may include data files, program files, database files, graphics files, or audio files".

Dan Schrader, former chief security analyst at Trend Micro, said the patents are very broadly drawn and he suggested they had been filled in continuance of legal battle between Symantec and McAfee that has been dragging on for almost ten years.

"These are broad sweeping claims but its possible the patents would affect the incremental updates that are used by other vendors," said Shrader. "Patents are normally very broad and through litigation they are whittled down, really this just a continuation of the bad blood between McAfee and Symantec."

Graham Cluley, senior technology consultant at Sophos, said: "I don't believe this will hold water - you can do incremental updates in various ways. The patents don't come to much."

Symantec admits that software updating is old hat but claims that it is patenting technology which takes a different approach to the problem.

For anybody interested in taking a closer look at the patents look up US patent US6052531 for multi-tiered incremental software updating technology and patent US6167407 for backtracked incremental updating. ®

External Links

Symantec's press release on the patents
Symantec's patent

Related stories

Anti-virus becoming less important than content control
Encryption vs anti-virus
Users haven't learned any lessons from the Love Bug
Search engine veteran poo-poos AltaVista patent claims

The essential guide to IT transformation

More from The Register

next story
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Chinese hackers spied on investigators of Flight MH370 - report
Classified data on flight's disappearance pinched
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
prev story

Whitepapers

Top 10 endpoint backup mistakes
Avoid the ten endpoint backup mistakes to ensure that your critical corporate data is protected and end user productivity is improved.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Backing up distributed data
Eliminating the redundant use of bandwidth and storage capacity and application consolidation in the modern data center.
The essential guide to IT transformation
ServiceNow discusses three IT transformations that can help CIOs automate IT services to transform IT and the enterprise
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.