Feeds

Symantec under attack over security patents

Latest virus update debate

  • alert
  • submit to reddit

Beginner's guide to SSL certificates

Symantec has stirred up a controversy in the anti-virus community by filing two patents which cover its method for updating anti-virus software and definitions incrementally.

The patents, filed last year but only publicised this week, concern technology which allows users to download only those incremental virus definitions that are new since their last update, thereby saving time and resources.

Symantec said the patents refer to its "micro-definition architecture" system which is integrated into Norton AntiVirus 2001, Norton AntiVirus 2000 and Norton AntiVirus 5.0, as well as Symantec's corporate anti-virus products. Microdefinitions enable LiveUpdate, Symantec's schedulable and automatic update mechanism, to run up to four times faster.

This makes a lot of sense and indeed technology that works in a similar way is included is technology form McAfee and Trend, to name but two other anti-virus vendors.

It's also worth noting that the ability to download files that allow incremental patching of existing running software has been available for many years on Unix and Linux systems - and what Symantec is doing seems only to be "fine-tweaking" this.

In a statement, Symantec said the patents could also be applied to technology involved in the "update general computer readable files, which may include data files, program files, database files, graphics files, or audio files".

Dan Schrader, former chief security analyst at Trend Micro, said the patents are very broadly drawn and he suggested they had been filled in continuance of legal battle between Symantec and McAfee that has been dragging on for almost ten years.

"These are broad sweeping claims but its possible the patents would affect the incremental updates that are used by other vendors," said Shrader. "Patents are normally very broad and through litigation they are whittled down, really this just a continuation of the bad blood between McAfee and Symantec."

Graham Cluley, senior technology consultant at Sophos, said: "I don't believe this will hold water - you can do incremental updates in various ways. The patents don't come to much."

Symantec admits that software updating is old hat but claims that it is patenting technology which takes a different approach to the problem.

For anybody interested in taking a closer look at the patents look up US patent US6052531 for multi-tiered incremental software updating technology and patent US6167407 for backtracked incremental updating. ®

External Links

Symantec's press release on the patents
Symantec's patent

Related stories

Anti-virus becoming less important than content control
Encryption vs anti-virus
Users haven't learned any lessons from the Love Bug
Search engine veteran poo-poos AltaVista patent claims

Beginner's guide to SSL certificates

More from The Register

next story
Knock Knock tool makes a joke of Mac AV
Yes, we know Macs 'don't get viruses', but when they do this code'll spot 'em
Shellshock over SMTP attacks mean you can now ignore your email
'But boss, the Internet Storm Centre says it's dangerous for me to reply to you'
Why weasel words might not work for Whisper
CEO suspends editor but privacy questions remain
Feds seek potential 'second Snowden' gov doc leaker – report
Hang on, Ed wasn't here when we compiled THIS document
DEATH by PowerPoint: Microsoft warns of 0-day attack hidden in slides
Might put out patch in update, might chuck it out sooner
China is ALREADY spying on Apple iCloud users, claims watchdog
Attack harvests users' info at iPhone 6 launch
NOT OK GOOGLE: Android images can conceal code
It's been fixed, but hordes won't have applied the upgrade
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Saudi Petroleum chooses Tegile storage solution
A storage solution that addresses company growth and performance for business-critical applications of caseware archive and search along with other key operational systems.
How to simplify SSL certificate management
Simple steps to take control of SSL certificates across the enterprise, and recommendations centralizing certificate management throughout their lifecycle.