|
For the last 20 years, Cybercriminals are exploiting vulnerabilities in software to install their malware on our PCs. Crimeware, Web 2.0 attacks, Spyware, Trojans and other malware end-up running on our PCs after successfully exploiting security holes in Web browsers that we use. Cybercriminals are aware that signature-based security solutions such as Anti-Virus are in place to protect our PCs from getting infected. They also know that signature-based security solutions can detect and block malware that has been seen before and has been issued a signature. Cybercriminals are therefore always looking for new vulnerabilities they can exploit. They abuse those vulnerabilities for which no security patch has been issued by the software vendor and no signature exists yet. These are the zero-hour vulnerabilities that cybercriminals go for. ![]() Window-of Vulnerability, showing the time of risk Software vendors are unable to release patches for reported vulnerabilities on the spot, and therefore a Window-of-Vulnerability™ appears. This refers to the time between the moment a vulnerability becomes known, and the moment a patch is available to solve it. This creates an opportunity for cybercriminals to successfully conduct their attacks. Although software vendors try to shorten this timeframe by making patches availability as quickly as possible, it still leaves organizations and enterprises vulnerable for days, weeks, or even months.
Vulnerability-based vs. Signature-based Detection Cybercriminals use this Window-of-Vulnerability to steal valuable personal, financial and business data that they can use or trade for profit. The Window-of-Vulnerability puts a strain on IT managers, who are under constant pressure to patch their systems at the same rate that new vulnerabilities are discovered. Considering the multitude of operating systems, service packs, applications and security settings in use across an organization, it puts a huge strain on the IT department. To address this need, Finjan provides organizations with its Vulnerability Anti.dote™ solution as part of the Finjan Secure Web Gateway. Utilizing its patented active real-time content inspection, it provides powerful proactive security with minimal patch management overhead. Vulnerability Anti.dote protects against vulnerabilities that could be exploited by cybercriminals. It also proactively protects against silent “drive-by” Crimeware installations, obfuscated malicious code, and remote code execution attacks, all of which exploit unpatched vulnerabilities. To minimize the risk of zero-hour vulnerabilities, Finjan’s security experts create behavioral rules that enable the Vulnerability Anti.dote scanning engines to identify and block content that tries to exploit these vulnerabilities. It therefore dramatically reduces the resources required for patch management, thus saving on administration overhead and total ownership costs. Benefits
Finjan Solutions Overview
|
|||||||||||||||||||||||||||||||||||||||


