antivirus etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
antivirus etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

12 Eylül 2011 Pazartesi

Trend Micro Titanium Antivirus+ 2012

The software designers at Trend Micro identified three main pain points for security software users: complexity, intrusiveness, and overuse of resources. With Trend Micro Titanium Antivirus+ 2012 ($39.95, direct; three licenses for $59.95) they aim to avoid those pain points and offer an antivirus that's safe, lightweight, and easy to use. It succeeds at those goals, but PCMag's tests and independent lab tests agree that its actual protection capabilities lag behind the competition.

Changes for 2012
Bitdefender Antivirus Plus 2012 ($39.95 direct for three licenses, 4 stars) and Kaspersky Anti-Virus 2012 ($59.95 direct for three licenses, 3.5 stars) both got a full makeover this year, a new, simpler interface. Trend Micro's interface didn't need a change, as it was already super-simple. Interestingly, the latest edition lets you personalize the product by selecting a skin or using one of your own photos.


Specifications
Type
Business, Personal, Professional
OS Compatibility
Windows Vista, Windows XP, Windows 7
Tech Support
Free email, chat, and phone support plus online forum and videos.
More View Slideshow See all (16) slides

More
Action-wise this edition promises better protection against fake antivirus, better behavioral protection, and new technology to resist botnets and standard viruses. It also adds better detection and removal of rootkits, automatically offering a bootable rescue CD if needed to eradicate rootkits.

Trend Micro's Smart Protection Network (SPN) blocks 5 billion threats daily. About 80 percent of the antivirus's signature data resides in the cloud with SPN, to keep the product's footprint small. It's so quiet and unobtrusive that some users wondered if it was even working. The current edition offers a security report once a month, so you can see what it's doing for you. Of course, you can view the report any time you wish.

But wait! There's more! Whether you purchase one license or three of the PC-based antivirus, you get a free copy of Trend Micro Smart Surfing for Mac, which would normally cost $49.95.

Not Fond of the Labs

Trend Micro's researchers feel that many of the antivirus testing labs aren't doing their testing quite right. This product is designed to block malware at many levels, starting with the initial download of the file, and few labs test at all levels. Trend Micro stopped participating in Virus Bulletin's tests some while ago, and more recently withdrew from the retrospective tests performed by AV-Comparatives.org. In the latest on-demand malware cleanup test by AV-Comparatives, Trend Micro rated STANDARD, the lowest passing rating.

The company also declines to participate in testing by ICSA Labs. West Coast Labs certifies the product for both virus detection and virus removal.

All of the tests mentioned to this point are static tests in which the product is presented with thousands of inactive malware files and challenged to identify them. Trend Micro contends, quite reasonably, that dynamic testing of the whole product with active malware is more representative of the user's real-world experience.

Each quarter AV-Test.org runs a dynamic virus certification test under Windows 7, Vista, or XP. Products can earn up to six points in three areas: Protection, Repair, and Usability. A total of 11 points is required for certification. Trend Micro did make the cut, but just barely. Its last three scores were 12.5, 13.5, and 12.5. Bitdefender's technology averaged 16 point on the last three tests, the highest of any tested. and Kaspersky came in second with an average of 15.17.

In the dynamic whole product test by AV-Comparatives, Trend Micro impressively took the top rating, ADVANCED+.

AVG Anti-Virus Free 2012

AVG Technologies is best known for antivirus protection, but in recent years the company has branched out, adding system tune-up, parental control, online backup, and more. But have no fear; you can still get the powerful protection of AVG Anti-Virus Free 2012 without spending a penny. In my tests and in tests by independent labs it beats many of its for-pay competition. Do note that it's specifically free for personal use; business users must pay for AVG's antivirus protection.

The 2012 edition's main screen collapses the previous edition's ten component icons down to six, but adds three new ones to integrate the company's other products. If you use AVG Family Safety ($19.95 direct for three licenses, 4.5 stars), AVG PC Tuneup 2011 ($29.99/year direct, 4 stars), or AVG LiveKive online backup, you can click the icon to link your products. If you don't, naturally the antivirus includes an option to get them.


More
Specifications
Type
Personal
Free
Yes
OS Compatibility
Windows Vista, Windows XP, Windows 7
Tech Support
FAQ, forum, videos, email; free phone support in US, UK, Canada.
More Good Lab Results
All of the labs I follow test AVG's technology and give it generally good ratings. ICSA Labs and West Coast Labs certify it for virus detection; West Coast adds checkmark certification for virus removal as well. In all of the last ten tests by Virus Bulletin, AVG has received VB100 certification.

AVG participates in the on-demand test by AV-Comparatives.org, but not in the retrospective test, which simulates zero-day protection by using old virus signatures. In the on-demand test AVG rated STANDARD, the lowest passing grade.

AV-Comparatives also runs a whole-product dynamic test, challenging products to protect test systems from real-world up-to-the-minute threats. In this test AVG rated ADVANCED, a cut above STANDARD.

The ongoing antivirus certification tests by AV-Test.org are also dynamic tests, emulating a user's real-world experience. Products can receive up to 6 points for protection, repair, and usability, with a total of 11 points required for certification. In the most recent tests under Windows 7, Vista, and XP, AVG averaged 13.17 points.

The article How We Interpret Antivirus Lab Tests explains how I boil down results from the various labs to create the following chart.


AVG Anti-Virus Free 2012 lab tests chart

Very Good Malware Cleanup
AVG installed quickly on my twelve malware-infested test systems. Resistant malware on one system interfered with installation, but installing in Safe Mode solved that one. On half of the test systems AVG detected active threats immediately and requested a reboot to finalize cleanup.

A full scan on my standard clean test system took just 16 minutes, and a repeat scan finished in less than two minutes. That's plenty fast. The average scan time for recent products on this same system is 25 minutes.

I always find it odd that AVG separates rootkit scanning from the whole computer scan. For the test systems infested with rootkits I ran the separate rootkit scan, which added about three minutes.

When I tallied the results I was quite impressed. AVG detected 88 percent, the same as TrustPort Antivirus 2012 ($39.95 direct, 3.5 stars). Of the products tested with this current threat collection, only G Data AntiVirus 2012 ($29.95 direct, 3.5 stars), with 91 percent, detected more.

AVG didn’t clean up perfectly. It left behind executable files for some threats, and even left a few processes running. However, its score of 6.5 points for malware removal is a new high for the current crop of antivirus products, beating out the 6.4 point record held by Malwarebytes' Anti-Malware Free 1.51 (Free, 4 stars).

AVG detected all of the threats that use rootkit technology and scored 6.7 points for rootkit removal, a tie for top score with ZoneAlarm Antivirus + Firewall 2012 ($59.95 direct for three licenses, 3 stars). Bitdefender Antivirus Plus 2012 ($39.95 direct for three licenses, 4 stars) was the next-best rootkit remover, with 6.0 points.

The majority of current products detected all of my scareware samples. Malwarebytes scored a perfect 10, thoroughly cleaning up scareware. AVG was close behind with 9.5 points, the same as BitDefender, Panda Cloud Anti-Virus 1.5 Free Edition (Free, 3.5 stars), and several others.

This is quite an impressive showing, and it parallels the dynamic test results from the labs. For a full explanation of how I come up with these scores see How We Test Malware Removal.

Spyware Stoppers

Illustration: Doug FraserNot long ago, Web- and e-mail-borne viruses were a computer user's worst enemy. Though viruses and worms still cause more damage in compromised or lost data, a newer menace, popularly known as spyware, steals users' productivity and peace of mind. The "spyware" label can apply to legitimate but annoying programs that users consent (perhaps unwittingly) to have installed on their PCs, or it can describe programs that install themselves without permission. Both types of applications can drain your computer's resources, slow your Internet connection, spy on your surfing, and even forcibly redirect your Web browser. For the purposes of this story, we'll call the former category adware and the latter spyware. Adware clearly spells out its intent, comes with an uninstaller, and can be readily removed from a system. Spyware, in contrast, installs itself surreptitiously and can be nearly impossible to remove without assistance.

A crop of anti-spyware programs has sprung up to provide that assistance. We evaluated ten current anti-spyware utilities designed to detect and remove spyware and adware from PCs, looking at their rates of detection, scanning speed, ability to prevent unwanted applications from installing themselves, and ease of use. We were pleased to find that a couple of the programs did a very effective job of cleaning an infected system and preventing new infestations with effective real-time protection.

PC World tested seven products in the $20 to $40 range from big and small vendors: Allume Systems' (formerly Aladdin Systems') Internet Cleanup, Aluria Software's Spyware Eliminator, Computer Associates' ETrust PestPatrol Anti-Spyware, InterMute's SpySubtract Pro, McAfee's AntiSpyware, Sunbelt Software's CounterSpy, and Webroot Software's Spy Sweeper. In addition, we tested two popular free programs--Lavasoft's Ad-Aware SE Personal and Safer Networking's Spybot Search & Destroy--and a third free program that operates very differently but no less effectively, Merijn.org's HijackThis. (You can get all three free products here.) We did not include HijackThis in our charts because, unlike the others, it does not scan for infections. We also tested one product in beta, Microsoft's new Windows AntiSpyware, which was until late last year Giant Software's AntiSpyware.

2 Eylül 2011 Cuma

Anti-Virus Tips

Tips for Virus Detection and Prevention

Do not open any files attached to an email from an unknown, suspicious or untrustworthy source.
Do not open any files attached to an email unless you know what it is, even if it appears to come from a friend or someone you know. Some viruses can replicate themselves and spread through email. Confirm that your contact really sent an attachment.
Do not open any files attached to an email if the subject line is questionable or unexpected.
Delete chain emails and junk email. Do not forward or reply to any to them. These types of email are considered spam - unsolicited, intrusive messages that clog up the inboxes and networks.
Do not download any files from strangers.
Exercise caution when downloading files from the Internet. Ensure that the source is a legitimate and reputable one. Verify that an anti-virus program checks the files on the download site.
Update your anti-virus software regularly. McAfee security software like McAfee Total Protection update automatically and continuously via the Internet.
Back up your files on a regular basis. If a virus destroys your files, at least you can replace them with your back-up copy. You should store your backup copy in a separate location from your work files, one that is preferably not on your computer.
When in doubt, always err on the side of caution and do not open, download, or execute any files or email attachments. Not executing is the more important of these caveats. Check with your product vendors for updates for your operating system, web browser, and email. One example is the security site section of Microsoft located at http://www.microsoft.com/security.
If you are in doubt about any potential virus-related situation you find yourself in, you may report a virus to our virus team.

22 Ağustos 2011 Pazartesi

Use security software that updates automatically.

Keep your security software active and current: at a minimum, your computer should have anti-virus and anti-spyware software, and a firewall. You can buy stand-alone programs for each element or a security suite that includes these programs from a variety of sources, including commercial vendors or from your Internet Service Provider. Security software that comes pre-installed on a computer generally works for a short time unless you pay a subscription fee to keep it in effect. In any case, security software protects against the newest threats only if it is up-to-date. That's why it is critical to set your security software to update automatically.

Some scam artists distribute malware disguised as anti-spyware software. Resist buying software in response to unexpected pop-up messages or emails, especially ads that claim to have scanned your computer and detected malware. That's a tactic scammers have used to spread malware. OnGuardOnline.gov can connect you to a list of security tools from legitimate security vendors selected by GetNetWise, a project of the Internet Education Foundation.

Once you confirm that your security software is up-to-date, run it to scan your computer for viruses and spyware. If the program identifies a file as a problem, delete it.
Anti-Virus Software

Anti-virus software protects your computer from viruses that can destroy your data, slow your computer's performance, cause a crash, or even allow spammers to send email through your account. It works by scanning your computer and your incoming email for viruses, and then deleting them.
Anti-Spyware Software

Installed on your computer without your consent, spyware software monitors or controls your computer use. It may be used to send you pop-up ads, redirect your computer to websites, monitor your internet surfing, or record your keystrokes, which, in turn, could lead to the theft of your personal information.

A computer may be infected with spyware if it:

Slows down, malfunctions, or displays repeated error messages
Won't shut down or restart
Serves up a lot of pop-up ads, or displays them when you're not surfing the web
Displays web pages or programs you didn't intend to use, or sends emails you didn't write.

Firewalls

A firewall helps keep hackers from using your computer to send out your personal information without your permission. While anti-virus software scans incoming email and files, a firewall is like a guard, watching for outside attempts to access your system and blocking communications to and from sources you don't permit.

16 Ağustos 2011 Salı

What is pharming?

Whereas phishing uses fraudulent email messages to lure you to fake Web sites and try to get you to supply personal information like account passwords, pharming attacks redirect you to a hacker's site even when you type the address of a real site into your browser.

Real or not?

Pharming does not require that a user clicks on an email message or has a system compromised by a Trojan or a keylogger, and therefore pharming is often described as "phishing without a lure."

Pharmers typically redirect users to a spoofed website by tampering with a company's hosts files or domain name system (DNS) so that requests for certain URLs return a bogus address and subsequent communications are then directed to a fake site. This means that users are unaware that the website where they are entering confidential information is controlled by hackers.

Other types of pharming attacks involve Trojan horses, worms or other technologies that attack the browser address bar, thus redirecting the user to a fraudulent website when the user types in a legitimate address.

Pharming strike

In February 2007, a pharming attack that targeted online customers of at least 50 financial institutions in the US, Europe and the Asia-Pacific region infected at least 1,000 machines per day for several days. The attack was notable for the effort put into it by the hackers, who constructed a separate look-alike website for each financial institution they targeted.

Also in 2007, a new kind of pharming was discovered. In drive-by pharming a cyberattacker takes control of a user's home router by guessing the router password and any users who have not changed the default password on their router could be at risk.

Be aware

One way to protect yourself against pharming attacks is to only use pharming-conscious or (PhC) websites. If an attacker attempts to impersonate a PhC website, you will receive a message from the browser indicating that the website's "certificate" does not match the address being visited. You should never ever proceed to the website when you get such a message.

What is a rootkit?

Rootkits are a malware inventor's dream: they are created to allow worms, bots, and other malevolent software to hide in plain sight. Rootkits are designed to hide themselves from detection by users and security programs, so they don't show up in Windows Explorer, the running processes don't display in the Task Manager, and many antivirus programs can't find rootkit-hidden malware.

A rootkit is a special program that buries itself deep into an operating system (like Microsoft Windows) for malicious activity and is extremely difficult to detect. The malicious software operates in a stealth fashion by hiding its files, processes and registry keys and it can be used to create a hidden directory or folder designed to keep it out of view from a user's operating system and security software.

Attackers can then use the rootkit to hide their malicious software, which can range from spyware to keylogger software that can steal sensitive information from users' computers. Rootkits can allow criminals to remotely monitor, record, modify, steal and transfer any information entered or stored on a user’s computer, disabling some PC firewalls and evading some traditional security products at will.

Rootkits often bury themselves via other computer infections and then modify the operating system of the infected PC. They are often almost undetectable and extremely difficult to remove. Detecting a rootkit on a Windows PC is not unlike shining a flashlight at objects in a darkened room, and then trying to identify each object by the shadow it casts on the wall.

Rootkits are rapidly becoming more prevalent, more virulent and more sophisticated, security experts warn. The complexity in rootkits is growing at a phenomenal rate, allowing malicious software to bury deep and potentially go undetected inside Microsoft's Windows platform. Rootkits have grown over the past five years from 27 components to 2,400, according to a report from April 2007.

This means that there are more ways attackers can use these components to hide their malware and it means that the use of rootkits is increasing. One security company recorded a 62 percent annual increase in rootkit activity in 2006 and predicted an increase of around 40 percent 2007. Another security company that surveyed 291,000 users in October 2007 warned that increasing numbers of PC users are falling victim to rootkit infections.

What is a firewall?

A firewall is a hardware or software device configured to permit or deny data through a computer network in order to protect the resources of a private network from users from other networks. For example, an enterprise with an intranet that allows its workers access to the wider Internet would install a firewall to prevent outsiders from accessing its own private data resources and for controlling what outside resources its own users have access to.

In the same way, computer users install personal firewalls (usually software) to protect their computers from the threats of the Internet. The program simply sits between your computer and the Internet and its job is to filter incoming and outbound traffic. That way it can deny intruders or malware access to your computer and it can also detect unwanted outbound traffic. For instance, in order to guard against spyware which could be sending your surfing habits to a Web site.

Basically, a firewall examines all data trying to pass it to determine whether to forward it to its destination. This is done according to a set of rules set by the user, establishing which sorts of traffic to be allowed and which traffic not. The term "firewall" of course originated from firefighting, where firewalls are barriers established to prevent the spread of fire.

An up to date firewall is really one of the most basic must-have elements of computer protection and that became clear, when the Love Bug, MyDoom, Slammer, and Sasser worms swept across the globe in the first years of this millennium causing millions of dollars of damage. As a response ordinary computer users started installing firewalls and anti-virus products galore and the next generations of worms have pretty much been stopped dead in their tracks before they could start spreading to a serious degree.

Modern firewalls can filter traffic based on many packet attributes like source IP address, source port, destination IP address or port, destination service like WWW or FTP. They can filter based on protocols, TTL values, netblock of originator, domain name of the source, and many other attributes.

What are security holes?

Security holes are constantly discovered in all sorts of software and to plug the holes software vendors issue patches - also called "fixes" or just plainly "security updates" - to offer an immediate quick-repair solution for the problem and/or a general enhancement of the software.

Flaws in Microsoft's software seem to be the most popular to exploit, so the American software giant releases a lot of patches. But other common desktop applications like Firefox, QuickTime, RealPlayer, Adobe Reader, Adobe Flash Player, and Sun Java Runtime Environment also often need to be patched to fix security issues.

In 2003, Microsoft introduced Patch Tuesday to simplify patch management. Patch Tuesday is the second Tuesday of each month, when Microsoft releases the newest fixes for Windows and related software applications like Internet Explorer, the Office suite, and Windows Media Player.

Microsoft's patches are distributed via Automatic Updates and the company's Microsoft Update downloads website.

Unfortunately, releasing patches also means that cyber-criminals are able to analyse the patch code and exploit the vulnerabilities that the patches were intended to deal with. Therefore a lot of exploits are seen shortly after the release of a patch and the term "Exploit Wednesday" was coined for the day following Patch Tuesday. Malware authors also know that if they start exploiting a vulnerability not known to Microsoft right after Patch Tuesday, it will normally be an entire month before Microsoft releases a patch to fix it. In 2006 Microsoft only broke its patch cycle twice to release very critical fixes.

Today's cyber-criminals are very fast at creating exploit code. When Microsoft issues patches, exploit code for the publicly disclosed vulnerabilities will usually appear the same or the next day. Hackers are able to do that through reverse engineering.

In April 2008, a group of computer researchers urged Microsoft to redesign the way it distributes patches, after they created a technique that automatically produces attack code by comparing the vulnerable and repaired versions of a program.

Using an automated tool, an exploit could be created in a few minutes or less after looking at the patch, according to the researchers. This means it is theoretically possible for hackers to start trying to exploit machines a short time after the attackers have received the patch, putting more PCs at risk of becoming infected with malicious software.

Keeping your PC up-to-date

Constantly patching the software on your PC is just as important as keeping your antivirus program up-to-date and running a firewall. Yet the numbers show that a lot of users are struggling with the task of keeping all their software up-to-date.

Research released in January 2008 revealed that only 5 percent of users are running fully-patched Windows PCs, while more than 40 percent have more than 10 insecure applications installed.

Another survey from December 2007 showed that more than 20 percent of all applications installed on users PCs have known security flaws for which patches have been released by the vendors of the products. That result was based on scans of more than 14.5 million applications on end-user computers.

The length of time between the release of security patches and the development of exploits targeting the security holes they address has been dropping for some time. Hackers exploit this period of time - the so-called "patch window" - to launch attacks against unpatched machines.

Microsoft delivers almost all its patches on the second Tuesday of each month, known as Patch Tuesday. In 2006, Microsoft released 49 critical, 23 important, and 5 moderate updates, while 2007 brought 43 critical, 24 important, and 2 moderate fixes.

If your software applications have automatic update features, then be sure to switch them on. If you have to download patches manually, then make sure that you do it from the actually Web site of the software vendor and that you didn't wind up on the download page following a link from an untrusted source.

On occation cyber-criminals have tried to sneak malware past users by disguising it as an automatic update to a popular software product. If you are in doubt if an update trying to install itself on your computer is the real deal, it might be a good idea.

How a virus works

The word virus is often being used as a common term for all malicious programs, but technically a virus is a program or code that attaches itself to a legitimate, executable piece of software, and then reproduces itself when that program is run. Viruses spread by reproducing and inserting themselves into programs, documents, or email attachments. They can be transmitted through emails or downloaded files and they can be present on CDs, DVDs, USB-drives and any other sort of digital media.

A virus normally requires action to successfully infect a victim. For instance - the malicious programs inside email attachments usually only strike if the recipient opens them. The effect of a virus can be anything from a simple prank that pops up messages to the complete destruction of programs and data.

In recent years viruses have been on the decrease. In January 2007, one in 119.9 e-mails, or 0.83 percent, were infected with viruses, while more than 20 percent of emails at times contained viruses five years earlier. The difference is partly due to virus attacks becoming more targeted and no longer occurring as one large outbreak. Also, there has been big increase in spam emails that contains links to download viruses.

The computer virus turned 25 in 2007. Long-suffering computer users would be forgiven for thinking that the first computer virus appeared in the mid-1980s, but the first virus actually predates the first IBM-compatible PC. Elk Cloner, which spread between Apple II computers via infected floppy disks, was released July 1982 and it was the first computer virus to spread in the wild.

Viruses had their heyday around the year 2000, with the Y2K scare. In 1999, the Melissa virus caught antivirus companies flat-footed and propagated rapidly. It was the first real outbreak of many of its kind that spread using Microsoft's Word and Outlook. A year later, the 'I Love You' virus caught the world by surprise. Lloyds of London estimated that the virus cost the global economy $10bn, making it the most expensive piece of malicious software to be unleashed to date. It was also the first time a computer virus became the day's top story for newspapers and television stations, marking a shift to mainstream awareness of computer viruses.

Nowadays, also mobile operators are starting to feel the pinch from viruses resulting from the increasing use of emails and Internet browsing on cellphones. Attacks on cellphones rose five times in 2006, with clients of 83 percent of mobile operators around the world having been hit, an industry study showed.

But mobile viruses are around 20 years behind those plaguing PCs, which translates into more than 300 virus variants targeting mobiles and smartphones, but around 400,000 such threats targeting PCs. In June 2004, a security company released details of a piece of mobile-phone malware that used Bluetooth to try to spread to other Symbian Series 60-based mobiles. That is believed to be the first case of a self-replicating mobile-phone virus and since then there has been a consistent increase in mobile viruses.

2 Ağustos 2011 Salı

Computer security policy-Germany

Berlin starts National Cyber Defense Initiative

On June 16, 2011, the German Minister for Home Affairs, officially opened the new German NCAZ (National Center for Cyber Defense) [[1]] , which is located in Bonn. The NCAZ closely cooperates with BSI (Federal Office for Information Security) [[2]], BKA (Federal Police Organisation) [[3]], BND (Federal Intelligence Service) [[4]], MAD (Military Intelligence Service) [[5]] and other national organisations in Germany taking care of national security aspects. According to the Minister the primary task of the new organisation founded on Feb. 23, 2011, is to detect and prevent attacks against the national infrastructure and mentioned incidents like Stuxnet

14 Temmuz 2011 Perşembe

Capabilities and access control lists

Within computer systems, two security models capable of enforcing privilege separation are access control lists (ACLs) and capability-based security. The semantics of ACLs have been proven to be insecure in many situations, for example, the confused deputy problem. It has also been shown that the promise of ACLs of giving access to an object to only one person can never be guaranteed in practice. Both of these problems are resolved by capabilities. This does not mean practical flaws exist in all ACL-based systems, but only that the designers of certain utilities must take responsibility to ensure that they do not introduce flaws.[citation needed]

Capabilities have been mostly restricted to research operating systems and commercial OSs still use ACLs. Capabilities can, however, also be implemented at the language level, leading to a style of programming that is essentially a refinement of standard object-oriented design. An open source project in the area is the E language.

First the Plessey System 250 and then Cambridge CAP computer demonstrated the use of capabilities, both in hardware and software, in the 1970s.y8 A reason for the lack of adoption of capabilities may be that ACLs appeared to offer a 'quick fix' for security without pervasive redesign of the operating system and hardware.[citation needed]

The most secure computers are those not connected to the Internet and shielded from any interference. In the real world, the most security comes from operating systems where security is not an add-on.

Secure coding

If the operating environment is not based on a secure operating system capable of maintaining a domain for its own execution, and capable of protecting application code from malicious subversion, and capable of protecting the system from subverted code, then high degrees of security are understandably not possible. While such secure operating systems are possible and have been implemented, most commercial systems fall in a 'low security' category because they rely on features not supported by secure operating systems (like portability, and others). In low security operating environments, applications must be relied on to participate in their own protection. There are 'best effort' secure coding practices that can be followed to make an application more resistant to malicious subversion.

In commercial environments, the majority of software subversion vulnerabilities result from a few known kinds of coding defects. Common software defects include buffer overflows, format string vulnerabilities, integer overflow, and code/command injection. It is to be immediately noted that all of the foregoing are specific instances of a general class of attacks, where situations in which putative "data" actually contains implicit or explicit, executable instructions are cleverly exploited.

Some common languages such as C and C++ are vulnerable to all of these defects (see Seacord, "Secure Coding in C and C++").y8 Other languages, such as Java, are more resistant to some of these defects, but are still prone to code/command injection and other software defects which facilitate subversion.

Recently another bad coding practice has come under scrutiny; dangling pointers. The first known exploit for this particular problem was presented in July 2007. Before this publication the problem was known but considered to be academic and not practically exploitable.

Unfortunately, there is no theoretical model of "secure coding" practices, nor is one practically achievable, insofar as the code (ideally, read-only) and data (generally read/write) is

Secure operating systems

One use of the term computer security refers to technology to implement a secure operating system. Much of this technology is based on science developed in the 1980s and used to produce what may be some of the most impenetrable operating systems ever. Though still valid, the technology is in limited use today, primarily because it imposes some changes to system management and also because it is not widely understood. Such ultra-strong secure operating systems are based on operating system kernel technology that can guarantee that certain security policies are absolutely enforced in an operating environment. An example of such a Computer security policy is the Bell-LaPadula model. The strategy is based on a coupling of special microprocessor hardware features, often involving the memory management unit, to a special correctly implemented operating system kernel. This forms the foundation for a secure operating system which, if certain critical parts are designed and implemented correctly, can ensure the absolute impossibility of penetration by hostile elements. This capability is enabled because the configuration not only imposes a security policy, but in theory completely protects itself from corruption. Ordinary operating systems, on the other hand, lack the features that assure this maximal level of security. The design methodology to produce such secure systems is precise, deterministic and logical.
Systems designed with such methodology represent the state of the art of computer security although products using such security are not widely known. In sharp contrast to most kinds of software, they meet specifications with verifiable certainty comparable to specifications for size, weight and power. Secure operating systems designed this way are used primarily to protect national security information, military secrets, and the data of international financial institutions. These are very powerful security tools and very few secure operating systems have been certified at the highest level to operate over the range of "Top Secret" to "unclassified" (including Honeywell SCOMP, USAF SACDIN, NSA Blacker and Boeing MLS LAN.) The assurance of security depends not only on the soundness of the design strategy, but also on the assurance of correctness of the implementation, and therefore there are degrees of security strength defined for COMPUSEC. The Common Criteria quantifies security strength of products in terms of two components, security functionality and assurance level (such as EAL levels), and these are specified in a Protection Profile for requirements and a Security Target for product descriptions.y8 None of these ultra-high assurance secure general purpose operating systems have been produced for decades or certified under Common Criteria.
In USA parlance, the term High Assurance usually suggests the system has the right security functions that are implemented robustly enough to protect DoD and DoE classified information. Medium assurance suggests it can protect less valuable information, such as income tax information. Secure operating systems designed to meet medium robustness levels of security functionality and assurance have seen wider use within both government and commercial markets. Medium robust systems may provide the same security functions as high assurance secure operating systems but do so at a lower assurance level (such as Common Criteria levels EAL4 or EAL5). Lower levels mean we can be less certain that the security functions are implemented flawlessly, and therefore less dependable. These systems are found in use on web servers, guards, database servers, and management hosts and are used not only to protect the data stored on these systems but also to provide a high level of protection for network connections and routing services.