ITPRO

Printed from www.itpro.co.uk

Register to receive our regular email newsletter at http://www.itpro.co.uk/reg/register.

The newsletter contains links to our latest IT news, product reviews, features and how-to guides, plus special offers and competitions.

Skip to navigation

    IDF 2011: Intel unveils first fruits of McAfee acquisition

The new DeepSAFE security offering is different to the software protection approach, Intel and McAfee claim.

By Maggie Holland, 13 Sep 2011 at 20:27

IDF 2011 logo

McAfee has stepped up the fight against cyber criminals by tapping into the power of hardware rather than just focusing on software-based defences.

The security giant, which was acquired by Intel for $7.68 billion in August last year, took the wraps off the technology dubbed DeepSAFE at the Intel Developer Forum in San Francisco.

As the bad guys continue to circumnavigate security software such as firewalls and antivirus protection, those wishing to keep their data safe need to fight back. But using the same weapons of old is no longer viable, or won’t be in the long term, according to the two companies.

With the DeepSAFE technology platform, we’re actually able to protect our customers and save them time and money.

By opting for a hardware-related approach and utilising features already present in Intel processors, threats residing beneath the operating system can be tackled in real-time before they affect consumer or business machines and cause any damage, according to McAfee. This approach will be particularly useful in combating rootkit attacks, the company claims, adding that it estimates there are currently 1,200 new rootkits detected on daily basis.

What we think...

As a means of securing the software layer from the hardware layer, it's a good approach. Trend Micro has tried doing this before, and various BIOS builders have also built in capabilities to prevent root kits and so on. Indeed, Intel itself has stuff in the trusted computing platform that should do stuff like this.

One of the biggest issues though is if a false positive is flagged - such an approach is almost impossible to override. So a critical piece of software may not be installable.

For Intel, the biggest issue it has to worry about is that whatever it does at the silicon level with McAfee has to be open and something that others can also do otherwise the DoJ will jump down its throat on an anti-compete charge.

Clive Longbottom, founder, analyst firm Quocirca

“Many attacks are triggered when we launch a video or an application from one of our favourite sites. Often, users will see a warning that they click on through and ignore it,” said Candace Worley, McAfee’s senior vice president and general manager of Endpoint Security, as she demoed the technology in action.

While in beta now, the first DeepSAFE products are expected to hit the market this year, most likely initially focused on enterprise protection.

“Let’s take a look at a system that’s actually running the DeepSAFE technology. Here, running on top of DeepSAFE is beta software for a soon-to-be-announced product from McAfee that will do kernel node rootkit prevention,” she added.

“Once again, the user clicks through the warnings and unknowingly installs the Agony rootkit. But, because the DeepSAFE technology and beta software is used, utilising the VT technology from Intel, we actually recognise the rootkit as it attempts to load into memory and we block the attack in real-time.”

“With the DeepSAFE technology platform, we’re actually able to protect our customers and save them time and money,” Worley concluded.

CPU events can be monitored in real-time using the technology, which will also remove the hiding place for some of today’s threats, meaning the currently undetectable becomes detectable and resolvable.

Email to a friend

Print this page

Previous
1 2
< Previous   Firewalls : News

Be the first to comment on this article

You need to Login or Register to comment.

    You may also like...

 Sponsored Links

advertisement

    You may also like...

    Latest Firewalls Reviews

Fortinet FortiGate 111C

Rating: 6

Fortinet's compact FortiGate 111C appliance has a remarkable range of security measures at an affordable price. In this exclusive review, Dave Mitchell puts it on test to see if it really does have every security angle covered.

Read more

 
advertisement

    Register for IT PRO

You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.

Sponsored Links
Advertisement