<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic New Generation of AntiVirus Software for Workstation in Member Support</title>
    <link>https://community.isc2.org/t5/Member-Support/New-Generation-of-AntiVirus-Software-for-Workstation/m-p/3868#M411</link>
    <description>&lt;P&gt;Dear Members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be your&amp;nbsp;expected protection feature(s) in New Generation AntiVirus?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please correct me if I am wrong...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scanning Object (known Virus Signature) and Sending Object (Potential Malicious) to Sandbox test did not provide a Comfortable&amp;nbsp;Security level for End-Point-Protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would&amp;nbsp;like to have features as below (monitoring&amp;nbsp;the Malware Behaviour and Objective via the Approach from Web Application Protection, Digital Forensic, Malware Analysis):-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor the activities of browser - alert Malicious Traffic, Re-Direct, XSS, Keylogger...(Do not expect Web Application Developers to take all responsibilities to protect their Users); alert access to Malicious Web Site (Should verify the Web Site from blacklist in Cloud); Double check the Digital Signature of the Web Site (avoid MITM - request a product in&amp;nbsp;Cloud to verify one more time)...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor Parent and Child Process - alert any Background task and or Network connection and or storage...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Data Acquisition on potential attack target file and registry - alert on change...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Computer Activity Summary Report&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please share your view and comment (expected feature) on handling the UNKNOWN...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, Joseph&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2017 07:02:22 GMT</pubDate>
    <dc:creator>sgjoelee</dc:creator>
    <dc:date>2017-11-26T07:02:22Z</dc:date>
    <item>
      <title>New Generation of AntiVirus Software for Workstation</title>
      <link>https://community.isc2.org/t5/Member-Support/New-Generation-of-AntiVirus-Software-for-Workstation/m-p/3868#M411</link>
      <description>&lt;P&gt;Dear Members,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What will be your&amp;nbsp;expected protection feature(s) in New Generation AntiVirus?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please correct me if I am wrong...&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Scanning Object (known Virus Signature) and Sending Object (Potential Malicious) to Sandbox test did not provide a Comfortable&amp;nbsp;Security level for End-Point-Protection.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I would&amp;nbsp;like to have features as below (monitoring&amp;nbsp;the Malware Behaviour and Objective via the Approach from Web Application Protection, Digital Forensic, Malware Analysis):-&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor the activities of browser - alert Malicious Traffic, Re-Direct, XSS, Keylogger...(Do not expect Web Application Developers to take all responsibilities to protect their Users); alert access to Malicious Web Site (Should verify the Web Site from blacklist in Cloud); Double check the Digital Signature of the Web Site (avoid MITM - request a product in&amp;nbsp;Cloud to verify one more time)...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Monitor Parent and Child Process - alert any Background task and or Network connection and or storage...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Data Acquisition on potential attack target file and registry - alert on change...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Computer Activity Summary Report&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please share your view and comment (expected feature) on handling the UNKNOWN...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks, Joseph&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 07:02:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/New-Generation-of-AntiVirus-Software-for-Workstation/m-p/3868#M411</guid>
      <dc:creator>sgjoelee</dc:creator>
      <dc:date>2017-11-26T07:02:22Z</dc:date>
    </item>
    <item>
      <title>Re: New Generation of AntiVirus Software for Workstation</title>
      <link>https://community.isc2.org/t5/Member-Support/New-Generation-of-AntiVirus-Software-for-Workstation/m-p/4012#M419</link>
      <description>&lt;P&gt;Hi Joseph,&lt;/P&gt;&lt;P&gt;Full disclosure - I work for Cylance (&lt;A href="http://www.cylance.com" target="_blank"&gt;www.cylance.com&lt;/A&gt;) as a system engineer. the AV/ NGAV space is&amp;nbsp;probably the most congested of all technology solutions out there with at least 60+ vendors fighting for market share. Before I joined Cylance over 1 year ago I worked for security&amp;nbsp;integrators in the UK and reviewed the majority of NGAV offerings and the reason I joined Cylance is because I found&amp;nbsp;Cylance to be using a groundbreaking, revolutionary approach&amp;nbsp;that I feel could change the way AV works going forward.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As you say, you want to know how to protect against unknown... in short, malware has become a big data problem which is why Cylance uses machine learning techniques to predict whether a never seen before file is bad based upon previously learned analysis. In truth, everyone has upped their game in catching something quicker than they would have done with just a signature (known bad) but like sandboxing, almost all have the problem of patient-0.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm not a sales guy but I can speak about my experience to help you make an informed choice/ shortlist. Let me know how else I can help.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Patrick Bayle CISSP&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2017 09:30:19 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Member-Support/New-Generation-of-AntiVirus-Software-for-Workstation/m-p/4012#M419</guid>
      <dc:creator>pbayle</dc:creator>
      <dc:date>2017-11-30T09:30:19Z</dc:date>
    </item>
  </channel>
</rss>

