Norton AntiBot

Last updated
Norton Antibot
Developer(s) Symantec Corporation
Final release
1.1.851
Operating system Microsoft Windows XP / Windows Vista
Platform Microsoft Windows
Size 12.9 MiB
Available in English
Type Antivirus software (Proactive defense / Heuristics)
License Proprietary commercial software
System Requirements
CPUWindows XP: 600 MHz
Windows Vista: 1 GHz
MemoryWindows XP: 256 MB
Windows Vista: 1 GB
Hard Drive Space50 MB
Other CD-ROM/DVD-ROM drive or an Internet connection

Norton AntiBot, developed by Symantec, monitored applications for damaging behavior. The application was designed to prevent computers from being hijacked and controlled by hackers. According to Symantec, over 6 million computers have been hijacked, and the majority of users are unaware of their computers being hacked.

Contents

AntiBot was designed to be used in conjunction with other antivirus software. Unlike traditional antivirus products, AntiBot does not use signatures; there is a delay between when a vendor discovers a virus and distributes the signature. During the delay, computers can be affected. Instead, AntiBot attempts to identify a virus through its actions; viruses are malicious by nature. However, AntiBot was not intended to replace an antivirus product. The program uses technology licensed from Sana Security.

The product has been discontinued after AVG acquired Sana Security in January 2009, developing a standalone program similar to AntiBot called AVG Identity protection, which was also discontinued and integrated in AVG Internet Security 2011. Product updates and technical support were available from Symantec for one year after a customer's last purchase or renewal. [1]

History

Ed Kim, director of product management at Symantec, highlighted the rise of botnets. A botnet is a collection of compromised computers, known as bots, which hackers usually control for malicious purposes. Two main uses of botnets include identity theft and e-mail spam. [2] Kim cited a 29 percent increase of bots from the first half of 2006 to the second half. In all, there were six million active bots by the end of 2006. [3]

On 7 June 2007, Symantec released a beta version of Norton AntiBot. [4] AntiBot was designed to supplement a user's existing antivirus software. Unlike traditional antivirus software, AntiBot does not use signatures to identify malware. Instead, it monitors running applications for damaging or malicious behavior, licensing technology from Sana Security.

AntiBot can also supplement SONAR technology by Symantec, found in Norton AntiVirus 2007, Norton Internet Security 2007, and Norton 360. Similar to AntiBot, SONAR monitors for malicious behavior. However, SONAR does not run continuously in the background; only during a virus scan in those specific products. [5]

AntiBot was made available to the general public on 17 July 2007. On 16 January 2009, AVG announced their plans to acquire Sana Security were finalized. J.R. Smith, CEO of AVG Technologies, highlighted the 40,000 unique malware samples their analysts see each day. He noted the time frame between when a sample is analyzed and a signature is created, emphasizing the need for "instant protection", since hackers are constantly modifying their malicious software to evade signature detection. Often, there are several strains, or variations, of one virus, each with a different classification and signature. [6] [7] Symantec confirmed ceasing sales and distribution of Norton AntiBot in early 2009. Product help and updates would still be available for one year following a customer's last purchase or renewal. [8]

Reception

PC Magazine noted AntiBot's above average ability to identify malicious programs based on behavior and the fact it did not mistakenly mark a legitimate program as malicious during testing. However, on some infected systems AntiBot failed to install or caused blue screens because it failed to completely remove a virus. [9]

A technical limitation is that AntiBot cannot detect inactive malware since there is no behavior for the software to monitor. [10]

Related Research Articles

<span class="mw-page-title-main">Malware</span> Malicious software

Malware is any software intentionally designed to cause disruption to a computer, server, client, or computer network, leak private information, gain unauthorized access to information or systems, deprive access to information, or which unknowingly interferes with the user's computer security and privacy. Researchers tend to classify malware into one or more sub-types.

<span class="mw-page-title-main">Antivirus software</span> Computer software to defend against malicious computer viruses

Antivirus software, also known as anti-malware, is a computer program used to prevent, detect, and remove malware.

<span class="mw-page-title-main">Gen Digital</span> Multinational software company

Gen Digital Inc. is a multinational software company co-headquartered in Tempe, Arizona and Prague, Czech Republic. The company provides cybersecurity software and services. Gen is a Fortune 500 company and a member of the S&P 500 stock-market index. The company also has development centers in Pune, Chennai and Bangalore. Its portfolio includes Norton, Avast, LifeLock, Avira, AVG, ReputationDefender, and CCleaner.

Linux malware includes viruses, Trojans, worms and other types of malware that affect the Linux family of operating systems. Linux, Unix and other Unix-like computer operating systems are generally regarded as very well-protected against, but not immune to, computer viruses.

<span class="mw-page-title-main">Botnet</span> Collection of compromised internet-connected devices controlled by a third party

A botnet is a group of Internet-connected devices, each of which runs one or more bots. Botnets can be used to perform Distributed Denial-of-Service (DDoS) attacks, steal data, send spam, and allow the attacker to access the device and its connection. The owner can control the botnet using command and control (C&C) software. The word "botnet" is a portmanteau of the words "robot" and "network". The term is usually used with a negative or malicious connotation.

<span class="mw-page-title-main">Spybot – Search & Destroy</span> Spyware removal software

Spybot – Search & Destroy (S&D) is a spyware and adware removal computer program compatible with Microsoft Windows. Dating back to the first Adwares in 2000, Spybot scans the computer hard disk and/or RAM for malicious software.

<span class="mw-page-title-main">ESET NOD32</span> Computer protection software

ESET NOD32 Antivirus, commonly known as NOD32, is an antivirus software package made by the Slovak company ESET. ESET NOD32 Antivirus is sold in two editions, Home Edition and Business Edition. The Business Edition packages add ESET Remote Administrator allowing for server deployment and management, mirroring of threat signature database updates and the ability to install on Microsoft Windows Server operating systems.

Norton AntiVirus is an anti-virus or anti-malware software product founded by Peter Norton, developed and distributed by Symantec since 1990 as part of its Norton family of computer security products. It uses signatures and heuristics to identify viruses. Other features included in it are e-mail spam filtering and phishing protection.

<span class="mw-page-title-main">Avast</span> Czech security software company

Avast Software s.r.o. is a Czech multinational cybersecurity software company headquartered in Prague, Czech Republic, that researches and develops computer security software, machine learning, and artificial intelligence. Avast has more than 435 million monthly active users and the second largest market share among anti-malware application vendors worldwide as of April 2020. The company has approximately 1,700 employees across its 25 offices worldwide. In July 2021, Norton LifeLock, an American cybersecurity company, announced that it was in talks to merge with Avast Software. In August 2021, Avast's board of directors agreed to an offer of US$8 billion.

Norton Internet Security, developed by Symantec Corporation, is a discontinued computer program that provides malware protection and removal during a subscription period. It uses signatures and heuristics to identify viruses. Other features include a personal firewall, email spam filtering, and phishing protection. With the release of the 2015 line in summer 2014, Symantec officially retired Norton Internet Security after 14 years as the chief Norton product. It was superseded by Norton Security, a rechristened adaptation of the Norton 360 security suite.

<span class="mw-page-title-main">Rogue security software</span> Form of malicious software

Rogue security software is a form of malicious software and internet fraud that misleads users into believing there is a virus on their computer and aims to convince them to pay for a fake malware removal tool that actually installs malware on their computer. It is a form of scareware that manipulates users through fear, and a form of ransomware. Rogue security software has been a serious security threat in desktop computing since 2008. An early example that gained infamy was SpySheriff and its clones, such as Nava Shield.

<span class="mw-page-title-main">PC Tools (company)</span> Australian software company

PC Tools, formerly known as WinGuides.com, was a software company acquired by Symantec in 2008; the new owner eventually discontinued the PC Tools name. Company headquarters were in Australia, with offices in Luxembourg, the United States, United Kingdom, Ireland and Ukraine. The company had previously developed and distributed security and optimization software for the Mac OS X and Microsoft Windows platforms.

SONAR is the abbreviation for Symantec Online Network for Advanced Response. Unlike virus signatures, SONAR examines the behavior of applications to decide whether they are malicious. SONAR is built upon technology Symantec acquired in its late 2005 purchase of WholeSecurity, a developer of behavioral anti-malware and anti-phishing software solutions in the United States.

Kaspersky Internet Security was an internet security suite developed by Kaspersky Lab compatible with Microsoft Windows and Mac OS X. Kaspersky Internet Security offers protection from malware, as well as email spam, phishing and hacking attempts, and data leaks. Kaspersky Lab Diagnostics results are distributed to relevant developers through the MIT License.

<span class="mw-page-title-main">AVG Technologies</span> Brand of cybersecurity, privacy, performance and utility applications

AVG Technologies is a brand of cybersecurity, privacy, performance and utility software applications for desktop computers and mobile devices developed by Avast, a part of Gen Digital. AVG was a cybersecurity software company founded in 1991 and it merged into Avast following an acquisition in 2017. It typically offers freeware, earning revenues from advertisers and from users that upgrade to paid versions for access to more features.

<span class="mw-page-title-main">Microsoft Security Essentials</span> Free antivirus product produced by Microsoft for the Windows operating system

Microsoft Security Essentials (MSE) is an antivirus software (AV) product that provides protection against different types of malicious software, such as computer viruses, spyware, rootkits, and Trojan horses. Prior to version 4.5, MSE ran on Windows XP, Windows Vista, and Windows 7, but not on Windows 8 and later versions, which have built-in AV components known as Windows Defender. MSE 4.5 and later versions do not run on Windows XP. The license agreement allows home users and small businesses to install and use the product free of charge. It replaces Windows Live OneCare, a discontinued commercial subscription-based AV service, and the free Windows Defender, which only protected users from spyware until Windows 8.

Zeus, ZeuS, or Zbot is a Trojan horse malware package that runs on versions of Microsoft Windows. While it can be used to carry out many malicious and criminal tasks, it is often used to steal banking information by man-in-the-browser keystroke logging and form grabbing. It is also used to install the CryptoLocker ransomware. Zeus is spread mainly through drive-by downloads and phishing schemes. First identified in July 2007 when it was used to steal information from the United States Department of Transportation, it became more widespread in March 2009. In June 2009 security company Prevx discovered that Zeus had compromised over 74,000 FTP accounts on websites of such companies as the Bank of America, NASA, Monster.com, ABC, Oracle, Play.com, Cisco, Amazon, and BusinessWeek. Similarly to Koobface, Zeus has also been used to trick victims of technical support scams into giving the scam artists money through pop-up messages that claim the user has a virus, when in reality they might have no viruses at all. The scammers may use programs such as Command prompt or Event viewer to make the user believe that their computer is infected.

<span class="mw-page-title-main">Norton Security</span> Computer security suite by NortonLifeLock

Norton Security is a cross-platform security suite that provides subscription-based real-time malware prevention and removal in addition to identity theft protection and performance tuning tools. Other features include a personal firewall, email spam filtering, and phishing protection. It was released on September 23, 2014. In April 2019 it has been replaced by the Norton 360 brand.

Norton 360 was an "all-in-one" security suite for the consumer market developed by Symantec. Originally released in 2006, it was discontinued in 2014; its features were carried over to its successor, Norton Security.

References

  1. "Norton AntiBot Upgrades & Renewals". Symantec Corporation. Retrieved 5 April 2009.
  2. "Symantec Arms Consumers Against PC Hijackers with Norton AntiBot". WebWire. 20 July 2007. Retrieved 5 April 2009.
  3. Sharon Gaudin (8 June 2007). "Symantec Moves Anti-Botnet Weapon Into Public Test". United Business Media LLC. Retrieved 5 April 2009.
  4. Robert Vamosi (7 June 2007). "Norton AntiBot goes into public beta". CNET . Retrieved 5 April 2009.
  5. Erik Larkin (8 June 2007). "Symantec releases beta of Norton AntiBot software". IDG Communications. Retrieved 5 April 2009.
  6. Neil J. Rubenking (13 January 2009). "AVG Buys Sana's Behavior-Based Security Tech". PC Magazine . Retrieved 5 April 2009.
  7. David Meyer (13 January 2009). "AVG Technologies buys Sana Security". CBS Interactive Inc. Retrieved 5 April 2009.
  8. Stefanie Hoffman (13 January 2009). "AVG Acquires Sana Security, Adds ID Protection". 09 United Business Media LLC. Archived from the original on 4 June 2012. Retrieved 5 April 2009.
  9. Neil J. Rubenking (9 August 2007). "Norton AntiBot". PC Magazine . Retrieved 7 April 2009.
  10. Erik Larkin (7 June 2007). "Symantec Releases Beta of Norton AntiBot". PCWorld. Retrieved 5 April 2009.