Friday, January 30, 2004

Antivirus feature creates a burden - News - ZDNet:
"A common antivirus feature that automatically replies to e-mails infected with a virus--to inform the senders that they are infected--is obsolete and should be disabled, because it creates almost as much trouble as the virus itself, according to security experts.

When an antivirus application detects malware in an e-mail, such as the recent MyDoom worm, it can automatically reply to senders of messages to inform them that they have been infected. However, virtually all modern e-mail viruses disguise the original senders' addresses by spoofing the 'to' field of the reply message with stolen, but valid, e-mail addresses. This means that users receive e-mails telling them that they are infected when they are not, resulting in significant quantities of unnecessary traffic. "

This additional traffic is a further burden on administrators, because it occurs when companies are trying to clean their systems from the virus attack. Jack Clark, technology consultant at McAfee, an antivirus division of Network Associates, estimates that "bounce-back" e-mails play a significant part in slowing down corporate networks and says the feature should be disabled immediately.

http://zdnet.com.com/2100-1105_2-5148995.html

No comments: