Search 
You are here: ArticlesEmail/Internet Security Issues and Tips   
ArticlesMinimize
IN FOCUS: Is ClamAV Vulnerable to a Corporate Attack?
Posted by SteveT on Thursday, February 07, 2008 :: Last Updated on Thursday, February 07, 2008:: Views 4618

   

Mark Joseph Edwards, News Editor, mark at ntsecurity / net

Software vulnerabilities caused by faulty code pop up every day, and most of them are fixed in a reasonably quick fashion. But there's another type of software vulnerability that's going unpatched. That vulnerability has to do with intellectual property and patent claims.

As you might know, Microsoft claimed that various open-source software packages, such as Linux and OpenOffice.org, violate as many as 235 of the company's patents. You can read more about Microsoft's claims at http://ct.email.windowsitpro.com/rd/cts?d=33-2082-803-202-5219-160766-0-0-0-1-2-207 (http://ct.email.windowsitpro.com/rd/cts?d=33-2082-803-202-5219-160767-0-0-0-1-2-207.

To date, none of Microsoft's claims have been backed up by evidence, so some Linux vendors think it's all a bunch of smoke and mirrors designed to frighten people away from using Linux.

Recently, Trend Micro has gone after Barracuda Networks -- an avid supporter of open-source projects -- because it includes the open-source ClamAV (www.clamwin.com/http://ct.email.windowsitpro.com/rd/cts?d=33-2082-803-202-5219-160768-0-0-0-1-2-207) in its Security appliances. In case, you've been living in a cave for the last five years, ClamAV is a hugely popular antimalware solution. More than one million people download its signature updates each day, if that gives you any idea as to how widespread its use has become. Many of those downloads come from a plethora of Windows users running a ported version of ClamAV.

Trend Micro's argument is that ClamAV violates at least one of Trend Micro's patents that centers on scanning for viruses at a gateway. Because Barracuda Networks uses ClamAV, Trend Micro decided to file a lawsuit against the company. Trend Micro hasn't openly stated why it didn't go after the developers of ClamAV directly, but it doesn't take a rocket scientist to figure out that because ClamAV is a free, open-source product, there's no money to be gained by suing the developers of ClamAV. Suing Barracuda Networks could kill two birds with one stone: Trend Micro might collect a ton of cash in a settlement, and the payment of a big settlement could, hypothetically, put Barracuda Networks out of business, thereby eliminating one of Trend Micro's competitors.

Interestingly enough, Sourcefire acquired ClamAV in December of 2007. Sourcefire is the company behind the hugely popular Snort Intrusion Detection and Prevention system. Why Trend Micro hasn't confronted Sourcefire regarding ClamAV is yet another mystery. Trend Micro's legal approach might have something to do with the terms of the General Public License (GPL).

Mysteries aside, Barracuda Networks isn't waiting for the other shoe to drop. The company is going after Trend Micro's patent claims and hopes to have the patent negated. To do so, Barracuda Networks will need evidence of a prior work that existed before Trend Micro filed for its patent. Right now, it seems that Barracuda Networks is looking to get its hands on a copy of MIMESweeper 1.0 because the company thinks that the software could possibly represent a prior work.

I'm no legal expert, so I have no idea which company's argument is stronger. If you're interesting in a pretty good amount of information about the battle, read Groklaw's article at www.groklaw.net/article.php?story=20080125135544713 (http://ct.email.windowsitpro.com/rd/cts?d=33-2082-803-202-5219-160769-0-0-0-1-2-207, which explains some of the finer points of the battle. But before you do that, head over to Barracuda Networks' Web site and read its summary of the allegations, which offers some good background information, at www.barracudanetworks.com/ns/legal/ (http://ct.email.windowsitpro.com/rd/cts?d=33-2082-803-202-5219-160770-0-0-0-1-2-207.

 

Previous Page | Next Page

COMMENTS


DonationsMinimize

Find our site useful? Make a donation to show your support

Donate

logo_ccMC.giflogo_ccVisa.giflogo_ccDiscover.giflogo_ccAmex.gif

ArGoStuff Supporters

 


News from ArGoSoftMinimize
1 2 3 4 5 6


Mail Server v1.0.8.3
  • Added support of STARTTLS (STLS) command for SMTP, POP3, IMAP, and SMTP relay and delivery, which will allow secure, fully encrypted connections, when possible;
11/6/2011 1:10:34 PM
Mail Server v1.0.8.2
  • Optimized delivery speed. In earlier versions each "tick" which was checking whether messages were in the outbox queue, was picking up only one message at a time. Now it will attempt to pick MaximumAllowedThreads-ActiveDelivery threads messages, which should considerably increase deliver speed;
  • Optimized SEARCH and STATUS IMAP commands. They appear to be used very extensively by Android, and (not that extensively, but still) by iPhone. Now users who use mobile phones to access their IMAP accounts will see considerable improvement;
  • Optimized STORE IMAP command. Before storing of IMAP flags was occuring one message at a time, which seemed to be fine with SQL server, but proved to be slow for SQLite... Now it happens with single SQL call.
10/8/2011 7:59:35 PM
ArGoSoft Mail Server v1.0.8.1
  • Fixed a bug: when using IMAP via Firefox with "When I delete a message, move it to Trash folder" option, marking messages in the trash folder was causing high CPU usage, and was taking some time, making the server pretty much non-responsive. The problem was happening only when using SQLite.
6/6/2011 9:33:36 PM
ArGoSoft Mail Server v1.0.8.0
  • Fixed a problem with web interface - was showing only first page of messages, and would not switch to other pages; In order to fix the web interface, mail server itself has to be updated;
  • When installint initially, was still using SQLite, even when SQL was requested;
  • There was a problem with switching from SQLite database engine to SQL server database engine: the SQL database was not being created;
5/23/2011 5:53:55 PM
ArGoSoft Mail Server .NET v1.0.7.9
  • The server no longer requires Microsoft SQL Server. If SQL server is not found, it will use SQLite engine, which does not require separate installation. If SQL server is found, then user will be prompted whether he wants to use it;
  • Made other improvements, such as, now mailbox rebuild indexes orphaned records, rather then deleting them, also added an opotion to increment UIDL validity of folder (both on the Mailbox viewer box);
  • Made minor improvements on web interface;
4/26/2011 9:47:25 PM


1 2 3 4 5 6

Protect Your Computer today withGet AVG Today


Home:ArGoStuff:Forums:Articles:Cyber Security Tips:FAQ:Downloads:Links
Copyright 2006-2011 by ArGoStuff Terms Of UsePrivacy Statement