Thursday 4 April 2013

CASE 1 - CHAPTER 8 (WHEN ANTIVIRUS SOFTWARE CRIPPLES YOUR COMPUTERS)

The answers:

1. Management Factor which causing the McAfee's software is when the test simulation were done, management didn't run these for windows XP with service pack 3. Users using the McAfee's Virus Scan version 8.7, this affected to faulty update download.

Organization Factor is when the staff didn't work efficiently. McAfee update the virus scan that was intended to deal with the new viruse named "w32/wecorl.a". But the company doesn't detect the problem that this virus could make itself appears as the name svchost.exe, which a windows file that is critical to PC's performance.

Technology problem is without the svchost.exe, windows can't boot properly. McAfee determined that the majority of affected machines were using windows XP service pack 3 combined with McAfee Virus Scan 8.7. They also noted that the "Scan Process on Enabled" option the virus scan, off by default in most virus scan installation, was turned on in majority of effected computers. 

2. The business impact is the reputation to the McAfee company was dropped. Besides that, the customer also get impact because the users computer were crippled or totally not functional.

3. If I were an enterprise customer,I would consider McAfee's response to the problem is not be acceptable. Because the slipup caused the system becomes unsecured. McAfee also makes a mistake that without the svchost.exe, windows can't boot properly.Virus can users applied the update, tried rebooting their system, and were powerless to act as their systems went haywire, repeatedely rebooting, losing their network capabilities and their ability to detect USB drivers, which is the only way of fixing affected computers. 

4. They should implement the additional QA protocols for any releases that directly impact critical system files. McAfee is also rolling out additional capabilities in Atermis that will provide another level of protection against false positives by leveraging an expensive whitelist of critical system files and their associated cryptographic hashes. 

No comments:

Post a Comment