VB2017 preview: Calling all PUA fighters

Posted by   Martijn Grooten on   Aug 31, 2017

While a lot of attention is focused on the fight against advanced malware, a different kind of threat is providing just as big a headache for security companies: that of apps (often free ones) whose behaviours sit right on the limits of what is acceptable from a security point of view. The "better safe than sorry" approach preferred by security vendors usually doesn't align with the views of their customers – or those of the often powerful lawyers employed by the vendors of some of these apps.

Last year, industry veteran Dennis Batchelder set up AppEsteem to take an interesting and pragmatic approach to this issue. Rather than come up with even more complicated ways of blocking potentially unwanted apps, he is working with the app developers and distributors themselves, to ensure they stay within the limits of what is acceptable from a security point of view. AppEsteem then provides feeds and services to security vendors, to help them avoid blocking such apps – while at the same time, making it easier to block those that do engage in malicious or deceptive behaviour.

We have asked Dennis to give a Small Talk at VB2017 to discuss how this works, and to explain how security vendors and testers can make use of AppEsteem's services.

Don't forget to register for VB2017 to learn about the latest threats, how to fight them and how to collaborate with others in the industry.

VB2017-325w.jpg

 

twitter.png
fb.png
linkedin.png
googleplus.png
reddit.png

 

Latest posts:

What kind of people attend Virus Bulletin conferences?

If you are considering submitting a proposal for a talk to VB2018 and you're not familiar with the event, you may find it useful to know what kind of people attend the conference.

Olympic Games target of malware, again

An unattributed malware attack has disrupted some computer systems of the 2018 Winter Olympics. In 1994, a computer virus also targeted the Winter Olympics.

There are lessons to be learned from government websites serving cryptocurrency miners

Thousands of websites, including many sites of government organisations in the UK, the US and Sweden, were recently found to have been serving a cryptocurrency miner. More interesting than the incident itself, though, are the lessons that can be…

We need to continue the debate on the ethics and perils of publishing security research

An article by security researcher Collin Anderson reopens the debate on whether publishing threat analyses is always in the public interest.

WordPress users urged to manually update to fix bug that prevents automatic updating

Users of the popular WordPress content management system are urged to manually update their installation to version 4.9.4, as a bug in the previous version broke the ability to automatically install updates.