IBM's ISS blasts security rival Trend Micro over bugs

By Gregg Keizer, Computerworld |  Security, IBM, ISS 2 comments

In an unusual move, a security company owned by IBM has publicly blasted a rival for not patching reported bugs in its enterprise-grade, server-side antivirus software.

On Monday, David Dewey, a researcher with IBM Corp.'s Internet Security Systems, explained why his company had released several advisories that covered multiple vulnerabilities in Trend Micro Inc.'s ServerProtect software, even though according to IBM, Trend has not fixed the flaws.

X-Force, the research arm of IBM's security group, reported the first bugs to Trend two years ago, said Dewey, and followed up with additional vulnerability reports through January 2008. But Trend's response was unsatisfactory. "Each time, Trend would assure us that fixes would be provided in the next scheduled patch," he said in a post to the X-Force blog. "We have worked with them through four security patches, and in all cases, the reported vulnerabilities were ignored or the solution they implemented was inadequate."

One fix Trend released, Dewey said, was "easily evaded in a matter of minutes after installation of the patch."

When X-Force got nowhere by working with Trend Micro directly, it instead tried to coordinate with its competitor through CERT/CC (Computer Emergency Response Team Coordination Center) and JPCERT, Japan's CERT group. Trend Micro is headquartered in Tokyo.

Even that, however, didn't work, Dewey claimed. "They responded to each of those organizations the same way they did to us, which was to dismiss true problem resolution and try to indicate their workarounds were sufficient to consider the issues addressed," he said.

X-Force essentially tossed in the towel. "It is apparent that we have reached a crossroads with Trend," Dewey said, "where they are unable or unwilling to sufficiently patch these eight critical vulnerabilities reported by X-Force. At this point, I feel it is important to let our customers know about the inherent and abundant security risks of running TrendMicro ServerProtect."

Tuesday, the company posted four advisories that sketched out only the vaguest details about the eight vulnerabilities X-Force says it has found in ServerProtect, an antivirus program that runs on Windows, Linux and Netware. Unlike traditional advisories, which are usually issued only after a patch is available, X-Force's omitted the kind of technical details that might give hackers clues on finding and exploiting the bugs.

A security researcher and an industry analyst both said X-Force's public chastising of Trend is unusual.

"Generally, the industry bands together and prefers not to speak poorly about others," said Andrew Storms, director of security operations at security vendor nCircle Network Security Inc. "Although what gets said in sales meetings when you are working for the PO isn't always so full of rainbows."

"It is kind of unusual," said John Pescatore, analyst and research fellow with Gartner Inc. "It's definitely the norm these days that security firms find vulnerabilities in each other's products, and X-Force has been one of the leaders in the last three or four years. And it looks like they followed responsible disclosure, gave Trend plenty of warning."

But in some ways, Pescatore said, X-Force broke an unspoken rule. "They definitely compete with each other," he said, referring to IBM's Internet Security Systems and Trend Micro. "Does the blog post warn users of the danger? That's what the vulnerability advisories are for. Would X-Force do the same thing if it found bugs in IBM's WebSphere? If IBM didn't patch fast enough or the patches didn't work too well, would they be blogging that, 'We've had it with IBM'?"

A spokeswoman for Trend Micro, meanwhile, responded to a call for comment by saying "Trend Micro has already issued security patches for ServerProtect," and ticking off a pair of updates issued in March and May of this year. She declined to answer any additional questions about X-Force's allegations, however.

In Pescatore's eyes, X-Force went too far. "If Microsoft was to find bugs in Linux and publicize them, we'd all be negative about Microsoft," he said. "Come on, take the high road."

2 comments

    Anonymous 2 years ago
    If you are like me then you have probably tired many different types of scans to try and protect your computer. There are many different options available but I have found that most of them pick up the same bugs whether you pay for the scan or download a free version. Search-and-destroy Antispyware (http://www.Search-and-destroy.com) is one of the best that I have found so far and it cost less than many of the other well-known scans on the market today. If you are searching for a good scan I suggest that you check out the antispyware solution from Search-and-destroy.
    Anonymous 3 years ago
    Trend has been telling their customers for at least two years to ditch the ServerProtect product and install OfficeScan on servers. Any administrator still using ServerProtect should have their head examined. Does Trend even still support ServerProtect?

      Add a comment

      Post a comment using one of these accounts
      Or join now
      At least 6 characters

      Note: Comment will appear soon after you have activated your account.
      Obscene/spam comments will be removed and accounts suspended.
      The information you submit is subject to our Privacy Policy and Terms of Service.

      ITworld LIVE

      SecurityWhite Papers & Webcasts

      White Paper

      Overcome Top 7 Admin Challenges of Active Directory

      As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

      White Paper

      Insiders Can Ruin Your Company. Take Action.

      Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

      White Paper

      Top Solutions and Tools to Prevent Devastating Malware

      Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

      White Paper

      Streamline Compliance and Increase ROI

      Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

      White Paper

      X-Ray of the PCI Process-4 Proactive Steps

      This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

      See more White Papers | Webcasts

      Ask a question

      Ask a Question