You are here: silicon.com > Software > Security Strategy

Security Strategy

Software EV SSL: The next weapon against malware?

Who really made your software?

Tags: malware, verisign, security

By Nick Heath

Published: 13 November 2008 12:21 GMT

The technology that protects consumers from spoof websites could be unleashed as the next weapon in the fight against malware.

Security company Verisign is looking at creating a system to certify software is what it claims to be, rather than malware masquerading as a software upgrade, for instance.

The vision is for a system which will work similarly to Verisign Extended Validation SSL (EV SSL), which turns web browsers' address bar green to guarantee that sites are genuine and not malicious.

The proposed system for authenticating software could flash up a symbol during the installation process certifying software was created by the organisation it purported to be.

The plans are being discussed by the Certification Authority Browser Forum, a voluntary organisation of certification authorities and vendors of internet browser software, including Microsoft, that helped develop the EV SSL certificate system.

silicon.com Financial Services

Get the latest financial services news straight to your inbox. Sign up for the FS newsletter today!

Verisign would offer certificates to software makers who passed its screening and auditing criteria - much in the same way that it does to online organisations signing up for EV SSL certificates.

The operating system would hold a list of certificates issued to trustworthy software makers and check for the certificates within the software during installation.

A spokesman for Verisign said: "We are looking to expand the SSL to other certificate types where we will know the identity of the author of a piece of software before you install it on the machine.

"The OS would control what it looks like."

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
Citrix Technical Support Engineer - Networking Support Group

Strong understanding of TCP/IP, the OSI Model and network infrastructure protocols (SSL/TLS, DNS, DHCP, WINS, NTP, FTP, HTTP, SMTP, CIFS, LDAP, and ...

Network Administrator (IT Support)

Desirable Skills / Experience Citrix support Cisco PIX ...

Customer Implementation Engineering Group Team Leader,

Is familiar with other communications protocols, specifically TPAD APACS, ISO8583, SSL, and SDLC/HDLC. Cisco certification is recommended ...

Agenda Setters 2008
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: