• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

To catch a cyberthief: How Symantec does it

By
Stephanie N. Mehta
Stephanie N. Mehta
Down Arrow Button Icon
By
Stephanie N. Mehta
Stephanie N. Mehta
Down Arrow Button Icon
September 14, 2009, 6:00 AM ET

As cyber-heists become more daring, security firms have to deploy more resources to stay abreast of the bad guys.

CEO Salem compares cybercrime and security to an arms race. Photo:Symantec

By Julia Ioffe, contributor

Hacking used to be so quaint. In the old days (the early 90s) the villains typically were attention-seeking computer geeks infecting computers with viruses that were a headache for consumers and tech departments to debug.

Today’s cybercriminals are out to inflict real harm: They can be commercial entities breaking into competitors’ records, or international crime rings stealing valuable data like credit card numbers and email passwords.

And because such cyber-heists extremely lucrative – some estimates put the size of this underground economy at $1 trillion –more players are getting into the game, developing increasingly sophisticated ways to crack into computer systems and exploit their ill-gotten gains. Viruses alone can take trillions of forms, and spam, the most popular way of infiltrating computers, accounts for some 90% of all e-mail traffic.

All of which makes it harder for computer security companies to stay one step ahead of these evolving threats. “Clearly, it’s an arms race,” says Enrique Salem, CEO of Symantec, (SYMC) the world’s largest software security company. “They’re always trying to find ways of getting around our technology, so we’ve got to keep innovating” – and getting inside the criminal mind.

Symantec, based in Cupertino, Calif., continues to deploy a set of tried and true tools to keep digital risks at bay: Last year the company generated 1.6 million automated signatures –signatures are virus-specific cures– to block known attacks. Its software also automatically blacklists and filters bad programs and sites. And the company applies advanced behavioral technology to monitor and shut down malicious software just before it’s about to do something really harmful, thereby minimizing the impact on a corporate computer system or even an individual user.

But even this aggressive, multi-pronged approach isn’t enough to stop the bad guys. Blacklists are not fast enough to catch brand-new malware; “white lists” of safe software are too restrictive. And cybercriminals now generate malware automatically so that every visitor to, say, a bad website gets a slightly different version of the bug, making individualized cures highly impractical, if not impossible.

“Most of it is generated by virus-generating software,” says Steve Trilling, a former stand-up comedian and software engineer who runs Symantec’s STAR team, short for Security Technology and Response. “There are now many tens of millions of viruses out there, and you just can’t keep scaling at that rate.”

New protection codenamed “Mr. Clean”

And so last week Symantec launched the latest version of its Norton products with yet another layer of protection called Quorum (known internally as “Mr. Clean”). Quorum works in much the same way that the Zagat’s restaurant guide does, by relying on reputation. If you want to download a program that very few people in the world have, Quorum will recommend you stay away from it but leaves the ultimate choice to the consumer. After all, the program could be a randomly generated virus – or a highly-customized piece of software.

To prevent the program from blocking good software (what’s known as false positives), Quorum checks in with the back end and, if a program checks out, Quorum will not block it and slow the user down.

Symantec is able to calculate reputation with such confidence because, for the past year, 29 million Symantec customers have been using a Quorum prototype and automatically relaying data to the Symantec mother ship, where it is anonymized and crunched.

This provides Symantec with a large database from which to compute a program’s standing – and, with nearly 60 million Symantec customers around the world, that database is going to grow at a fast clip once the software is released on a wider market. And because the calculation is fully automated and based on a massive data base, hackers will have a difficult time distorting the real number of people who have downloaded their software.

This program also takes up less space and so can be run on mobile devices, which have yet to come under extensive attack. (Though the prospect is increasingly likely, industry watchers say, the mobile-device market is still too fragmented to be profitable for security companies; nor do people make many financial transactions on their phones – yet- making cell phones and BlackBerrys less likely to be attacked.)

Thwarting the Cult of the Dead Cow

But even cutting-edge software and a massive global infrastructure staffed by 17,500 employees cannot stop every single threat. To cut down on future breaches Symantec tries to educate school kids on smart web-browsing techniques. And it works with Congress and international governments to create a uniform legal standard to bring cybercriminals to justice. (The famous case of the ILOVEYOU Bug, in 2000, illustrates the need. When Symantec brought forward information pinpointing the Filipino hackers behind the globally infectious virus, all charges were dropped because the Philippines have no laws banning cybercrime.)

But as the cybercrooks get ever smarter, Symantec also is devoting more resources to the digital equivalent of “black ops” – folks who spend their days attending hacker events and trolling the ‘net for secretive chat rooms where the bad guys boast of their conquests and tactics. Every summer, for instance, hackers gather in Las Vegas for the Defcon Conferences – and Symantec goes, too.

One year, as a hacking group named Cult of the Dead Cow presented their new hacking techniques by lobbing informational discs (and hunks of raw meat) into the audience, Symantec reps ran them back to the hotel where a team of Symantec programmers sat churning out signatures, hobbling the tactics almost as soon as they were introduced.

It may sound a bit surreal, but CEO Salem tries to put the war on computer crimes into perspective: “You’re never going to eliminate crime,” he says. “You’re never going to eliminate cybercriminals and that’s going to be an ongoing challenge.” But to paraphrase an old saw: you have to think like a cyber criminal to catch a cybercriminal.

About the Author
By Stephanie N. Mehta
See full bioRight Arrow Button Icon

Latest in

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • Future 50
  • World’s Most Admired Companies
  • See All Rankings
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
Fortune Secondary Logo
  • About Us
  • Editorial Calendar
  • Press Center
  • Work At Fortune
  • Diversity And Inclusion
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in

Law
Alabama Gov. opts not to execute a man who didn’t kill anyone
By March 10, 2026
5 minutes ago
LawGold
Man hailed as a hero for finding the Ship of Gold and then jailed for losing the coins now released after a decade in prison
By The Associated Press and John SeewerMarch 10, 2026
10 minutes ago
NewslettersMPW Daily
Professional sports are desperate to reach female fans. So why did an NBA team try to host an event at a strip club?
By Emma HinchliffeMarch 10, 2026
16 minutes ago
Lloyd Blankfein, former CEO of Goldman Sachs
SuccessEducation
Former Goldman Sachs CEO got into Harvard at 16, growing up in Brooklyn public housing—he still says college is the best ticket to the middle class
By Emma BurleighMarch 10, 2026
27 minutes ago
Warren Buffett and Jane Fraser
SuccessCareers
Citi CEO Jane Fraser has a Warren Buffett-approved trick for dealing with a toxic boss or difficult colleague: ‘Never in anger, respond to that email’
By Preston ForeMarch 10, 2026
40 minutes ago
gu
PoliticsOlympics
Eileen Gu and Alysa Liu: 2 Olympians, 2 Californians, 2 countries
By Didi Tang and The Associated PressMarch 10, 2026
58 minutes ago

Most Popular

placeholder alt text
Real Estate
Billionaires Elon Musk and Mark Zuckerberg used mortgages to buy multimillion-dollar mansions. Here’s why that’s a savvy financial decision
By Sydney LakeMarch 9, 2026
1 day ago
placeholder alt text
Energy
Trump promised to fill America’s oil reserves ‘right to the top.’ A year later, oil has exceeded $100 and they’re still less than 60% full
By Tristan BoveMarch 9, 2026
23 hours ago
placeholder alt text
Middle East
Like Trump, Iran’s new supreme leader is a real estate mogul, with a house on ‘Billionaires’ Row,’ a villa in Dubai, and upscale European hotels
By Jason MaMarch 9, 2026
22 hours ago
placeholder alt text
Investing
Oracle is under pressure from more than $100 billion in debt and massive layoffs as it pushes ahead with Larry Ellison's 3-step transformation 
By Amanda GerutMarch 9, 2026
16 hours ago
placeholder alt text
Personal Finance
Current price of silver as of Monday, March 9, 2026
By Joseph HostetlerMarch 9, 2026
1 day ago
placeholder alt text
Energy
Oil over $100, markets in free fall, and Iran's new supreme leader is Trump's 'worst case' scenario
By Jim EdwardsMarch 9, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.