Desktop search: a new platform for malware scanning?

Andy Payne WholeSecurity, Inc.
Oliver Schmelzle WholeSecurity, Inc.

Desktop search is quickly becoming a core operating system component. Local search engines provide a holistic view of all files, email and other resources on a given desktop machine.

Combined with extensibility APIs these search engines could provide a powerful development platform for endpoint security products. For example, both Google Desktop Search and Apple's Spotlight technology in OS X can be extended through a public API. Using these APIs, executable files could be scanned for malicious signatures. Email inboxes could be searched for patterns related to spam and automatically filtered.

We discuss the details of desktop search engines that have APIs and compare their capabilities as platforms for malware scanning. We also present a prototype of an application that leverages a desktop search engine to perform scans of media that could contain malicious content. We compare this to traditional malware scanning approaches. Finally, we summarise our experience with the prototype and its feasibility for real-world products.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Career Sidebar

VB100 certification

VB100 This month VB's test team put 26 products to the test on Windows Server 2008. John Hawes has the full results.
See full results.

Virus Bulletin currently has 190,610 registered users.