Research suggests throttling viruses at the source
Wired is running an interesting story on some virus research that's being done at HP's labs that takes a different approach than current virus prevention software. Instead of focusing on preventing a machine from becoming infected in the first place, the idea is to curtail a virus' ability to spread from an infected machine.
Computers contaminated by a virus behave differently from uninfected computers. An infected computer's primary goal in life is to reproduce the virus it harbors. In order to do that, the infected computer will try to make connections –- through e-mail or directly -- with as many other computers as possible, as quickly as possible.
Williamson's idea hinges around slowing viral spread by limiting a computer's ability to connect to new computers.
Though the article suggests that this new technique sacrifices a few machines in favor of the greater good, I don't see why it couldn't be used in conjunction with existing virus protection software to produce an even more robust system.
As much as I hate to admit it, no matter how good virus protection software gets, you're still going to have users clicking on attachments they shouldn't. The only way to guard networks against that kind of irresponsibility may be to throttle viruses at the source.