Technology Review - Published By MIT
Advertisement

Spying on Spyware

Analysts say spyware writers are gaining the upper hand over computer security experts.

By Lamont Wood

Thursday, November 17, 2005

smaller text tool iconmedium text tool iconlarger text tool icon

With an estimated 72 percent of PCs in homes now bogged down by an average 24 spyware infections each, and with the number of websites disseminating spyware skyrocketing, the question arises: who's winning the war on spyware?

Indeed, the latest "State of Spyware" quarterly report released by Webroot Software, a security software firm in Boulder, CO (from which the figures above were taken) contains chilling news: the bad guys are now bringing up their big guns, so-called "rootkit" technology and "polymorphic" code. Both are being used more and more extensively in spyware, and most old-line anti-virus programs are helpless against them, claims Richard Stiennon, Webroot's vice president of threat research.

Spyware programs often exploit browser security holes to download themselves onto a user's hard drive, where they surreptitiously send back information about the user's Web-browsing habits. With rootkit technology, these files can make themselves invisible to the host computer's operating system, allowing spyware or virus files to take up residence deep within the machine and operate undetected.

Anti-virus programs that scan hard drives for malicious code aren't much help. Rootkit files "know when they are being scanned and stop doing anything," says industry analyst Rob Enderle, head of the Enderle Group in San Jose, CA. "They are incredibly dangerous, and operate at a level where the current generation of anti-malware products cannot operate."

The danger posed by rootkit technology was brought to the fore this month when a security expert discovered that Sony BMG Music Entertainment had placed rootkit files on as many as 20 popular music CDs, to keep them from being pirated by PC users. Sony has apologized and offered a fix -- but three examples of malicious software have already been found that took advantage of the rootkit files left on PCs by the Sony CDs, and several class action lawsuits are in the works.

Another virulent spyware tool, polymorphic software, uses multiple files with random names, so that each infection is unique, requiring a unique disinfectant. Your computer's operating system might spot one, but removing it manually won't solve the problem, since the infecting files monitor each other, and if one is removed the others summon a replacement from the Web.

"You have to understand which file to get rid of first -- it's like grabbing the tail of a snake," Stiennon says. But the main problem is that scanning for the dozen or so infection routes used by most older viruses no longer works, he says.

Comments

  • Vista wont solve the problem
    The problem with Vista is the huge number of PCs that will not be upgraded, just like all the W2k and W98 systems out there still whose owners are clueless about what their machines are doing.  Even if Vista is as good as Enderle thinks and Microsoft promises, malware exploits will get worse before the installed base upgrades fully.  So far, Mac OS X is a still safer choice for companies and individuals and a better choice for all internet users.
    Rate this comment: 12345
    Guest (Stephen Keese)
    11/18/2005
    Posts:1
    • Use Linux
      ... and be safe.
      Rate this comment: 12345
      Guest (RB)
      12/01/2005
      Posts:1
    • Use Linux
      ... and be safe.
      Rate this comment: 12345
      Guest (RB)
      12/01/2005
      Posts:1
  • Vista wont solve the problem
    The problem with Vista is the huge number of PCs that will not be upgraded, just like all the W2k and W98 systems out there still whose owners are clueless about what their machines are doing.  Even if Vista is as good as Enderle thinks and Microsoft promises, malware exploits will get worse before the installed base upgrades fully.  So far, Mac OS X is a still safer choice for companies and individuals and a better choice for all internet users.
    Rate this comment: 12345
    Guest (Stephen Keese)
    11/18/2005
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Making 3D Maps on the Move
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.