Technology Review - Published By MIT
Advertisement

Spying on Spyware

Continued from page 1

By Lamont Wood

Thursday, November 17, 2005

smaller text tool iconmedium text tool iconlarger text tool icon

The war is still a long way from over, though, says Craig Schmugar, a virus research manager at McAfee Inc., the noted security software vendor in Santa Clara, CA. Both rootkits and polymorphic code have been around for several years, he says, and there are counter-measures that can be marshaled against them.

"Do the bad guys have an A-bomb? There has been speculation about that for years," Schmugar says. "There have been flare-ups, and there have been zero-day attacks [that is, malicious code using a trick unknown to the software vendors until the day of the attack], but most have been mitigated by good security policies and procedures. Then it becomes a race to implement the anti-technology."

But today there's a new factor changing the way viruses are created and delivered: money.

"Several years ago one of the ways we received sample viruses was directly from the authors, who wanted their five minutes of fame," says Schmugar. "It might come from an anonymous address, or from someone who says they had 'found' it. There are still some of those, but now money is the driving factor. They get advertising money from affiliate programs, so it behooves them to conceal their installation as long as they can."

In other words, lone, anti-social hackers have turned into an underground of socially aware advertisers, according to Schmugar, seeking to turn the world's PCs into little zombie billboards that can spring to life at the spyware writer's request. "Botmasters" have also arisen, he says, who control multiple infected computers by passing commands to them through Internet Relay Chat channels. They can test their "bot" spyware against multiple anti-virus programs until it proves it can survive, and then download it to the other machines they control.

In fact, last week federal agents arrested a man in California for allegedly controlling a vast network of 400,000 infected PCs. He supposedly rented them out to spammers or people who wanted to launch denial-of-service attacks (which flood a website with traffic and make is unusable), asking as little as 20 cents per infected machine. Now he faces federal prison, because some of those machines belonged to the U.S. Navy.

While viruses used to be circulated as e-mail attachments, today they are disseminated from websites that users are tricked into visiting. The sites cannot be traced because they're set up by infected bots, at arms-length from the botmaster, Schmugar explains.

Although increasingly many advertisers don't want to be associated with spyware, that backlash won't put an end to these electronic invasions. There are always other advertisers, typically pornographers, who don't care, says Schmugar.

Comments

  • Vista wont solve the problem
    The problem with Vista is the huge number of PCs that will not be upgraded, just like all the W2k and W98 systems out there still whose owners are clueless about what their machines are doing.  Even if Vista is as good as Enderle thinks and Microsoft promises, malware exploits will get worse before the installed base upgrades fully.  So far, Mac OS X is a still safer choice for companies and individuals and a better choice for all internet users.
    Rate this comment: 12345
    Guest (Stephen Keese)
    11/18/2005
    Posts:1
    • Use Linux
      ... and be safe.
      Rate this comment: 12345
      Guest (RB)
      12/01/2005
      Posts:1
    • Use Linux
      ... and be safe.
      Rate this comment: 12345
      Guest (RB)
      12/01/2005
      Posts:1
  • Vista wont solve the problem
    The problem with Vista is the huge number of PCs that will not be upgraded, just like all the W2k and W98 systems out there still whose owners are clueless about what their machines are doing.  Even if Vista is as good as Enderle thinks and Microsoft promises, malware exploits will get worse before the installed base upgrades fully.  So far, Mac OS X is a still safer choice for companies and individuals and a better choice for all internet users.
    Rate this comment: 12345
    Guest (Stephen Keese)
    11/18/2005
    Posts:1

Log In

Forgot your password?     Register »
Advertisement

Videos

Microsoft's Many Multitouch Mice
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 

The Compelling Case for Conferencing
Read how you can improve workload support and find IT efficiencies

Download

How Windows Server 2008 R2 Helps Optimize IT and Save you Money
Read how you can improve workload support and find IT efficiencies

Download

Windows Server 2008 R2 Hyper-V Live Migration
See how Windows Server 2008 R2 and Hyper-V enable virtualization and Live Migration

Download
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.