Readers: 9 | Updated: 04-17

Malware threat lists slammed as 'useless'

Translate Into:

Security vendor PC Tools has questioned the usefulness of the threat lists used by many security companies to warn of current malware attacks.

The problem, according to the Australian company, is that the lists -- which are now regularly issued by almost every security software company -- measure volumes rather than the underlying danger of a particular type of malware.

PC Tools, itself an anti-malware vendor in the same space, dismisses them as being "of no practical use for the security industry or consumers," and, not surprisingly, advocates its own ThreatExpert analysis system that cross-references volume with other factors such as the design complexity of a threat, its innovation, and its payload.

Examples of threats that regularly turn up on some lists but which pose relatively little danger include the four year-old Netsky, and the packer NSAnti, which itself is merely a means of hiding malware, and shouldn't even appear on such lists at all, the company said.

"Threat analysis is highly complex. There was a time when volume alone was an acceptable indicator of the level of threat. But the threat landscape has changed significantly and there are a number of additional parameters, besides volume, which are equally, if not more important in identifying and classifying top threats," said PC Tools CEO, Simon Clausen.

The underlying problem highlighted by the PC Tools blast is an interesting one. There is little independent security data that can be quickly understood by even experienced users. Typically, information lies in the hands of self-interested security vendors, who use it for marketing purposes.

There are a few exceptions to the rule such as third-party security information providers such as Danish outfit Secunia, but they focus on new threats. Working out which pose the greatest risk still requires a means of cross-checking real-world volumes with sophistication analyzed by looking at source code.

And then there is the dark suspicion many malware watchers have that the most dangerous attacks are the ones you never or rarely hear about until the criminals are long gone.

The company puts forward its own suggestions for the malware that the average user -- which is to say moderately protected user -- should worry about right now. These include the bot-builders Kraken/Bobax, Srizbi, Cutwail/Pandex as well as the ubiquitous Storm family.

Other popular and current threats include the fascinating MBR-infector Mebroot, which has attracted plenty of attention from industry insiders who see it as a clever throwback to virus techniques thought long dead, and social engineering infectors such as Zlob, which masquerades as a legitimate anti-spyware program.

Carole Theriault of Sophos took issue with the PC Tools assessment of threat lists in the strongest terms.

"I don't know of any reputable security company that only publishes top threat info without giving context or explanations. Talking about why a threat is more prevalent than any other is a great way to get the message out to computers users about the importance of security," she said.

"The mere fact that Netsky is still hammering away and infecting systems is VERY important. It shows that there are a large numbers of computers out there that have completely inadequate or nonexistent computer security."

Techworld is an InfoWorld affiliate.


From The Blogs

Andy Beal's Marketing Pilgrim

03-05
Should Search Engines Do More about Malware?
Last month, Google released a report stating that 1.3% of search queries returned malicious results, which included malware.Many people took this as reason to panic and immediately asked Why arent the... 查看全文

/Film

05-17
M. Night Shyamalan’s The Happening Slammed and New 5-Minute Video Clip
Our friends at Collider have the first reader review of M. Night Shyamalan’s The Happening and it’s not good at all: “The Happening is a terrible, terrible movie. I mean, its bad on an epic scale. Its... 查看全文

Slashdot

05-17
Shape-Shifting Malware Hits the Web
Stony Stevenson writes to tell us that in a recent interview, Marc Henauer has revealed that security researchers are falling behind now that malware is starting to be able to change its signature eve... 查看全文

InfoWorld RSS Feed

05-23
Anti-malware group scolds Apple over Safari 'carpet bomb'
An anti-malware organization has called on Apple to beef up its Safari Web browser to protect users from exploits that could let attackers download malicious code to a Mac or Windows users desktop.Sto... 查看全文

Google Blogoscoped

05-24
Does a Site Have Malware? Google Provides Diagnosis
Google put up a new* malware diagnosis service; just append any domainyour domain or another site you want to check onto the end of the URL google.com/safebrowsing/diagnostic?site=", or paste a domain... 查看全文

Google Operating System

05-24
Google Anti-Malware Diagnostic Pages
ZDNet's security blog points to an update to Google's malware warnings. Like McAfee SiteAdvisor, now each web site has a special diagnostic page that lists answers to four questions:1. What is the cur... 查看全文

不钻牛角尖

05-27
Comodo BOClean Anti-Malware使用指南
Comodo BOClean Anti-Malware是一款完全免费的反恶意程序软件(好像comodo的产品都是免费的),目前最新的版本是4.26,Changes to code for Vista ... 查看全文

Mashable!

06-06
Opera 9.5 Will Protect You Against Malware
It aint easy being Opera. On one hand, you have Internet Explorer, which is the default web browser in the worlds most used operating system. On the other, you have Firefox, media and open source comm... 查看全文

TechCrunch

06-07
Opera Browser Integrates Haute Secure to Block Malware
Opera, the Norwegian-based web browser, has struck a deal with Haute Secure to include malware detection and blocking in the browsers new 9.5 release.The new version is currently available as a beta, ... 查看全文

Consumerist

06-10
Gas Price Impact Map: Rural US Getting Slammed By $4 Gas [Fuel]
Suburban commuters may not enjoy paying an average of $4 a gallon for gas, but the rural US, where income levels are low and dependence on large vehicles is high, is getting hit the hardest says the N... 查看全文
More Articles