two
Volume 4, Number 35 -- September 19, 2007

In Search Of a More Secure Internet

Published: September 19, 2007

by Alex Woodie

It's no secret that the Internet has become a giant cesspool of sorts, teeming with a rich assortment of spyware, rootkits, spam, Trojans, exploit kits, and Russian crime bosses that continually evolve to maintain their edge. By some accounts, 30,000 Web sites are hacked every day. While the sheer hugeness of the Internet tends to mask the problems, it's no wonder we haven't all become digital hypochondriacs by now. Thanks to people like Roger Thompson of Exploit Prevention Labs, people may continue to enjoy the Internet from within a cocoon of ignorance.

As the chief technology officer of Exploit Prevention Labs, which is based in New Kingstown, Pennsylvania, Thompson's job is to keep an eye on the "bad guys" (as he puts it), and their attempts to use vulnerabilities in common software products to infect computers.

There's no shortage of work at EPL these days, as Thompson and his crew have been the first researchers to spot several hacks. These include the use of Google's AdWords for malware distribution and the compromise of a handful of small government Web sites to distribute malware. Just last weekend, Thompson discovered a drive-by exploit in an advertisement on Facebook.

Business is good these days for Thompson, which means it's bad for people who value security. "Every few years, the bad guys reinvent themselves and move the target," he says. "It used to be that most of the guys--mostly guys--who write virus do it to show their buddies how smart they were. They write worms to say they crashed the Internet, or infected 80 percent of the Internet overnight. That used to be the motivation. Eventually, those guys grew up and got a job, or got a girlfriend, and found something better to do, and stopped." But times have changed, and today's typical malware writer is working for profit, not fun.

One of the most disturbing trends in computer security these days has been the emergence of pre-packaged exploit kits, such as MPack, WebAttack, NeoSploit, and IcePack, that criminals can use to infect a large number of PCs in a short amount of time. "They're sold to people who want to be malicious Webmasters, but they don't have the skills to put together they're own exploit set. We see them all the time," Thompson says.

These kits, which emanate primarily from Russia, are professionally developed and pose a significant threat to Web security because traditional security tools, such as firewalls and antivirus software, have a hard time stopping them, says Thompson, who spends much of his time tracking the kits. "We know where the bad guys tend to be, and we know where their test servers are in many cases. We monitor what they're doing," he says.

A typical infection cycle goes as follows. A budding malicious Webmaster spends a few hundred dollars to get an exploit kit, and goes off to find a Web server or a group of Web servers that are susceptible to one or more of the vulnerabilities targeted by the exploit kit. Once the Web server is hacked, the malicious Webmaster will set up the Web site to infect the Web browsers of every visitor who visits that site. This malware could be used to do any number of things, including stealing the user's identity, installing "keyloggers" that capture the user's keyboard input, or installing mini servers that keep the whole ball rolling in the form of spam e-mails linking back to other malicious sites.

Thompson directs much of his research into LinkScanner, a security tool that he developed and which is sold by EPL (subscriptions cost $20 per year, although there is a free version, too). LinkScanner protects PC users from falling victim to Web attacks launched using these exploit kits, as well as others, by identifying the signatures of known exploit attacks, and then blocking them, even if the software they're using has a known security vulnerability.

"It's easy to explain, but it's not so easy to do," Thompson says of the techniques used by LinkScanner. "You have to know what the critical exploits are, and how to block them reliably." The majority of the big security software companies have yet to develop comparable technology to block attacks using these exploits, he says. (They can easily solve this deficiency by buying EPL, Thompson jokes halfheartedly.)

Business for malicious Webmasters (and hence EPL) looks to be good for the next few years, as the current Web 2.0 trend continues. That's because computer security is being weakened by modern coding techniques, especially AJAX (Asynchronous JavaScript and XML), Thompson says.

"Most people aren't thinking too hard about security. They're thinking about functionality and trying to get people to their Web site," Thompson says. "There's more and more AJAX, which allows mixing of code in the form of VBscript and JavaScript and data freely. We've sort of forgotten the lessons of the last 15 years that you should separate code and data."

In time, products like LinkScanner will become ubiquitous, Thompson predicts. "Good security is all about having as many layers in place as you can. You can't do without your firewall, and you can't do without antivirus. My view is you can't do without an anti-exploit filter to stop the Web-based things. And of course people should patch."

There has been a give and take between hackers and security professionals since Al Gore invented the Internet last century. There's nothing new in that. What is new is the level of professionalism and sophistication that hackers are exhibiting today.

Indeed, security on the Web will get worse before it gets better, according to Thompson. "The bad guys have gotten really good at infecting large number of Web sites," he says. "They don't want to crush the Internet anymore because if they got 10 million infections, it would be a waste. They couldn't handle it. They don't want to cut down the tree anymore. They just want to shake it and pick up the apples that fall off."




                     Post this story to del.icio.us
               Post this story to Digg
    Post this story to Slashdot


Sponsored By
IT SECURITY

Get Maximum Pain Relief for Your
Windows & Linux Integration!

Directory services play a critical role in ensuring computer networks
are properly secured and efficiently managed.

While Linux machines running in Microsoft Windows networks can
interoperate with Active Directory, configuration is complicated.
This is especially true for administrators lacking Linux expertise.

Download this FREE white paper to learn more.


Editor: Alex Woodie
Contributing Editors: Dan Burger, Joe Hertvik,
Shannon O'Donnell, Timothy Prickett Morgan
Publisher and Advertising Director: Jenny Thomas
Advertising Sales Representative: Kim Reed
Contact the Editors: To contact anyone on the IT Jungle Team
Go to our contacts page and send us a message.

Sponsored Links

COMMON:  Join us at the annual 2008 conference, March 30 - April 3, in Nashville, Tennessee
Vision Solutions:  MIMIX takes the work and worry out of Windows data protection
NowWhatJobs.net:  NowWhatJobs.net is the resource for job transitions after age 40

 

 

IT Jungle Store Top Book Picks

The System i Pocket RPG & RPG IV Guide: List Price, $69.95
The iSeries Pocket Database Guide: List Price, $59.00
The iSeries Pocket Developers' Guide: List Price, $59.00
The iSeries Pocket SQL Guide: List Price, $59.00
The iSeries Pocket Query Guide: List Price, $49.00
The iSeries Pocket WebFacing Primer: List Price, $39.00
Migrating to WebSphere Express for iSeries: List Price, $49.00
iSeries Express Web Implementer's Guide: List Price, $59.00
Getting Started with WebSphere Development Studio for iSeries: List Price, $79.95
Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
Getting Started with WebSphere Express for iSeries: List Price, $49.00
WebFacing Application Design and Development Guide: List Price, $55.00
Can the AS/400 Survive IBM?: List Price, $49.00
The All-Everything Machine: List Price, $29.95
Chip Wars: List Price, $29.95


 
The Four Hundred
EGL: The Future of Programming for the System i?

Rumored Layoffs at IBM Rochester Not True

HP Beats the System i on Integration for Midrange Shops

LANSA Packages Modernization; Leasing Covers it All

The Linux Beacon
Canonical, VMware Create Skinny Linux for Virtual Appliances

HP Engineers New Blade Server Box for SMB Shops

SCO Files for Bankruptcy Protection

Transitive Rejiggers Emulation Software, Adds Partners

Four Hundred Stuff
Windows Vista Poses Challenges to Emulation Vendors

NetCustomer Capitalizes on Dissatisfaction with Oracle

Infor Provides Details on SOA Roadmap

Microsoft Ships BizTalk Server R2

Big Iron
Leverage

Top Mainframe Stories From Around the Web

Chats, Webinars, Seminars, Shows, and Other Happenings

Four Hundred Guru
Reuse Deleted Records? *YES!

Accessing File Member Timestamps from a .NET C# Program

Admin Alert: A Primer for Changing Your i5/OS Startup Program

System i PTF Guide
September 15, 2007: Volume 9, Number 37

September 8, 2007: Volume 9, Number 36

September 1, 2007: Volume 9, Number 35

August 25, 2007: Volume 9, Number 34

August 18, 2007: Volume 9, Number 33

August 11, 2007: Volume 9, Number 32

The Unix Guardian
Sun Rolls Out Update for Solaris 10 Unix

AMD Gets Aggressive About Watts with Quad-Core Barcelonas

Transitive Rejiggers Emulation Software, Adds Partners

Sirius Expands Northeast Presence with SCS Buy

Four Hundred Monitor
Four Hundred Monitor's
Full iSeries Events Calendar

THIS ISSUE SPONSORED BY:

MKS
IT Security
Storage Guardian
World Data Products
Vibrant Technologies


Printer Friendly Version


TABLE OF CONTENTS
Microsoft Loses Antitrust Appeal in European Court

In Search Of a More Secure Internet

Sun and Microsoft Go All the Way with Windows

HP Engineers New Blade Server Box for SMB Shops

But Wait, There's More:

Opsware Adds Storage, Process Management with System 7 Tools . . . Visual Studio Group Gets New GM . . . Microsoft and Novell Open 'Interoperability Lab' . . . Microsoft Bags Two More Big Linux Customers . . . European Developers Embrace C#, AJAX . . . Virtual Earth to Power EPA Mapping Applications . . .

The Windows Observer

BACK ISSUES





 
Subscription Information:
You can unsubscribe, change your email address, or sign up for any of IT Jungle's free e-newsletters through our Web site at http://www.itjungle.com/sub/subscribe.html.

Copyright © 1996-2008 Guild Companies, Inc. All Rights Reserved.
Guild Companies, Inc., 50 Park Terrace East, Suite 8F, New York, NY 10034

Privacy Statement