On last.fm: Taylor Swift photos and free music!
BNET Business Network:
BNET
TechRepublic
ZDNet

July 9th, 2008

The key to an open, transparent malware filtering system

Posted by Ryan Naraine @ 8:43 am

Categories: Anti Virus, Arbitrary Code Execution, Botnets, Browsers, Data theft, Firefox, Java, Malware, Microsoft, Pen testing, Social Networking Applications, Spam and Phishing, Viruses and Worms, Web Applications

Tags: Malware, Web Site, Site, Web Site Development, Web Technology, Viruses And Worms, Security, Internet, Ryan Naraine

* Ryan Naraine is on vacation.

Guest editorial by Max Weinstein

Max WeinsteinIt’s no secret that Web sites have become a medium of choice for delivering malware and soliciting personal information for criminal use. One increasingly popular approach to addressing this problem is warning users when they try to visit websites believed to be a threat. Firefox, IE, Yahoo! search and Google search are among the products that offer some form of integrated warning to their users, and nearly every anti-virus vendor is now offering a web warning or blocking product, as well.

There’s a good reason for this approach’s popularity: it works reasonably well. Although not perfect — fast-flux attacks and other techniques sometimes keep the filters a step behind the bad sites — we know that many users will skip sites that they’ve been warned against, and therefore avoid possible infection.

Not all filters and blocking services are created equal, however, and I’m not referring to the interface or the list of dangerous sites. Instead, I’m talking about the approach companies take to ensure that this de facto filtering is done fairly and accurately.

Imagine this scenario: you are a small business Web site owner running a simple shopping cart application. You’re doing decent business, when suddenly, one day, your business and site traffic drop off by 20 percent, and you have no idea why. Your Google PageRank hasn’t changed, you haven’t done anything new, and you don’t know of any new competitors. Only after a loyal customer e-mails you a few days later to tell you that he received a warning from his AV software about your site are you able to figure out what’s happening.

You try to go to the AV vendor’s website, but you can’t find any information about why your site is receiving a warning, and an e-mail to the company goes unanswered. In this scenario, one of two things happened, neither of which is acceptable: your site was flagged erroneously when there was nothing wrong, or your site was compromised, and no one is helping you to fix it and restore your site’s security and reputation. Either way, you and your potential customers got hurt.

The same problem has historically occurred with certain spam blacklists and other approaches that have attempted to protect users but, in so doing, created collateral damage to well-intentioned and sometimes completely innocent site or network owners.

A good filtering system, then, isn’t just about collecting a list of bad sites and warning users about them. Instead, it requires all of these traits:

  • A low false-positive rate
  • Clear, publicly-available criteria for determining which sites are listed
  • Information about why a particular site is listed
  • A transparent, responsive process for requesting removal of incorrect or outdated listings
  • Support and education for owners of compromised sites

Note that a system with all of these traits isn’t just better for the website owners; it’s better for the end users, too. It ensures that they aren’t being kept away from their favorite sites (or new sites that they’ve yet to discover) any longer than necessary. With a little additional effort, the provider can also use the warnings as a way to educate consumers about the danger of drive-by downloads or phishing and how to protect themselves more generally from malware.

One of the reasons StopBadware.org exists is to help realize this ideal of an open, transparent system that protects and educates, that serves end users and site owners. It’s not easy, and one could argue that we’re not fully there yet, but we continue working with our partners and keeping our door open to new partners who are committed to these principles. I hope that as website warning products evolve and mature, we will see more companies producing systems that are designed with the broadest public interest in mind.

* Maxim Weinstein is the manager of StopBadware.org, a partnership among academic institutions, technology industry leaders, and volunteers committed to protecting computer users from threats to their privacy and security caused by bad software.

Ryan NaraineRyan Naraine is a journalist and security evangelist at Kaspersky Lab. He manages Threatpost.com, a security news portal. Here is Ryan's full profile and disclosure of his industry affiliations.


Email Ryan Naraine

For daily updates on Ryan's activities, follow him on Twitter.

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 25 Talkback(s)
Slow?
I'm not an Open DNS user, but couldn't you just run a caching nameserver on your network to mitigate this?... (Read the rest)
Posted by: JDThompson Posted on: 07/26/08 You are currently: a Guest | | Terms of Use
Open DNS  aeriform | 07/09/08
OpenDNS is slow  qmlscycrajg | 07/10/08
not always  tech_walker | 07/10/08
OpenDNS  gypkap@... | 07/14/08
Slow?  JDThompson | 07/26/08
Malware filtering  gsteck | 07/09/08
RE: The key to an open, transparent malware filtering system  rdhalsteatzd | 07/09/08
RE: The key to an open, transparent malware filtering system  jokerscool@... | 07/09/08
RE: The key to an open, transparent malware filtering system  El Condor | 07/09/08
RE: The key to an open, transparent malware filtering system  Rafal.Los (RX8volution) | 07/09/08
RE: The key to an open, transparent malware filtering system  bharat_kantharia@... | 07/09/08
Another approach !  sloer@... | 07/09/08
e-mail is easy  Sagax- | 07/10/08
RE: The key to an open, transparent malware filtering system  justinseinlin | 07/10/08
Personally  mtgarden | 07/10/08
Been there too  Sagax- | 07/10/08
International Organizations???  Sagax- | 07/10/08
Myspace, Facebook, AIM Dashboard  rebelxhardcore | 07/10/08
Wondering if you run as admin  tech_walker | 07/10/08
Running AV again...  JCitizen | 07/10/08
Censoring the Internet will close it!  Thempleton | 07/12/08
RE: The key to an open, transparent malware filtering system  jasonwheeler | 07/13/08
RE: The key to an open, transparent malware filtering system  solie1953@... | 07/14/08
what goes around comes around...  aswarm@... | 07/14/08
RE: The key to an open, transparent malware filtering system  george@... | 07/14/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads