On The Insider: Movie Roles the Stars Turned Down
BNET Business Network:
BNET
TechRepublic
ZDNet

February 12th, 2009

Microsoft announces industry alliance, $250k reward to combat Conficker

Posted by Adam O'Donnell @ 12:12 pm

Categories: Anti Virus, Botnets, Malware, Microsoft, Viruses and Worms

Tags: Alliance, Industry, Microsoft Corp., Worm, Jose, Cyberthreats, Viruses And Worms, Security, Strategy, Management

Microsoft has announced an alliance of various industry partners whose goal is to fight the Conficker worm. The announcement is short on actionable methods for stopping the worm, but it does include one gem: a $250,000 (US) bounty for information leading to the capture of those responsible for the worm.

Microsoft is taking the Conficker worm pretty seriously. They have, for the first time, coordinated a group of industry representatives from security companies, consulting firms, and registrars to actively combat the outbreak. Microsoft is not limiting itself to technical solutions; they are offering a $250,000 reward for information that leads to the arrest of the worm’s authors.

The aforementioned group does not consist of bounty hunters.  They are trying a variety of operational techniques to slow down the botnet’s growth. Jose Nazario of Arbor Networks has filled in the gaps on what the group is actually planning:

One of the strategies being used by the group that has come together is to “soak up” the domain names being used by Conficker with pre-registration and lock. … That sinkhole data is being shared within the “cabal” and shared with customers: ISPs and their customers, enterprises, CERT teams, and others. This, in turn, is being used to try and clean up hosts with tools and information sheets with clear instructions.

Jose goes on to say that even though the update mechanism may be interdicted, the population of compromised machines will still be in the field. Yes, this is bad.

If you are interested in the technical analysis of how the bot works, I suggest you check out the extremely thorough writeup from SRI.

Adam O'DonnellAdam J. O'Donnell, Ph.D. is an R&D engineer who has focused on computer security since 2000. He currently is the Director of Emerging Technologies at Cloudmark, a messaging security company located in San Francisco. See his full profile and disclosure of his industry affiliations.

Email Adam O'Donnell

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 12 Talkback(s)
And how well did that go over?
NOT very...

The problem was that virus - Welchia - infected systems using the same attack vector as the Blaster worm. The problem is - it never logged what changes were made, generated a ton of... (Read the rest)
Posted by: Wolfie2K3 Posted on: 02/13/09 You are currently: a Guest | | Terms of Use
Taking seriously, eh?  forrestgump2000@... | 02/12/09
RE: Microsoft announces industry alliance, $250k reward to combat Conficker  gennx30 | 02/12/09
Safer? LOL!  GuidingLight | 02/12/09
Oh really?  storm14k | 02/12/09
Tough question ...  n0neXn0ne | 02/12/09
I seem to remember a few years ago...  itpro_z | 02/12/09
And how well did that go over?  Wolfie2K3 | 02/13/09
Microsoft should arrest themselves...  bbneo | 02/12/09
Much too lame  GuidingLight | 02/12/09
Arrest yourself  ExperiencedSoftwareDeveloper | 02/12/09
and arrest yourself too.....  spinit | 02/13/09
what what what on guy or small group have force MS to get out  Quebec-french | 02/13/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

Enterprise Applications

  • Check out some of the easiest and most powerful ways to boost productivity while saving money on your application infrastructure. See ZDNet's comprehensive Enterprise Application resource center, now!
  • New Online Dashboard
  • Read about top issues IT decision-makers face every day, plus get cost effective solutions to real life IT problems. Oracle Topline