Read up on the latest ideas and technologies from companies that sell hardware, software and services. CRM your salespeople will love
Email Archiving Implementation: Five Costly Mistakes to Avoid
Taking On Demand CRM Integration to the Next Level
Web Security SaaS: The Next Generation of Web Security
Email Archiving Technical Overview
Improving Sales Productivity: An Opportunity for Sales and IT Leadership
Radicati Market Quadrant 2008 on Corporate Web Security
Enterprise Wireless WLAN Security
Zones provide focussed content from Computerworld and leading technology partners.Newsletter Subscription
Gone are the days of amateur, single-source security threats as big business takes over creating an Internet filled with converged attacks.
University of Auckland computer security researcher Peter Gutmann gave a dim overview of the types of sophisticated software now used to take over computers to conduct cybercrime.
"There isn't really any single threat anymore," Gutmann said, adding as an example that spam is being used for identity theft.
"We've seen over the last 20 years a convergence of network technologies into this one big cloud called the Internet [and] the convergence of viruses and trojans into this one blended threat."
Speaking at this year's Australian Unix Users Group (AUUG) conference in Melbourne, Gutmann said spam and malicious code is becoming more sophisticated, because the businesses proliferating such threats are hiring professionals - from programmers to psychologists.
"Current viruses are written by paid professional programmers and they do serious amounts of testing on different environments," he said. "They're not just written by script kiddies. Some use digitally signed, encrypted updates that are equivalent to the Windows update."
Spam "vendors" are using PhDs in linguistics to bypass filters, and phishers use psychology graduates to craft their scams.
There is also some spamware that includes the open source Spamassassin anti-spam tool in its code to see if it will get through.
Gutmann said the spam business involves selling CDs with e-mail addresses at a price dependent on the quality of addresses.
"You go via a spam broker and use money to buy credits to send out spam messages," he said. "You can also buy 'botnets' and a machine can spam for 30 seconds then transfer to another bot which will spam for another 30 seconds, so it's virtually impossible to track them down."
Gutmann said most spam services are hosted in China where the ISPs don't care about it and bandwidth is cheap.
"Botnets are infinite resources of power and bandwidth," he said, adding many botnets are IRC-based which are not very resilient. However, the emergence of P2P botnets have made them more resilient and completely decentralized them.
"Freely available robots, like Agobot, can do all types of nasties, from harvesting e-mail addresses to packet sniffing and rootkit functionality.
"Ironically, botnets are full of 'good guys' PCs being taken over to send spam from DSL and cable Internet connections.
"With delivery mechanisms in place, malicious code has the ability to take control and manipulate the operating system down to the kernel level.
"Viruses can act as special-purpose spam relays, disable anti-virus software or modify anti-virus database files, and one even uses multiple levels of encryption.
"They're extraordinarily difficult to detect and specifically coded to stop anti-virus software from detecting it," Gutmann said.
Since a lot of software has user interface options to turn off security features, viruses can also be programmed to do this. Other common problems include installing rogue root certificates and patching the Windows kernel so that "everyone is running as root".
Gutmann cited BroadcastPC as an extreme example of malware which installs 65MB of .Net framework on the computer without the user being made aware of it.
Regarding phishing, Gutmann said like spam and viruses, it is being orchestrated by professionally run organizations.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
Fortinet Debuts Data Theft Detection and Prevention Security Appliance 2008-10-08 17:00:00+10
Open Text Positioned in Leaders Quadrant in Top Analyst Firm’s Enterprise Content Management Industry Report 2008-10-08 16:34:00+10
Carbonite Australia launches local website - www.carbonite.com.au 2008-10-08 15:54:00+10
Mid-Comp’s Odyssey supply chain solution allows Sydney University students to do their home work 2008-10-08 15:11:00+10
AIIA Challenges the ICT Industry to Reduce Australia's Carbon Footprint 2008-10-08 12:16:00+10
Revolutionising Back-up and Recovery
Rapid adoption of virtual server technology, and the challenges associated with the backup and recovery of ever-growing stores of information is causing a number of IT managers to reevaluate their data protection strategies. New backup and recovery methods which use data de-duplication technology to reduce capacity and network bandwidth requirements are being deployed to keep up with explosive data growth, shrinking backup windows, compliance initiatives and security concerns. Read on to find out more.











