In Depth

Spyware: Scumware Out There

Security vendors big and small are in an arms race to root out spyware and other malicious code, but so far they're all losing.

By Sarah D. Scalet

November 01, 2004CSO — Maybe I clicked "no" in a dialog box that I ought to have closed, or installed a bogus version of a browser plug-in. Maybe I just visited the wrong website on the wrong day, and with my Web browser's unwitting compliance became a victim of a drive-by downloading of rogue software. Whatever the case, my punishment was brilliant and unstoppable. The spyware hijacked my Web browser and bombarded me with pop-up ads, even when the browser was closed and the network connection was unplugged. It made dubious offers of antispyware tools that would supposedly clean my system, yet hid from three legitimate cleaning tools and my antivirus software. It resisted my attempts to close it from the Windows task manager or delete it from the startup file. Applications ran grindingly slowly, and my system crashed so often that it was rendered useless. Whenever I thought I had the monster killed, it reared its ugly head again.

Finally, my company's IT technicians threw up their hands and reformatted my hard drive, mystery unsolved.

Along the way, something happened to me that observers say has happened to a critical mass of even the most security-savvy computer users over the past six months: Spyware became not just a nuisance but a plague that brought my productivity to a screeching halt.

"In enterprise, the guys are telling me that as much as 25 percent of their desktops at any time are affected by increasingly destabilizing software," says Peter Firstbrook, an analyst at Meta Group. "It's their number-one help desk issue."

"We have evidence that [spyware] is at least partially responsible for approximately half of the application crashes our customers report to us," Jeffrey Friedberg, Microsoft's director of Windows privacy, told Congress last spring—and you know that's a lot of application crashes. "It has become a multimillion-dollar support issue."

"We've never seen malicious code to the level we've seen in the last six months," says Ed Skoudis, author of Malware: Fighting Malicious Code. "It's just exploded."

Unfortunately for CSOs, there simply isn't an automatic or foolproof way to make sure their companies' computer systems aren't infected with this type of malware. Antivirus vendors are still figuring out how to change their business models to encompass the threat, and antispyware boutique firms are struggling to roll out enterprise versions of their consumer-oriented products. Legislation and case law are only just emerging, even as the companies involved hurl lawsuits at one another faster than you can say "reboot." Meanwhile, creators of spyware and its trickster cousin, adware, are developing versions of their wares that are so elusive and pervasive that they've earned a nickname: scumware.

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Data Center Directions Virtual Conference

Data Center VCAttend this free, 100% online event exploring tools and techniques for making your data center deliver for today and tomorrow.

» Learn more and register here

WEBCAST
The Surest Path to Effective and Efficient Compliance

VeriSignIn this webcast, we explore why and how — with best practices, practical tips and solutions that work — to ease your compliance challenge.

» View the webcast

Featured Sponsors
Sponsored Links

IS/IT Project Mgt. Credentials From Villanova - 100% Online

Learn how the new Quad-Core AMD Opteron™ processor improves performance

Data Protection: Challenges for the Traveling User

Key strategies for C-level executives and security staff

E-LOAN Maintains Reputation as a Privacy Leader with Symantec

Data Loss Prevention: Keeping Sensitive Data Out of the Wrong Hands

Prudential Financial Protects its Brand with Symantec

Envision Identity-Based Access Control for the Datacenter

Using Likewise to Comply with PCI Data Security Standard

Think your data is safe? Think again. It's time to Outthink the Threat. Get eBook now

IDC Defines an Identity and Access Management Submarket

IDC Defines an Identity and Access Management Submarket for Managing Privileged User Accounts and Meeting GRC Requirements

Everything Today's CISO Needs to Know About Using SSO to Succeed in the Web 2.0 Era

Configuration Assessment: Choosing the Right Solution

Revolutionizing Endpoint Security with a Single Agent

Envision Identity-Based Access Control for the Datacenter

Rolling the dice with your security? Take the Self-Assessment Test now

7 Requirements of Data Loss Prevention

Information Security: Data Drains and How to Prevent Loss

How Are Open Source Development Communities Embracing Security Best Practices?

Digital Identity Protection and Data Security Get Personal

The Case for Business Software Assurance ~ Securing Your Applications

Diebold: Frost & Sullivan Global Physical Security Systems Integrator of the Year

Welcome to the age of Service-Oriented Security (SOS)

Enabling Compliance with Converged Mainframe Security and Storage