Why no news is bad news -- at least when it comes to malware

By Markus Jakobsson  Add a new comment

Once upon a time, malware authors wrote code to infect thousands of machines for entertainment and intellectual stimulation. Today, it's all about the money, and the greatest threat may lie in the silence, making a far more dangerous landscape.

Let's look back at the brief history of malware. It is 1986, and the first computer virus has just been released. The "brain virus" -- a benevolent-acting boot sector virus that immediately declares its presence on an infected machine. Ten years later, researchers at Columbia University predict that crypto-enabled ransomware may strike -- the Archiveus Trojan fulfills the prophecy. It encrypts files on infected machines and offers the decryption key for sale. Yet a few years later, keyloggers become part of the everyday threat on the Internet. What has changed? They do not announce their presence. They hide. They spy. This is an important change in functionality, in particular when we talk about security attitudes of typical Internet users. To many, if the malware does not announce its presence, it simply is not there.

With practically no worries, people will install "fun applications" -- games, screensavers, and other cute things that will put their machines in harm's way. Many people do not realize that a game may moonlight as a keylogger, a method of capturing and recording userkeystrokes. People will click "yes" if they are asked to install something time after time after time, and the question just won't go away as long as they click "no". Offer people convenience over security, and security will lose. The average Internet user is more lazy than security aware.

Average Internet users will play full-screen movies sent by friends, even if it means running self-signed executables (these are programs that have been certified to be good -- but not by a trusted entity, but by the person who wrote the program.) They will buy and install pirated software, which of course can have been gently augmented to include malware. Ironically, a large portion of pirated anti-virus software may not help the user too much. And of course, it does not matter whether the original version was made by a respectable anti-virus vendor or not. People will put up their own websites, but not quite know how to manage their security. Many of these sites (unwittingly to their owners) become hosts for malware.

People do not know that their machines have been infected these days because it is not in the best interests of the malware authors that they do.

The silence is deadly. And because money is the main motivator, the term crimeware is increasingly being used instead of malware.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question