Microsoft Windows Vista Community Forums - Vistaheads
Recommended Download - Clean, repair and optimize your system



Welcome to the Microsoft Windows Vista Community Forums - Vistaheads, YOUR Largest Resource for Windows Vista related information.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so , join our community today!

If you have any problems with the registration process or your account login, please contact us.

Driver Scanner 2009 - Free Scan Now

Thoughts on Security Intelligence (McColo Corp alleged spam/malware host knocked offline), (Wed, Nov 12th)

Security News




Recommended Fix - Fix Vista Errors and Optimize Performance

Click On Your Flag for Translation
Simplified Chinese French Spanish Italian Portugeuse Japanese German Dutch
Driver Scanner 2009 - Free Scan Now
Reply
  #1 (permalink)  
Old 11-12-2008
Steve's Avatar
Moderator
 
Join Date: Sep 2006
Location: Emerald Isle
Posts: 57,918
Steve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to beholdSteve is a splendid one to behold
Thanks: 11
Thanked 92 Times in 21 Posts
Thoughts on Security Intelligence (McColo Corp alleged spam/malware host knocked offline), (Wed, Nov 12th)
Based on the investigative research of the Washington Post's Brian Krebs, US-based McColo has been taken offline by their various upstream providers. This has once again led to discussion on the merits of knocking the bad guys offline compared to doing security intelligence and mitigating the threats they pose. First, some details.
The McColo network not only was a large source of spam in the US (check your spam counts, you'll see a noticeable drop), but also trafficked in child pornography and malware. Skipping past allegations of whether or not McColo is culpable, the badness certainly was on their network and it wasn't been addressed. It has been known that McColo was home to some of this stuff that was sitting in a San Jose, California data center.
Herein lies the problem. When security researchers discover where bad behavior is coming from, do they take it offline or do they do research to try to mitigate the threats posed. In the case of child porn, the answer should be obvious, but the question is more about malware / spam operations. At first glance, it is tempting to simply glean information from these people while they are unaware of us watching, but I argue this is a poor long-term strategy.
Intelligence is not an end-product, it is a tool. You do *something* with intelligence, you don't gather it for the sake of gathering it. Creating signatures for AV/AM, IDS/IPS and spam filters is great, but the statistics show that the bad guys are adapting just as fast as we churn out signatures. In short, waiting for them to adapt and then creating counter-measures only ensures that they get the first win (or what I call the First Win Principle). We only can react after they've already stolen information. This is a bad thing tm.
That isn't to say we should chuck AV/AM and reactive security overboard, far from it. But to truly achieve results in securing cyberspace, we need to be proactive. You don't win an information war solely by playing defense. Spam, malware, electronic crime and the like keep working and keep proliferating for two reasons:
1) It is very cheap

2) It is very profitable
The costs from prosecution and the costs from being shut down are negligible so the bad guys can use their finite resources to keep developing their techniques and technologies to get around our countermeasures. And they are winning. The key to fighting spam and malware is to make them more costly and less profitable. Sure, knocking these people offline only causes them to go elsewhere, but it imposes costs on them to move their operations, costs to increase their own security and defensive posture and gives us time to breathe. From a purely economic standpoint, as long as the costs are low and the gains are high, bad behavior will continue to increase and evolve to the point where our current strategies will simply no longer work.
There is a place for security intelligence and research. When we find these nests of badness we should glean all we can from them, but then we need to shut it down. Knowing where the bad guys are doesn't help the people who get their identities stolen. The only long-term solution is increased prosecution and imposing increased costs on the bad guys.
Thoughts? Use our contact form and let us know what you think.
--

John Bambenek

bambenek /at/ gmail \dot\ com

More...
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Security World: Barack Obama used for a malware spam attack Steve Security News 0 11-06-2008 11:30
Security World: October 2008 malware and spam geographical and vertical trends Steve Security News 0 11-03-2008 15:30
Security World: Q3 spam and malware trends statistics and analysis Steve Security News 0 10-28-2008 21:10
Hackers knocked Comcast.net offline Paul Security News 0 05-30-2008 18:10
Security issue with malware on Vista bypasses UAC and sends out SPAM Grant - CNW microsoft.public.windows.vista.security 12 01-22-2008 05:56




All times are GMT +1. The time now is 12:20.




Driver Scanner - Free Scan Now

Vistaheads.com is part of the Heads Network. See also XPHeads.com and Win7Heads.com.


Funny Commercials to make you laugh :-)

Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.3.2

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119