New User? Need help? Click here to register for free! Registering removes the advertisements.

Computer Cops
image image image image image image image image
Donations
If you found this site helpful, please donate to help keep it online
Don't want to use PayPal? Try our physical address
image
Prime Choice
· Head Lines
· Advisories (All)
· Dnld of the Week!
· CCSP News Ltrs
· Find a Cure!

· Ian T's (AR 23)
· Marcia's (CO8)
· Bill G's (CO11)
· Paul's (AR 5)
· Robin's (AR 2)

· Ian T's Archive
· Marcia's Archive
· Bill G's Archive
· Paul's Archive
· Robin's Archive
image
Security Central
· Home
· Wireless
· Bookmarks
· CLSID
· Columbia
· Community
· Downloads
· Encyclopedia
· Feedback (send)
· Forums
· Gallery
· Giveaways
· HijackThis
· Journal
· Members List
· My Downloads
· PremChat
· Premium
· Private Messages
· Proxomitron
· Quizz
· RegChat
· Reviews
· Google Search
· Sections
· Software
· Statistics
· Stories Archive
· Submit News
· Surveys
· Top
· Topics
· Web Links
· Your Account
image
CCSP Toolkit
· Email Virus Scan
· UDP Port Scanner
· TCP Port Scanner
· Trojan TCP Scan
· Reveal Your IP
· Algorithms
· Whois
· nmap port scanner
· IPs Banned [?]
image
Survey
How much can you give to keep Computer Cops online?

$10 up to $25 per year?
$25 up to $50 per year?
$10 up to $25 per month?
$25 up to $50 per month?
More than $50 per year?
More than $50 per month?
One time only?
Other (please comment)



Results
Polls

Votes: 981
Comments: 19
image
Translate
English German French
Italian Portuguese Spanish
Chinese Greek Russian
image
image crkatk: Commentaries: How Much Is a Hacker's Head Worth? image
Crack Attack
How Much Is a Hacker's Head Worth?
By Alison Diana
E-Commerce Times

On the positive side, if virus writers continue to brag about their exploits, as they are notorious for doing, Microsoft's reward could encourage witnesses to come forward. On the other hand, the bounty could drive malware creators further underground.

When it comes to fighting traditional crime, tipsters play an integral role in reporting suspicious activities, questionable characters and true confessions. But while few people question the existence of Crime Stopper hotlines or highway billboards, Microsoft's recent plan to offer a bounty for information leading to the arrest of malware authors brings tip lines into the digital age.

Since it was founded in the mid-1970s, the Crime Stoppers organization has helped clear more than 1 million cases, been responsible for more than 500,000 arrests and paid nearly US$65 million in rewards, according to the group's Web site .

In contrast, Microsoft launched its Anti-Virus Reward Program with $5 million in its coffers. The program is designed to help the FBI, U.S. Secret Service and Interpol identify and arrest individuals who write and release malicious viruses and worms on the Internet. The Redmond, Washington-based industry giant has set aside two rewards of $250,000 each for information that leads to the arrest and conviction of those responsible for launching the MSBlast.A and Sobig worms.

This is another aspect of Microsoft's program for trusted computing, said Hemanshu Nigam, a corporate attorney in the Digital Integrity Group, Microsoft Law & Corporate Affairs, in an interview with E-Commerce Times. [Virus writers] are victimizing lots of people. Security, for us, is a priority, and it's our responsibility to do it the best we can.

Drafting Deputies
Although the bounty program initially is limited to attacks on Microsoft products, it is receiving high marks from some industry organizations, such as the Business Software Alliance.

BSA applauds [Microsoft's] announcement to establish the new Anti-Virus Reward Program, as it is one more example of increased public-private partnerships needed to promote cyber security around the globe, Robert Holleyman, BSA president and CEO, told the E-Commerce Times. Many cyber crimes are not yet perceived as real crimes. Collectively, we need to raise awareness globally that computer viruses, worms and denial-of-service attacks are not clever acts of mischief, but serious crimes that can cause major economic damage or worse.

The reward program, plus efforts by Microsoft, developers and IT organizations to eliminate the configuration errors that frequently create network vulnerabilities, are part of an overall effort to reduce damage by malware writers. And the IT community continues to invest heavily in security: In an October survey by the Software & Information Industry Association, 34 percent of senior IT executives polled said they plan to focus new spending on security.

That is a good thing, as there will have been more than 180,000 digital attacks worldwide by year's end, resulting in economic damage of $80 billion to $100 billion, according to UK research firm mi2g.

Think Twice
However, some security industry executives think Microsoft's move may not be the slam-dunk the Redmond titan would like to achieve.
This is my personal opinion -- not CA's -- and I think that, while something like this [bounty] probably doesn't hurt, it would probably only impact some of the fringe elements that write viruses, Stephen Gohres, vice president of marketing for Computer Associates' My eTrust, told the E-Commerce Times. Something like this reward would deter a certain percentage at the margin -- the script [kiddies]. I'd question whether it would have a real impact on the real serious type [of virus writer]. They already know it's against the law, right?

On the positive side, if virus writers continue to brag about their exploits, as they are notorious for doing, the reward could encourage witnesses to come forward. On the other hand, the bounty could drive malware creators further underground, Gohres cautioned.

Alternate Routes
In lieu of the age-old bounty concept, some people believe new paradigms are necessary for the digital medium.

For example, instead of offering a reward for those who already have launched worms and viruses, the industry should consider preventative measures, said Mark Rasch, a former head of the Justice Department's computer crime unit who currently is senior vice president and chief security counsel at Omaha, Nebraska-based managed security service provider Solutionary.

You've got a lot of people out there who are gray-hat hackers, he told the E-Commerce Times. The vast majority of the things they're finding are configuration problems. There's no mechanism for them to do anything with that vulnerability [information].

Catch-22
Indeed, hackers who find a vulnerability often do not know who to contact at an enterprise or software developer to pursue resolution of the issue. Even if a hacker is taken seriously, developers or IT executives have no way of gauging the veracity of the vulnerability information, which can be a problem if they are being asked to pay for it. For their part, gray-hat hackers -- who have only discovered, not leveraged, the vulnerability -- face the possibility of arrest if caught, according to Rasch.

Some of these people want to get, at a minimum, compensated for the work they've done finding this vulnerability, he said. There's no good way to do this. Let's come up with a mechanism for reporting these vulnerabilities.

Although such an endeavor would be fraught with complicated questions and logistical concerns, Rasch recommends creating an Information Sharing and Analysis Center that would let gray-hat hackers provide information on vulnerabilities to corporations and ISVs. The problem with my solution is someone's got to build it, someone's got to operate it, someone's got to fund it, he said. You've got to be independent and, at least in the short-term, self-financed. If we really want to put our money where our mouth is, let's do it.
At present, even as Microsoft continues to explore other anti-crime avenues, the company hopes to spend the $5 million in its antivirus war chest, said Nigam. If, at some point, the $5 million has been expended, we'll be celebrating, he added, noting that the software developer then will consider adding more capital to the fund. Historically, rewards work. This idea of moving them into the cyber world is new and unique.

Source: ECommerceNetwork
Posted on Wednesday, 26 November 2003 @ 04:50:00 EST by phoenix22
image

 
Login
Nickname

Password

· New User? ·
Click here to create a registered account.
image
Related Links
· TrackBack (0)
· Microsoft
· HotScripts
· W3 Consortium
· More about Crack Attack
· News by phoenix22


Most read story about Crack Attack:
Beware Attacker from IP 200.55.7.235 and Whole 200.x.x.x Block

image
Article Rating
Average Score: 5
Votes: 1


Please take a second and vote for this article:

Bad
Regular
Good
Very Good
Excellent


image
Options

Printer Friendly Page  Printer Friendly Page

image
"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.

No Comments Allowed for Anonymous, please register