Will Microsoft's 'Most Wanted' hunt work?

Experts divided in their reactions...

By Robert Lemos, 6 November 2003 08:50

NEWS Security researchers disagree on the effect Microsoft's Anti-virus Reward Program will have on the underground world of virus writing.

The initiative promises a reward of up to $250,000 for information leading to the conviction of the person or group responsible for launching the MSBlast worm and another $250,000 for similar information about the Sobig.F virus. The programme has been funded with $5m from Microsoft's coffers and will offer similar amounts for future threats.

Some security experts believe the bounty could disrupt the relationships between virus writers, effectively shutting down the loose online circles where authors meet and exchange code.

"It really depends on the demographic," said Carey Nachenberg, chief architect for security firm Symantec. "It will make the typical virus writers - 13- to 25-year-olds - think twice about releasing viruses."

Virus writers who intend to release bugs will have to be a lot more careful about who they associate with on the internet, said Peter Allor, director of vulnerability research for network protection provider Internet Security Systems.

"You have a fair chance of someone turning their buddy in," he said. Virus writers "are going to be very careful about who their alliances are with and who they work with".

Others believe the reward won't have a practical effect, aside from marginally increasing the distrust in an already paranoid community.

"Nothing will change," said Roberto Preatoni, founder of security site Zone-H.org. "I guess it's more like a publicity advertising stunt. [Microsoft chairman] Bill [Gates] cares about security and he will pay on behalf of the world."

The litmus test for the new initiative will be whether the $250,000 bounties produce additional suspects in the MSBlast and Sobig virus investigations, which have seemingly stalled.

MSBlast, also known as Blaster and Lovsan, spread to as many as 1.2 million computers, according to data from security company Symantec. The worm compromised computers by using a serious vulnerability in Windows systems for which Microsoft had released a patch a month earlier. A variant of the worm, MSBlast.D, was intended to protect machines against the original program but it ended up being so aggressive that the avalanche of data it produced shut down networks. The Sobig.F virus spread via email on 19 August, compromising users' computers with software designed to turn the systems into tools for junk emailers.

The US Department of Justice, the FBI and Microsoft have announced the arrests of two men who are suspected of modifying and releasing minor variations of the MSBlast worm but have made little progress in catching the original author or the person or group responsible for the Sobig virus. Those attacks were serious enough to hurt Microsoft's bottom line and boost security companies' profits.

The main measure of the new initiative's success will be whether fewer major attacks are seen, Symantec's Nachenberg said.

"This bounty is really meant to deter people from releasing malicious code into the wild, not necessarily writing malicious code," he said.

Robert Lemos writes for CNET News.com.

Comments

There are 4 comments. Join the discussion

  1. 1. Karl Chappell

    It's so obvious that these young kids are smarter than some of those at Microsoft, if I were working for MS I'd take them on and fire the plonkers who aren't up to the task.

  2. 2. Borjk

    It becomes a game of eye spy, take your pick which hole to look in but you have to remember who or what you are looking for is invisible at first sight and unless you recognise the code it is impossible to understand what's going on. Two suspected bit players implies there are some bigger players involved/ I reackon an anti virus hunt is a great idea by Microsoft whoever thought it up must have been trippin!

  3. 3. Victor

    Microsoft Anti Virus is a great idea they should make it a priority , intergrate it into the OS and make it work because the current Anti Virus vendors ain't working...

  4. 4. Richard Ash

    I still get MS-blast infected mail (cleaned at mail servers) now - how long does it take people to fix their systems? I could release 1 virus via a wireless hotspot completely anonomously, so why is it likely anyone will be caught 3 months on - most of the web logs concerned will have been purged by now.

Post your comment

In order to post a comment you need to be registered and logged in.

Log in or create your silicon.com account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy.

Questions about membership? Find the answers in the Membership FAQ