ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Can Microsoft's virus bounty fight organised crime?

Munir Kotadia ZDNet.co.uk

Published: 10 May 2004 17:30 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Microsoft's $5m Reward Program may help catch script kiddies, such as the German teenager suspected of authoring a variant of the Sasser worm, but it is unlikely to have any effect on virus writers working for organised crime syndicates, say security experts.

Four months after the MSBlast worm tore through the Internet, Microsoft announced it had set up a $5m fund -- to be used for rewarding people who offer information leading to a conviction with $250,000. Since the launch of the fund, although a number of suspected malware authors have been arrested, none have yet been convicted.

Simon Perry, vice president of security at Computer Associates, said the rewards may lead to script kiddies "telling" on each other, but it won't bother the organised criminals who have started using experienced software writers to create malware that allows them to take control over a large number of PCs.

Perry said that there has been a transition over the past few years in which organised crime gangs have brought the traditional protection racket to the Internet.

"This new breed of virus writers and spammers will not feel threatened by a $250,000 bounty on their heads. They are operating so far underground that there is virtually no chance of someone being compelled to give them up," Perry said.

However, Richard Starnes, vice president of ISSA's UK Chapter, said that rewards have historically been shown to work, even in the world of organised crime. But he warned that they are only a component of the overall war against virus writers, and rewards should be combined with a complete law enforcement programme.

"I doubt there will be a difference in effectiveness between posing a reward for an electronic crime and a more traditional crime," he said.

Microsoft UK's chief security officer Stuart Okin said the Sasser arrest only came about when a group of people contacted Microsoft to ask if the company was offering a reward for the Sasser author. He said that rewards are commonly used to catch organised criminals in non-Internet-related crimes, so there is no reason to think they won't have the same effect in cyberspace.

"We decided there would be a reward if the information was reliable. We contacted the German police and the informants came forward with a name," Okin said.

The informants' behaviour was correctly anticipated by Peter Allor, director of vulnerability research for network protection provider Internet Security Systems, when Microsoft's policy was first announced.

"You have a fair chance of someone turning their buddy in," Allor said.

CA's Perry said Microsoft's efforts, although positive, will not have any affect on criminals operating in countries without stringent computer crime laws.

"What if this teenager wasn't in Germany and was in Afghanistan? That country has no concept of computer crime," Perry said.

CNET News.com's Robert Lemos contributed to my report.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
88 out of 158 people found this useful


Company/Topic Alerts

Create a new alert from the list below:











Related Jobs

Reward Specialist Cheshire

My client, a nationally renowned blue-chip client, is currently seeking a high-calibre Reward Specialist As a leader within the retail market, my ...

Web Consultant- HTML, Java Script, SQL- Home based- Excellent

You will come from a software development background and will have strong experience with some/all of the following technologies: HTML, Java Script, ...

Business Support Credit Derivatives (CDS, CDO, ABS & Credit Risk Management) / ( SQL and Unix script skills) London

Title: Business Support Credit Derivatives (CDS, CDO, ABS & Credit Risk Management) / ( SQL and Unix script skills) London Location: London Type: ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation