ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Anti-spyware group finalises detection plans

Alorie Gilbert CNET News.com

Published: 13 Jan 2006 09:30 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A coalition of software companies have agreed on standard methods for identifying and combating spyware, those unwelcome downloads that have plagued Internet users with pop-up ads and other annoyances.

The Anti-Spyware Coalition, whose members include Microsoft, Symantec, Computer Associates, McAfee, AOL and Yahoo, said on Thursday it has finalised its spyware detection guidelines. The final version takes into account public comments on a proposed version introduced in October.

Spyware and adware have become widely despised for their sneaky distribution tactics, unauthorised data gathering and tying-up of computer processing power. Although adware makers say there are legitimate uses for their programs, an entire anti-spyware market has been spawned to combat the stuff.

The Anti-Spyware Coalition's guidelines, or risk model description, aim to provide a common way to classify spyware, based on risks a piece of software poses to consumers. They also suggest ways to handle software, based on those risk levels.

Among the behaviours the group considers high-risk are programs that replicate themselves via mass emails, worms and viruses. Also, programs that install themselves without a user's permission or knowledge, via a security exploit, are also deemed high-risk, as are programs that intercept email or instant messages without user consent, transmit personally identifiable data, or change security settings.

The coalition hopes the final guidelines, which have changed little from the proposed version, will lead to better anti-spyware products. To that end, Cybertrust, through its ICSA Labs unit, is planning to certify products that meet the guidelines. Consumers should see the first products with its anti-spyware seal of approval within the next few months, the IT security and risk management company said.

The guidelines should also make it clearer when companies cross the line of what's acceptable and legal and what's not when it comes to downloads, as Sony BMG did recently with its "rootkit" programs, said Ari Schwartz, a spokesman for the Anti-Spyware Coalition. Sony recently settled a class-action lawsuit over copy-restriction software hidden on customers' computers using a rootkit, which opened those PCs up to attack. The company also recalled the CDs after a public uproar.

Yet attempts to define spyware, create guidelines and certify products are controversial. Critics fear guidelines will legitimise spyware and enable distributors to dodge blocking tools while continuing bad behaviours.

The Anti-Spyware Coalition group plans to conduct a public workshop on 9 February in Washington, DC, and is currently working on tips for consumers and businesses, Schwartz said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
87 out of 150 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:







Related Jobs

QA (Quality Assurance) Auditor

The role involves: + auditing, both internally and externally, to ISO 13485 guidelines + heavy involvement in the management and running of Quality ...

Network Security Technician - North London 20 25K+BONUS:

This IT Security Specialist - focuses on Intrusion Prevention, Anti Virus URL & Email Filtering Are you a person that can build upon this companies ...

J2EE Team Leader (Telecoms) - Customer Management

Review all project deliverables to ensure standards and guidelines are adhered and high quality software is delivered. Lead an efficient and ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation