Fighting cyber threats with malware not ideal

 

Summary

Using "good" viruses to eliminate cyber threats can be effective but brings about technical issues and questionable motives, security insiders say.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Countries are increasingly taking up the option of fending off cyber threats with homebrewed malware but while this might prove effective, security insiders noted this might bring technical and ethical issues and, ultimately, not the best method to curb online threats.

Japan, for one, was reported last week to have commissioned IT vendor Fujitsu to develop a malware that can track, identify, and disable sources of online attacks. The Asian giant joins the ranks of the United States and China, among others, which are developing cyberweapons, according to the ZDNet Asia report.

Commenting on this development, Ang Chye Hin, regional sales director for Southeast Asia at SonicWall, pointed out that the strategy of "fighting fire with fire" is a highly effective one when used to defend against specific malware families. He explained in his e-mail that with just one "good" malware, it can reach out to the various branches as well as go straight to the root of the cyberattack.

For example, this good malware can be used during a botnet takedown to switch corrupted command-and-control (C&C) servers with clean ones. It can also be used to take over the attacker's C&C communications to disabled bots on infected computers as well as gather information on the process of how the attack was put together, he elaborated.

Questionable motives, end-results
David Harley, senior research fellow at ESET Security, agreed that there are advantages to using malware in covert operations such as intelligence, counter-intelligence and government purposes.

That said, there are also potential issues regarding maintaining control once the good malware is released into the wild, possible incompatibilities and dependency issues in systems where the malware had not been tested on, he highlighted.

Control, in particular, can be easily wrested from the hands of government agencies, he warned. This is because if the good virus is self-replicating, it is difficult to manage its spread and any collateral damage will "pour hot coals" and invite scrutiny on the agency or country that launched it should innocent parties get adversely affected, the ESET executive added.

"There is a clear suggestion here of unauthorized access and possibly modification, and that's going to be a legal disaster as it crosses borders into jurisdictions where those unauthorized actions are unequivocally illegal," Harley warned.

Furthermore, there might be technical challenges in terms of having systems differentiating between good and bad viruses, he pointed out. If the good malware uses similar techniques to "badware", it is often not possible for automated malware detections systems to tell them apart, he said.

The assumption that the malware would be able to trace cyberattacks all the way back to its source also shows a "tenuous grasp" of the realities of Internet traffic, as well as the way botnets and other malware operate, Harley argued.

"I'm concerned that people and agencies will sustain damage through unrealistic expectations of what this tool, whatever it turns out to be, can achieve," he added.

Luis Corrons, technical director of PandaLabs at Panda Security, agreed that once a malware--regardless of its intentions--is released, it is designed to replicate itself and control over it will be lost.

He then questioned the motivations behind creating such software, saying such tit-for-tat cyberdefense strategy is simply an excuse to "strike back on attackers".

"The excuse here is that it is needed to build defenses, but a virus is not a defensive weapon, it is an offensive one," Corrons said in his e-mail. "You use it to break into some place, to steal information and sabotage others."

Talkback

Threats in cyberspace don’t disappear; But some security pros have identified a handful of problems that have raised their heads in the last year or so that they believe will be the major trends in the coming year.

sairaise February 15, 2012
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

Alibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk

CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

Quickflix WatchNow 2.0 http://t.co/XWti5VWT

Official UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow

Why wouldn't they be?: CFOs increasingly involved in IT investment decisions http://t.co/4gHYrmQy via @zdnetasia

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate