Cybercitizens called upon to squash hackers

By Cliff Edwards, BusinessWeek
Wednesday, September 09, 2009 10:36 AM

Since the earliest days of the Internet, people have tried to hack their way into the computers of others. Even as hacking has grown from a way for geeks to impress each other to a means for criminals to steal and blackmail, the strategy for computer security has remained largely the same: Companies and consumers erect the thickest walls they can around computers so the bad guys cannot get in.

Now security experts, realizing they are losing the battle, are ready to try a new approach. They plan to recruit victims and other computer users to help them go on the offensive and hunt down the hackers. "It's time to stop building burglar alarms to keep people out and go after the bad guys," said Rowan Trollope, senior vice-president for consumer products at Symantec, the largest maker of antivirus software.

Symantec is one of several companies trying to turn the tables. When its new Norton Internet Security is introduced, Symantec will ask customers to opt in to a program that will collect data about attempted computer intrusions and then forward the information to authorities. Symantec will also begin posting the FBI's top 10 hackers and their schemes on its Web site, where customers go for software updates. Next year, the company will begin offering cash bounties for information leading to an arrest.

Bryan Rutberg is ready to help out. Earlier this year hackers commandeered the Seattle resident's Facebook page and told his friends that he needed money wired to London because he had been robbed at gunpoint. The thieves collected more than US$1,000 before Rutberg put a stop to the scam. "It's deeply frustrating," Rutberg said. "If any company can do something to [improve Internet security], it's a huge service for the online community."

Black hats
The strategy to involve PC users has its risks, though. Hackers who find novices on their trail may trash their computers or steal their identities as punishment. Citizen hunters could also become cybervigilantes and harm bystanders as they pursue criminals. But some law enforcement experts believe the best way to slow down hackers, whose crimes often span multiple legal jurisdictions, is to get more people involved. "It's impossible to eradicate cybercrime from the top down," said Assistant U.S. District Attorney Matthew A. Parrella, who heads the Computer Hacking & Intellectual Property unit in Northern California.

Hackers, or black hats, as they are known, are increasingly adept at worming their way into corporate networks or deceiving people into installing malicious code on their computers. According to government-backed Internet Crime Complaint Center, the number of complaints rose 33 percent last year, to 275,284.

Symantec's new product uses a technology dubbed Autopsy that quarantines suspicious software being downloaded to a customer's computer. It then creates an onscreen alert that tells the user the software came from an unexpected location such as China or Eastern Europe. A service called Norton Community Watch collects the data and forwards them to law enforcement.

The approach is a reversal from past efforts to make security scans less intrusive. Symantec and other companies long thought people did not want to be bothered as security software looked for viruses. Now Symantec is betting customers will not mind being disrupted if they can help snare the bad guys. "I'm convinced we can clean up the Internet in 10 years if we can peel away the dirt and show people the threats they're facing," said Trollope.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Configure Apache to support multiple SSL sites on a single IP address

Open Source

With Apache 2.2.12 and support for the Server Name Indication extension to the SSL protocol, you can configure name-based HTTPS sites, just as you can name-based HTTP sites.


Read more »



Amendments to empower Copyright Tribunal

Blog thumbnail

As a lawyer, I often inform my clients about the need to clear licenses with the various licensing societies whenever they use works belonging to other parties. This is especially..... by Bryan Tan

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web