Feeds

Desktop search and malware: friend or foe?

Double-edged sword

Security for virtualized datacentres

Anti-virus experts are experimenting with desktop search as a way of scanning for viral code. Both Google Search and Apple's Spotlight technology come with programming hooks (APIs) that allow their functions to be extended. Using these APIs, executable files might be scanned for malicious signatures.

Andy Payne and Oliver Oliver Schmelzle of security firm WholeSecurity have developed a prototype malware scanner based on Google Desktop Search. In a presentation at last week's Virus Bulletin conference in Dublin, the duo demonstrated the prototype. Admittedly, this is more of an experiment into what's possible than a serious product development project: a lack of full file indexing and kernel system access makes the approach impractical at present.

Conventional anti-virus scanning tools are much more thorough and faster. But as desktop search becomes a core operating system component the potential to use it for security applications increases. Payne said desktop search could be applied to other applications such as searching email inboxes for spam and filtering it automatically. It is unclear if this approach would prove any better than email plug-ins such as SpamBayes - this was beyond the scope of WholeSecurity's research - but it is an interesting idea. As desktop search becomes more pervasive it could be applied to more security functions such as auditing and compliance tools or within anti-phishing technology.

Desktop search also carries potential security risks. Search events might be used to trigger adware pop-ups or virus writers might create malicious indexer plug-ins, making it easier to harvest data from compromised machines, Payne warned. Sidebar user interface interference might also possible, as least theoretically. "Malware could be created that infects as it indexes. What's good for finding might be good for infecting too," he said.

The two sides of desktop search mirror the use of Google queries by both penetration testers and hackers to search for security holes in online systems. Google hacking, as it has become known, has been around for at least two years or more and security researchers are now beginning to grapple with the same sorts of issues on the desktop. ®

Beginner's guide to SSL certificates

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Three 1TB solid state scorchers up for grabs
Big SSDs can be expensive but think big and think free because you could be the lucky winner of one of three 1TB Samsung SSD 840 EVO drives that we’re giving away worth over £300 apiece.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.