Feeds

Security maven sics 'special ops' on botnet gangs

League of net justice

Security for virtualized datacentres

RSA Sometimes fighting botnets, spam, and other online crime is like raking leaves on a windy day. Bag one operation and almost overnight there are a half-dozen more that take its place.

It's a story that's all too familiar to Joe Stewart, director with SecureWorks' Counter Threat unit. Now, he's proposing members of the security industry borrow a new page.

"Right now, we've got a very scattered approach," he said during an interview at the RSA security conference in San Francisco. "We're looking more at attacks than attackers. As we jump around from attack to attack, we're not really having a long term impact."

Stewart is suggesting a series of small "special ops" groups that work to make cybercrime less profitable by disrupting a gang's business. The special ops teams would work to thwart ongoing attacks by getting known criminals disconnected from the internet quickly and more effectively distributing new malware signatures so exploits can be detected faster.

The approach in many ways emphasizes the economics that's at the heart of most computer crime. At their core, criminal gangs are business enterprises that take risk, reward, and effort into consideration when deciding whether to pursue new attacks. The idea is to create a grassroots movement that increases the risk and effort and reduces the rewards.

Stewart envisions the special tactics as an interim strategy that will tide the law-abiding world over until it can pass a global treaty that would hold each country responsible for the cybercrime perpetrated inside its borders. CERTs, or computer emergency readiness teams, in each nation would be empowered to deal with computer abuse by, among other things, having the legal authority to disconnect people who are using the internet to spread malware or carry out other crime.

Of course, there are some potential land mines in such an approach. As we've pointed out before, self-appointed white-hat netizens who take it upon themselves to disconnect certain parties from the internet with no due process is always a concern. Stewart also worries that the treaty could be monopolized by the RIAA, MPAA, or other intellectual property groups. This seems like a reasonable concern.

But as we learned last year when an internet host by the name of McColo was shut down, a little industry cooperation can go a long way. Almost overnight, spam volumes were cut in half, thanks to the actions of the service providers that were upstream from McColo.

No, there's no one known to be actively working on making this pie-in-the-sky vision a reality, and yes, its specifics are still undefined. But amid the steady rise in cybercrime, it's an idea worth pondering. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
NASTY SSL 3.0 vuln to be revealed soon – sources (Update: It's POODLE)
So nasty no one's even whispering until patch is out
Russian hackers exploit 'Sandworm' bug 'to spy on NATO, EU PCs'
Fix imminent from Microsoft for Vista, Server 2008, other stuff
'LulzSec leader Aush0k' found to be naughty boy not worthy of jail
15 months home detention leaves egg on feds' faces as they grab for more power
Forget passwords, let's use SELFIES, says Obama's cyber tsar
Michael Daniel wants to kill passwords dead
FBI boss: We don't want a backdoor, we want the front door to phones
Claims it's what the Founding Fathers would have wanted – catching killers and pedos
Kill off SSL 3.0 NOW: HTTPS savaged by vicious POODLE
Pull it out ASAP, it is SWISS CHEESE
Facebook slurps 'paste sites' for STOLEN passwords, sprinkles on hash and salt
Zuck's ad empire DOESN'T see details in plain text. Phew!
prev story

Whitepapers

Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Why cloud backup?
Combining the latest advancements in disk-based backup with secure, integrated, cloud technologies offer organizations fast and assured recovery of their critical enterprise data.
Win a year’s supply of chocolate
There is no techie angle to this competition so we're not going to pretend there is, but everyone loves chocolate so who cares.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.