Feeds

IEEE group aims to forge malware sharing standard

Rebel Alliance forms to fight black-hatted evil empire

Top 5 reasons to deploy VMware with Tegile

The IEEE has brought together an alliance of anti-virus vendors in an industry group that aims to improve and better organise collaboration, with an initial focus on better standards for malware sample sharing.

Vendors including AVG, McAfee, Microsoft, Sophos, Symantec and Trend Micro have signed up to the newly newly-formed Industry Connections Security Group (ICSG). Anti-virus researchers at these firms (and others such as Kaspersky and F-secure yet to sign up to ICSG) have been sharing virus samples for years. What the ICSG wants to bring to the party is better organisation and standardisation to this process, as its mission statement explains:

While there has been some ad-hoc co-operation in the industry in areas such as malware and phish URL sharing, this co-operation has not been standardized or documented in a format that lends itself to systematic improvement in operational efficiency or visibility and review by people outside the vertical industries.

ICSG currently has one Working Group looking at Malware, but expects to add other Working Groups over time.

Organising the sharing of malware samples in a more streamlined way is important, because growing malware volumes threaten to derail existing (mainly) informal virus sample sharing arrangements.

Plenty of industry groups already exist in this area - such as the Anti Phishing Working Group (APWG), the much older Computer Anti-Virus Research Organisaion (CARO), the AMSTO anti-virus testing group, and others. The IEEE group is focusing on standards, at least initially, and it hopes to tackle wider security protection challenges over time.

It already has firms such as Cisco and Team Cymru from outside the hardcore of anti-virus vendors involved as contributors, and wants to bring in more potentially interested parties, such as banks and ISPs. More about the ICSG's aims cam be found in a presentation here.

First up for ICSG is the goal of developing a sharing standard, incorporating XML data including information on where a sample originates, to augment the current malware sample sharing process.

We already have the CVE scheme for classifying vulnerabilities systematically and ICSG wants to do something similar for virus classification.

Whether it ever breaks out of that particular little quagmire remains far from certain. Just the seemingly straightforward task of agreeing names for malware samples has reduced strong men to tears of frustration for years.

The ICSG scheme is the first in a series of "incubator" programs the IEEE wants to put in place to assist in the early stages of standards development. ®

Internet Security Threat Report 2014

More from The Register

next story
'Kim Kardashian snaps naked selfies with a BLACKBERRY'. *Twitterati gasps*
More alleged private, nude celeb pics appear online
Home Depot ignored staff warnings of security fail laundry list
'Just use cash', former security staffer warns friends
Hackers pop Brazil newspaper to root home routers
Step One: try default passwords. Step Two: Repeat Step One until success
UK.gov lobs another fistful of change at SME infosec nightmares
Senior Lib Dem in 'trying to be relevant' shocker. It's only taxpayers' money, after all
Spies would need SUPER POWERS to tap undersea cables
Why mess with armoured 10kV cables when land-based, and legal, snoop tools are easier?
TOR users become FBI's No.1 hacking target after legal power grab
Be afeared, me hearties, these scoundrels be spying our signals
Snowden, Dotcom, throw bombs into NZ election campaign
Claim of tapped undersea cable refuted by Kiwi PM as Kim claims extradition plot
Freenode IRC users told to change passwords after securo-breach
Miscreants probably got in, you guys know the drill by now
THREE QUARTERS of Android mobes open to web page spy bug
Metasploit module gobbles KitKat SOP slop
prev story

Whitepapers

Secure remote control for conventional and virtual desktops
Balancing user privacy and privileged access, in accordance with compliance frameworks and legislation. Evaluating any potential remote control choice.
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
WIN a very cool portable ZX Spectrum
Win a one-off portable Spectrum built by legendary hardware hacker Ben Heck
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.