Home > Security News > ISP liability II: Does the bot stop here?
Security News:
EMAIL THIS

ISP liability II: Does the bot stop here?

By Michael S. Mimoso, Senior Editor
15 Sep 2005 | SearchSecurity.com

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   

In the second of a two-part analysis of Internet service providers' culpability in the growing number of compromised computers, experts say it's time ISPs do more -- and some are -- to stem damages from botnets. Part I of the series examines why that's a bad idea.

New botnets are appearing at a near-unstoppable rate of more than 150,000 a day, according to some recent studies, leading many security managers and legal experts to increase the volume on their calls for Internet service providers to be liable for damages resulting from distributed denial-of-service attacks.

ISPs are being asked to monitor for abusive traffic patterns, block machines and ports participating in DDoS attacks and even scan user machines for basic security controls. While the carrot in this argument is improved Internet health, the stick is legal negligence and expensive liability payouts if a company suffers damages.

While some ISPs like AmericaOnline have beefed up their security with free antivirus, spyware and SPIM protection, more is being asked of carriers like Verizon, MCI and AT&T.

"The courts will recognize soon that a baseline expectation of reasonable care can be provided by ISPs systemically to reduce the impact of spreading exponential mass infections, without a reduction in privacy," said Kimberly Laris, IT controls manager with the Timberland Co. of New Hampshire.

A paper written and published last year by Doug Lichtman and Eric Posner of the University of Chicago Law School said ISPs should be held accountable much in the same way restaurant and bar owners must control the behavior of employees. Common law tort liability should encourage ISPs to enhance their security.
What's your take?

Should laws be changed to make ISPs more responsible for the malicious traffic and illegal activity generated and perpetuated by its customers? Click the SoundOff link at the top of the story and join a discussion on the topic.

"Service providers control the gateway through which Internet pests enter and reenter the system. As such, service providers can help to stop these pests before they spread and to identify the individuals who originate them in the first place. ISPs should be required by law to engage in these precautions," the paper said.

Opponents, however, fear that liability will force ISPs to be overly thorough in their monitoring of network users. Erring on the side of caution would reign, and access for "marginal subscribers" would be cut off, the paper said. Also, the fear is the ISP liability would reduce any incentives users have to be vigilant on their ends. But managers like Laris believe that tactics like ISPs stripping malware in transit is more than a good gesture, it restores bandwidth and throughput speeds, keeping customers happy and themselves out of courtrooms.

"ISPs may not relish making an initial investment to reduce malware transfer. However, the community of ISPs receives the benefits of investing in security: reduced unwanted traffic, improved performance, reduced costs of managing escalating customer complaints, lost revenue to competitors and possibly fewer legal costs from defending against proposed lawsuits," Laris said. "ISPs may soon point to other ISPs as being part of the Internet community's problem if they are not participating as part of the solution by stripping malware traffic."

Meanwhile, carriers like AT&T are offering security-in-the-cloud services where perimeter functions like firewall and IDS monitoring are outsourced to the carrier. AT&T CISO Ed Amoroso said recently that calls for increased ISP vigilance are not always clear and across-the-board statutes may not be possible. Clear SLAs must be established that spell out what traffic should be filtered.

"We try to take this broad notion of 'a carrier should do more' and channel it to things that make sense and are reasonable," Amoroso said.

Tags: Information Security Laws, Investigations and EthicsMalware, Viruses, Trojans and SpywareInformation Security Policies, Procedures and GuidelinesVIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Information Security Laws, Investigations and Ethics
Cybersecurity czar candidate questions clout of new position
DHS fills National Cybersecurity Center post
FTC shutters rogue ISP for hosting malicious content, botnets
Experts optimistic of Obama cybersecurity plan
WH cybersecurity plan needs private sector guidance
Obama announces creation of cybersecurity coordinator position
Cybersecurity Act of 2009: Power grab, or necessary step?
Face-off: Who should be in charge of cybersecurity?
Feds should get private sector advice on cybersecurity
Federal efforts to secure cyberinfrastrucure

Malware, Viruses, Trojans and Spyware
ISP shutdown latest cat-and-mouse game with hackers
How to get rid of malware, botnets on a hospital IT network
How can search results lead to malware?
How to prevent mobile phone spying
Should a national cybersecurity strategy include offensive botnets?
How to defend against rogue DHCP server malware
New Trojan stealing FTP credentials, attacking FTP websites
Cybercriminals exploit Michael Jackson, Farrah Fawcett deaths
When BIOS updates become malware attacks
Antispyware buying guide for Indian enterprises

Information Security Policies, Procedures and Guidelines
Twitter risks, Facebook threats trouble security pros
Cybersecurity czar candidate questions clout of new position
Incident response planning
The basics of enterprise GRC project management
RSA council addresses growing security risks in the cloud
How to write a risk methodology that blends business, security needs
Risk management must include physical-logical security convergence
DHS fills National Cybersecurity Center post
New partnerships, creative thinking help security bust recession
Experts optimistic of Obama cybersecurity plan

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
CALEA  (SearchSecurity.com)
cyberstalking  (SearchSecurity.com)
cypherpunk  (SearchSecurity.com)
HSPD-7  (SearchSecurity.com)
I-SPY Act  (SearchSecurity.com)
Information Awareness Office  (SearchSecurity.com)
intelligence community  (SearchSecurity.com)
lawful interception  (SearchSecurity.com)
lifestyle polygraph  (SearchSecurity.com)
vulnerability disclosure  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



More Tips to Secure Your Network
Focused on Channel Security?