
THREAT MONITOR
The nasty truth about spyware
Michael Gregg 04.05.2005
Rating: -3.00- (out of 5)




|
While spyware is nothing new, it continues to grow in virulence and sophistication. Anyone who uses a computer and the Internet should be aware of the risk spyware poses. While it can be troublesome to the home user, it can pose an even bigger risk to a corporate network.
Spyware is not just one type of program. It's an entire category of malicious software that includes adware, Trojans, keystroke loggers and information-stealing programs. Some have likened it to the cancer of the computer world. Why? Because these programs have become increasingly intelligent. Many have the capability to install themselves in more than one location and just like cancer, any attempt to remove them, triggers the software to spawn a new variant in a uniquely new location.
This form of digital cancer is also capable of changing registry entries and forcing Windows to reinstall itself when the computer reboots. Spyware coders have even incorporated concepts such as Alternate Data Streams (ADS). For those of us using NTFS, this old-school hacker technique allows the spyware distributor to stream one file behind another. A quick search of the drive will find no trace of the offending executable as there is no entry in the FAT.
MORE INFORMATION:
What are some of the worst spyware programs that you might be exposed to? Webroot.com has a list, and the top ten includes KeenValue, a program that collects user information to target them with specific popup ads. Another is PurityScan, which advertises itself as a cleaner that removes items from your hard drive. Finally, there is CoolWebSearch. This program is actually a bundle of browser hijackers united only t
To continue reading for free, register below or login
To read more you must become a member of SearchSecurity.com

o redirect their victims to targeted search engines and flood them with popup ads.
Sure, home users are at risk but a compromised corporate desktop poses a real threat. These computers have the potential to access tons of proprietary and sensitive information on a scale that would be unheard of on a home computer. Corporate solutions have been slow to develop. Fortunately, Aluria Enterprise, Symantec, Sunbelt and others are starting to respond. Whatever you choose, make sure it's network friendly and can be easily managed from a central location. Integration is the key word.
Until you install a corporate-wide solution, there are some quick fixes you can perform to reduce the probability of infection.
We can only hope that the legislative and legal system will take action to prevent the ever-increasing problem of spyware. However, as usual, technology changes faster than the legal system can adapt. A good offense is about defense, so by implementing the solutions offered above and making the decision to deploy an enterprise-class spyware solution, this problem can be addressed. While there is no guarantee you won't become infected, there are ways to reduce the possibility.
About the author
Michael C. Gregg is the President of Superior Solutions Inc., a security assessment and training firm. His current responsibilities include performing security assessments and evaluations for corporate and government entities. He has served as the developer of high-level security classes, study guides, has taught classes for many Fortune 500 companies, and contributed to several books, including his most recent Que publication, CISSP Exam Cram 2.
 |

|
Rate this Tip
|
To rate tips, you must be a member of SearchSecurity.com. Register now
to start rating these tips. Log in if you are already a member.
|


');
// -->
DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.
|
 |
|
|
 |
|
 |