|
|
To print: Select File and then Print from your browser's menu
-------------------------------------------------------------- This story was printed from ZDNet Australia. --------------------------------------------------------------
|
Messagelabs: Clean up Net effluent now By Jason Curtis, Special to ZDNet May 10, 2004 URL: http://www.zdnet.com.au/insight/security/soa/Messagelabs-Clean-up-Net-effluent-now/0,139023764,139147092,00.htm
Q&A We are losing the malware war. Conventional anti-virus and anti-spam countermeasures seem ineffective against an increasingly sophisticated enemy. The argument is that server- and client-side solutions draw the battle lines far too deeply inside their own territory, robbing computing, bandwidth and other resources. What's more, their inherently reactive approach dooms IT staff to an endless cycle of patching and pushing out client updates. E-mail security provider Messagelabs is taking the fight against spam and viruses elsewhere by offering proactive managed services that stop spam and virus threats at the Internet level, before they reach corporate networks and end users. ZDNet  spoke with Messagelabs chief technical officer Mark Sunner about current Internet threats, organised crime, and the latest trends in combating today's overwhelming flood of unsolicited mails and dangerous malware. Messagelabs is a leading provider of managed e-mail security services with more than a 50 percent share of the managed e-mail security services market. The company currently protects more than 8,000 businesses worldwide from e-mail threats such as viruses, spam and other unwanted content before they reach their networks, without requiring additional hardware or software. Some of its customers include the British Government, The Bank of New York, EMI Music, HealthPartners, StorageTek, Air Products and Chemicals, SC Johnson, Conde Nast Publications and Fujitsu.
Within the last year, have you monitored an increase in the number and/or severity of Internet attacks? What were the hallmark features of recent Internet threat activity?
We've also seen social engineering being a factor as well, where virus writers are introducing a human element by putting malicious code in password-protected Zip-files and finding some route to encourage the user to then unlock the virus once it reaches the desktop. The final trend that we're seeing is a new convergence between viruses and spam. Just to put a mark on that, 66 percent of the spam that we're now intercepting is coming from open proxies -- these are machines that have been infected with Trojans similar to those dropped with viruses such as Sobig, Fizzer or MyDoom. The use of large zombie networks is definitely becoming the en vogue technique of choice within the hard-core spammer community.
Security experts claim that a new generation of malicious code seems to specifically target business and industry, and that a connection exists to organised crime. What evidence is there to support this?
The second, slightly more tenuous point is that the areas where the attacks, i.e. the Web pages, are hosted are areas that have been associated with organised crime in the past. Specifically we have seen a lot of "phishing" Web sites hosted in Russia.
What are governments currently doing to control the Internet and what might they do in the future?
Going forward, the way that this problem will really be solved is to move filtering to the Internet level, where the scale and the speed of updates mean that you can do a much better job, especially when you look at the home-user market, where the task of filtering is being placed on the end user. This is really the wrong place to put it; it's not the end user's core competence. Currently, many ISPs are allowing all Internet traffic to simply flow through completely unfiltered, which is akin to a water authority pumping out raw sewage to its customers and leaving it to them to fend for themselves. Advanced scanning needs to be shifted upstream to the Internet level, where it is possible to be proactive as opposed to reactive. Governments really need to put additional pressure on the ISPs to take ownership of the problem, and to filter the connections that they are providing to businesses and to home users.
Spam and viruses are often mentioned in the same context, and there is much talk about the so-called "blended threats". Is spam then more than just a nuisance? How does it fit into the big picture?
Current spam and virus solutions have arguably had limited success, primarily because they all tend to be reactive in nature. What are the most promising ideas for tackling the spam problem?
But more importantly, Internet-level scanning becomes much more pertinent when you look at the sheer volume of mail that's involved. Even if you had actual desktop prevention that was effective, the simple fact is that you've still got to receive all that mail to then decide you don't want it -- it's too late. By this time, your bandwidth and mail processing resources have already been tapped. The trend for the future, and obviously we are in this business, but we are seeing a trend -- not just ourselves, but also companies like us -- for Internet level protection to become the next big thing ... to stop spam at its source before it gets anywhere near corporate boundaries or home users and erodes resources. Ultimately, as these Internet-level solutions become more prolific, the costs that spammers themselves incur will increase dramatically. As it becomes harder and harder for spammers to achieve results, they will look on to something else.
Internet-level filtering is exactly Messagelabs' business. This means that all your clients' e-mail communication is monitored by you. Is this a potential cause for concern for corporate clients, specifically, that there is a third party out there that has root-level access to all mail that it sends or receives?
Copyright © 2009 CBS Interactive, a CBS Company. All Rights Reserved. |