US-CERT to unveil global worm-naming plan

Topics

worm, virus, us, anti, cme, cert, name

Zotob.E, Tpbot-A, Rbot.CBQ and IRCbot.worm: all names given to a single worm that wreaked havoc in Windows 2000 systems last month. Among the plethora of identifiers, perhaps the most useful -- CME-540 -- didn't make an impact.

But that's about to change. CME-540 was the tag attached to the worm by the Common Malware Enumeration initiative, which is just emerging from its test phase. Next month, the US Computer Emergency Readiness Team plans to officially take the wraps off the effort, meant to reduce the confusion caused by the different names security companies give worms, viruses and other pests.

CME is supported by researchers who work for US-CERT, but relies on participation by security vendors. Several major vendors, including the top three antivirus vendors, Symantec, McAfee and Trend Micro, currently participate in a preliminary editorial board.

The project assigns a unique identifier to a particular piece of malicious software. When included in security software, in alerts and in virus encyclopedia entries, this identifier should help people determine which pest is hitting their systems and whether they are protected, the initiative's backers said.

"There is a lot of confusion over the way that malware is referred to," Desiree Beck, the technical lead for the CME initiative, said in an interview. "We're trying to alleviate that by giving malware a common identifier, so everybody is talking about the same thing when some malware event happens."

The antivirus industry has tried, and failed, before to agree on common naming for worms and viruses. This time, US-CERT, the part of the US Department of Homeland Security that coordinates response to cyberattacks, is running the show. With that in mind, and because the plan allows companies to keep their own naming by assigning an ID rather than a common name, security software makers are hopeful that the effort will be a success, and they're eager to participate.

"Everybody recognises it as a pain point, and the industry has tried multiple times to come together," said Vincent Weafer, the senior director of security response at Symantec. "CME is a step in the right direction."

Jimmy Kuo, a senior fellow at software maker McAfee, agreed. However, he noted that the success of CME depends on industry participation, which is voluntary. "We have this problem because there is no authority that can force any type of coordination," he said. Kuo hopes people will push antivirus vendors to adopt the ID convention.

Symantec and McAfee both plan to support CME in their products and in their online reference libraries of threats, Weafer and Kuo said. Trend Micro and Kaspersky Lab will do the same, company representatives said. Other major antivirus providers -- F-Secure, Sophos, Computer Associates, Microsoft and MessageLabs -- are also involved in the effort. ICSA Labs, a research and testing outfit, also participates.

Recognising the threat
Because of the lack of coordination in naming threats, an outbreak can be tagged with a variety of names or variant designations, depending on the security company that's referring to it. This can result in confusion, with people wondering if there are multiple virus or worm attacks, or just one, and whether the product they own offers protection.

Victor Go, vice president of technology at retailer PureBeauty, sees value in the initiative. "It might help us speed up looking for virus information," he said. Still, there has not been a lot of confusion around viruses or worms at his midsized, Encino, California-based business, he said. "Every once in a while (there is), but eventually we come around in figuring it out."

The confusion could be even greater in larger organisations that use multiple security products from different vendors. "This is a real problem," Symantec's Weafer said. A desktop antivirus product may display a different name for a fast-spreading worm than the scanner at the e-mail gateway or the intrusion detection system, he said. This can send people scrambling to find out if each product has a defence against a particular pest.

CME identifiers should relieve some of the stress, said Beck, an employee of Mitre, which runs the initiative on behalf of US-CERT. Initially, only major threats will be given an ID number, but the ultimate goal is to cover all attacks affecting users, she said.

"It is a little bit subjective right now," Beck said, referring to the pests currently chosen to receive a CME ID tag. "We'd like to expand to anything that is out there that we could lend some clarity to."

The goal of CME is to offer a neutral, shared identification method that cuts through the naming clutter. It will assign one randomly chosen number to a worm or virus, regardless of what names it is known by at antivirus companies. Even if those companies disagree about the risk assessment or the background of the malicious software, CME will ignore this and focus on the characteristics of the attack to tag it.

The worm assigned CME-540, for example, was seen differently by several software makers: McAfee identified it as a new worm (IRCbot.worm), Symantec labelled it an offshoot of Zotob (Zotob.E) and Trend Micro saw it as another threat (Rbot.CBQ). Some times antivirus companies will rename a worm for the sake of conformity, but that typically doesn't happen quickly.

A CME identifier should get assigned within hours of a new worm or virus starting to spread, Beck said. Security vendors then should include the number in their products and link from their advisories to the information on the CME Web site, which is set to debut in early October. The proposal is for security companies to add the CME tag to the threat names, Beck said. An alert popping up on a user's screen could look like this: "Zotob.E!CME-540 detected."

The effort is completely reliant on industry participation. A number is assigned only after an industry researcher submits a sample of a threat with a write-up to CME. A group associated with the CME initiative then further researches the threat, collates information from antivirus companies, allocates an ID and publishes a threat profile.

Industry participation has been good, Beck said. "They have been really responsive, and I think they have confidence that it is something good for the long run," she said.

Participation on the organisation's editorial board, which includes Microsoft, Symantec, McAfee and the other industry majors previously mentioned, is by invitation-only, and companies have been lining up to get in, Beck said. The editorial board guides the process by which industry and researchers submit information on threats and by which the common IDs are assigned.

The first version of the CME Web site will have descriptions of a couple dozen threats, Beck said. Some have been written up in the months since the CME initiative started its trial run in the first quarter of this year. To begin with, the site will provide characteristics of threats and all the aliases used by different security companies, Beck said. By the end of the year, a more comprehensive Web site should be available, she said.

A worm or a virus is typically tagged by the first security company to discover it. Aside from some ground rules -- for example, the name can't be that of a real person or be offensive -- antivirus providers are essentially free to call the new pest whatever they like. "There are no grown-ups; there is nobody there to dictate standards to anyone, so you name the virus whatever you want to," said David Perry, director of global education at security provider Trend Micro.

In the case of a fast-spreading worm, a lot of security companies typically see it at the same time and all give it a moniker, Symantec's Weafer said. "Speed and response time are so critical -- that overwhelms any ability to get together with others and agree on a name for it," he said.

A convention that comes up with names ahead of time, like that used for hurricanes, doesn't work with worms or viruses, Weafer said. One reason is that there are many variants of worms and viruses, and antivirus companies don't always agree on whether a newly spotted threat is an offshoot or a brand new pest.

A few antivirus companies, including McAfee and Symantec, have already included CME identifiers in some of their advisories. As more threats get assigned an ID number, more companies will probably support the effort in their products, Beck expects.

"It is a chicken-and-egg problem. If there was stuff that they could point to, I think they would be very quick to link to it," she said.

While Go at PureBeauty does see some value in the naming initiative, he'd rather have his security software made more effective. "We get hit before virus definitions are out -- that has happened several times. I doubt this initiative will help against that," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Kaspersky is right. Even though voting is compulsory here, Australia needs to start work on this now. Once such a secure online credent...

5 minutes ago by Magnus on A farewell to democracy: Kaspersky

Chrome overtakes IE: does it matter? http://t.co/e4SILk8a

A ZDNet study showed that British Facebook users are drunk in 76 percent of their photos.

The HDMI cable ripoff and why retail is really dying http://t.co/eFT7zEW7

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/IUysbyKf

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/V7vL5QB9

Dazza - lets make a deal. I won't call you a troll if you don't call me a sheep. Anyway let's get some perspective on this. You cannot ...

1 hour ago by dickster on NBN users opt for 100Mbps

Further to the comments from James, I can add that most botnets will test the bandwidth of the end host before they take control of that ...

1 hour ago by patrickbutler on National Botnet Network coming: Earthwave

ZDNet reports Microsoft launches its own social service http://t.co/VJS5BkwF

by http://t.co/vmlLt4bh: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia P... http://t.co/4bfDRXo4

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/CtNlVWN7

Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia Pacific, shares some of h... http://t.co/ZxjpmqiM

Seriously, every business is slow to start off, that's common sense. But the NBN is attempting to replace an incumbent monopoly. So wait ...

1 hour ago by Beta on NBN users opt for 100Mbps

Microsoft is serious about open source: 10 proof points http://t.co/iv2ji74q

Ok, for all of those that are complaining about price lets look at it this way, Australia started using copper wiring back in the late 18...

1 hour ago by Kalthae on NBN users opt for 100Mbps

Ah so you have an anti-NBN website then...ok!

2 hours ago by Beta on NBN users opt for 100Mbps

@ Doubt, I think you should be a policy advisor to Tony Abbott. I can see it now pre-election 2013, Press Club - Journo: Mr Abbott, yo...

2 hours ago by Beta on NBN users opt for 100Mbps

@beachking, that's why the first N in NBN is of importance, because while this may come as a shock, the universe does not revolve around ...

2 hours ago by Beta on NBN users opt for 100Mbps

Err the words give it away "world class"... it's not Huawei class, China class or India class, it's world class! World Class from Farlex...

2 hours ago by Beta on NBN users opt for 100Mbps

How many billions of dollars have they spent for these 3500 connections? Whats the return in profit? How long are they going to keep subs...

2 hours ago by Dazza152 on NBN users opt for 100Mbps

Accelerator targets 'clean-tech' start-ups http://t.co/p9VPCzCa

RT @vexnews: NBN users opt for highest speed plan http://t.co/8eUvvVvQ

OutsourcingLive: #Outsourcing is still on the rise http://t.co/5U6R431A ^NK http://t.co/B8HtVvAD

In Facebook IPO fiasco the 'smart money' got burnt - ZDNet (blog): TIMEIn Facebook IPO fiasco the 'smart money' ... http://t.co/3iD1g6lG

So thats $2000 per premise just to replace the NTU...wow. Somebody is making a fortune on that work

2 hours ago by Coops1 on NBN's Tassie upgrade to cost $1.3 million

But will we actually get 100mps Internet speeds often overstated RT@vexnews: NBN users opt for highest speed plan http://t.co/1uTiHXrd

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

I guess fixed connections are not for the free spirits amongst us. Long live choice, it seems prepaid wireless for you is the go.

2 hours ago by Doubt on NBN users opt for 100Mbps

more cloud TV recording services tumble in wake of court victory for copyright monopolies - http://t.co/FEWm6Z7Y

Mike Quigley | Only 3500 NBN customers with active fibre services to date http://t.co/6eB525Ur via #auspol NBN very expensive failure

The take up figures are all a bit meaningless until NBN hits the big population centres.

2 hours ago by Doubt on NBN users opt for 100Mbps

Allow me to take your money if you are keen to give it away, a Western Union transfer is ok.

2 hours ago by Doubt on NBN users opt for 100Mbps

NBN users opt for highest speed plan http://t.co/8eUvvVvQ

The choice of connecting to fibre rests entirely in your hands, if you are so desperate to have a fibre connection, pack your bags and mo...

3 hours ago by Doubt on NBN users opt for 100Mbps

Funny argument the term "world class" , what does that mean when considering data networks. If NBN rolled out fibre but use Huawei equipm...

3 hours ago by Doubt on NBN users opt for 100Mbps

http://t.co/ZWOl5p8F

I agree it would (will) be nice to have a common platform. People are funny creatures and like to have choice. Some may feel they get bet...

3 hours ago by Doubt on NBN users opt for 100Mbps

Mr Quigley has to be politically aware, as does any CEO.

3 hours ago by Doubt on NBN users opt for 100Mbps

In essence the waiver of charges by NBN appears to be a subsidy to smaller or more remote areas. Idea! Setup a number of smaller service ...

3 hours ago by Doubt on NBN users opt for 100Mbps

http://t.co/JWINuozI

Remember, these are the high speeds that Mr Abbott believes you guys don't want.... http://t.co/Jtqnwb2M

Three tips for businesses to support connected customers http://t.co/to8fCl1N via @zite

Which Windows will make for a better tablet? http://t.co/wxr95itf via @zite

Cloud based TV recording services in Australia shutdown after negative ruling. http://t.co/9zlnSVJd

AD on azure, is all about APPS .. http://t.co/EMdsrHZF

children porn video

6 hours ago by nmhcqogu on Google to encrypt searches by default

#Biometric bugs too dangerous for public? http://t.co/IdIBiRUJ (via @zdnetau by @mukimu)

#Outsourcing is still on the rise http://t.co/ANaHIofI ^NK

#NBN users opt for 100Mbps
http://t.co/SmMFpItP #auspol

IBM's Intelligent Clusters - an old idea done well: IBM's pre-configured, pre-tested clusters take the uncertain... http://t.co/Z64vEYiL

33 must-have business and marketing iPad apps from Docstoc http://t.co/Bu7BhFRv

Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/08kaKg6R #infosec RT @dellenterprise

33 must-have business and marketing iPad apps from Docstoc http://t.co/0XqdwbAN

33 must-have business and marketing iPad apps from Docstoc http://t.co/pf1m0CNP

RT @sergicles: Google vs Oracle, that was a quick one. http://t.co/AFIEf8vG Oracle trolling pw4ned

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar