Yahoo search flags dangerous Web sites

Yahoo is using McAfee's SiteAdvisor to warn users of harmful Web sites appearing in its search results — but a security researcher warns the technology has a repuation for giving false positives.

The deal, an exclusive for Yahoo, uses McAfee SiteAdvisor technology to label a variety of potentially dangerous Web sites with red warning text and links to McAfee information about what risks the site poses.

The McAfee service flags risky Web sites in Yahoo searches with red warning text for users in the United States, Canada, the United Kingdom, France, Italy, Germany, Australia, New Zealand, and Spain.

Among the triggers for a red warning message are sites that host spyware, adware, or virus-infected downloads; sites that have links to other Web sites with dangerous material; and sites that have a track record of harvesting e-mail addresses later used to send spam, the companies said.

The move, along with related technology at Google and protections now built into browsers such as Internet Explorer and Firefox, spotlights a gradual expansion of the war against computer attacks.

Priyank Garg, director of Yahoo search product management, has high hopes for the Yahoo service, both for user protection and for hobbling attackers who try to exploit network insecurities.

"We expect users will have more confidence when searching on the Web," Garg said.

Curtailing Web attacks, but annoying Web administrators?
The Yahoo service could make life significantly harder for those who would attack people's computers, but it also stands to cause some Web administrators a headache by possibly incorrectly labeling them dangerous.

"We see millions of clicks on some of these sites through our search engine today," Yahoo's Garg said. "It is going to have a material impact in distribution of this content."

And the red flag is only the beginning. Through the McAfee technology, Yahoo has already removed an unspecified number of pages from its search results — for example those that attempt to compromise a vulnerable Web browser with a "drive-by download" attack launched simply by visiting a Web site. "We took out the risky sites where we don't want users to hurt themselves," Garg said.

But beyond the deleted entries and warning labels, Yahoo decided against altering search results. "There is an element of informed use," Garg said, likening the move to providing a city map with dangerous neighborhoods labeled as such rather than omitted altogether.

The Yahoo service isn't likely to directly address phishing, in which users are steered toward entering usernames, passwords, or other sensitive information into fake Web sites. "Phishing is less of a concern for the search experience," Garg said. "The Web sites that come up with phishing aren't usually around long enough" to make it into search results, he said.

While the service could improve security for searchers, it will also lead to a new phase in the constant battle between attackers and computer security firms, Forrester's Lambert predicted.

"At the end of the day, people are going to beat the technology," Lambert said. "You can only get so far ahead with security."

However, Web administrators will likely be caught in the crossfire between Yahoo-McAfee and malware distributors, according to Sunbelt security researcher, Alex Eckelberry, who said on the company's blog that SiteAdvisor has a track record of delivering false positives because it operates on allegations of malicious activity rather than proven occurrences.

"The major issue I see is false positives, which SiteAdvisor has had problems with in the past, and will put both companies squarely in the sights of upset Web masters. The StopBadware initiative(arguably Google's only similar offering) battles with upset Web masters on a regular basis, and they have a false positive rate that is arguably non-existent because their warnings are only based on real malware being on a website, not allegations of spam."

However, Allan Bell, marketing director for McAfee's Asia Pacific operations told ZDNet.com.au that Eckelberry misunderstands how SiteAdvisor works. A unique e-mail address is generated for each Web site it monitors, in order for McAfee to track e-mails or spam being generated by that Web site — not just allegations of spam.

Web site owners who believe their sites have been incorrectly labeled malicious are able to have their site re-scanned, said Bell, but he was unable to say how long that process would take.

ZDNet.com.au's Liam Tung contributed to this report.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

FugsFargy mulberry

26 minutes ago by BuhBypeepheri on Microsoft, Barnes & Noble ink $300m deal

Yes HC they have a whinge for every occasion, which contradicts itself (much like proverbs). Precious and most humorous, aren't they...!...

30 minutes ago by Beta on NBN users opt for 100Mbps

RT @sortius: #NBN users opt for 100Mbps http://t.co/lr7yE0A8 via @zdnetaustralia | do you have a reaction to this @TurnbullMalcolm?

RT @sortius: #NBN users opt for 100Mbps http://t.co/lr7yE0A8 via @zdnetaustralia | do you have a reaction to this @TurnbullMalcolm?

#NBN users opt for 100Mbps http://t.co/lr7yE0A8 via @zdnetaustralia | do you have a reaction to this @TurnbullMalcolm?

Notice how he didn't tell us when the "honeymoon" will end. It's all very convenient a NBN success story = artificial honeymoon, lol, but...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

Oh look it's the multiple banned, multi named fool alain... back from the dead. How many blogs are you banned at (not just one, eh - the...

1 hour ago by Beta on NBN users opt for 100Mbps

LOL, you wanted the money I was going to donate to the "bubububu please stop the nbn waste fund" Since I was only going to donate somethi...

1 hour ago by Hubert Cumberdale on NBN users opt for 100Mbps

I think everyone is missing the big picture here and that is the anti-NBN zealots have effectively admitted defeat by complaining about t...

2 hours ago by Hubert Cumberdale on NBN's Tassie upgrade to cost $1.3 million

Internet users certainly want the speed once they can get it#NBN

NBN users opt for 100Mbps http://t.co/JTQbWghv via @zdnetaustralia

It will be intersting to know what residences will sign up for when the NBN Co stops subsidising it all. 'NBN Co, the public-private par...

3 hours ago by advocate on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/DmebN1on

Australian NBN subscribers are opting for 100/40 over 12/1 speeds: http://t.co/QsWk7u6Y That's the least surprising news I've ever read! :)

UK 'cookie law' takes effect: What you need to know http://t.co/u7LZZ1oM

RT @juhasaarinen: NBN users opt for 100Mbps http://t.co/T7uk1hbK by @joshgnosis

Poor Oracle, poor, poor Oracle, I feel so sorry for them. I really hope they don't go bust, for at least another 5 or 6 months. Sucked in...

6 hours ago by Rex Alfie on Google didn't infringe on Oracle patents: jury

The point of pilot schemes is to determine the best practice and save money in the broader picture. The Tasmanian rollout planning actua...

6 hours ago by GregoryB1 on NBN's Tassie upgrade to cost $1.3 million

I think that a CBA is unlikely because with the high proportion of customers now electing for the highest rate (50% of connections in Apr...

6 hours ago by GregoryB1 on NBN cost-benefit analyses are so 2011

Pentaho adds native integration with MongoDB http://t.co/uJCqDA9B

RT @pussyeatingclub: Why you should pay for porn. A good read. http://t.co/PfhedCQs

DDoS works because you have enough compromised machines to clog the pipe or servers of the victim. If, the victim's pipe is widened by a ...

6 hours ago by GregoryB1 on National Botnet Network coming: Earthwave

Please stop with the analytical, common sense and facts, Gregory. Those opposed to the NBN don't want to hear such things, which is why ...

6 hours ago by Beta on Blowing the digital dividend on wireless NBN

But, yet again, Turnbull is clearly in error when he says that other companies cannot roll out copper. In South Brisbane Telstra chose to...

6 hours ago by GregoryB1 on Copper greenfield dominance irrelevant: Conroy

Not much point running fiber back to the exchange if that exchange itself is connected by copper. It is access to fiber backhaul that de...

7 hours ago by GregoryB1 on Copper greenfield dominance irrelevant: Conroy

+1

7 hours ago by Beta on Copper greenfield dominance irrelevant: Conroy

So instead you want these estates wired up with fiber and then left, unconnected with no service, until the fiber rollout reaches them in...

7 hours ago by GregoryB1 on Copper greenfield dominance irrelevant: Conroy

@paulbrislen @juhasaarinen Prices compared here: http://t.co/WnZzXP5Z

RT @joshgnosis: @paulbrislen @juhasaarinen Prices compared here: http://t.co/WnZzXP5Z

Water, roads and electricity were all rolled out by government because there private companies weren't interested as the ROI in the early...

7 hours ago by GregoryB1 on Five pros and cons of the NBN

NBN users opt for 100Mbps http://t.co/T7uk1hbK by @joshgnosis

Chrome beats Internet Explorer in global Web browser race | ZDNet http://t.co/3XfMdUXM

The case you outline, South Brisbane, is in fact the coalitions prefered model. They WANT the incumbent telco, Telstra, to provide the f...

7 hours ago by GregoryB1 on Five pros and cons of the NBN

Cybersecurity #collaboration between the US & Australia. http://t.co/p2uKLSBi

So, over time, the Coalition policy will cost much much more than Labor's because they intend to subsidise the broadband of farmers and t...

7 hours ago by GregoryB1 on Malaysia held up as NBN king

Any form of science training counts against you as a politician, in the coalition parties, doubly so. There may be others who keep quiet...

7 hours ago by GregoryB1 on NBN FUD: will Abbott ever learn?

Qld govt IT to be cleaned up by audit http://t.co/r4oNuNW8 #qldpol

Travel Tech Q and A: Skyscanner's Ewan Gray http://t.co/7ZfXZk19

Microsoft is serious about open source: 10 proof points | ZDNet http://t.co/2OtDR11D

Sex Tech: Faceporn win, Parental revenge porn, Google: No Porn ...: Google opposes UK porn filters, a fake porn ... http://t.co/0OR87oEt

Q&A of the Week: 'The current state of the cybercrime ecosystem' featuring Mikko Hypponen http://t.co/6lUYFs0X

RT @DellEnterprise: Dell Secureworks talks with ZDNet about Android's biggest #security flaws - http://t.co/LSFLQVFq #infosec

NBN users opt for 100Mbps: Customers are picking the top fibre plan that is available on the National Broadband ... http://t.co/sjtFSU3g

"Customers are picking the top fibre plan that is available on the National Broadband Network (NBN), more than a... http://t.co/M3P24Htn

RT @CorrieB: An iPad for every child: Inevitable or impossible? http://t.co/I7uS8l9s Thx to @timbuckteeth for this; http://t.co/jxkqIRIp

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

NBN users opt for 100Mbps - ZDNet Australia http://t.co/fLfHMzPn #australia #technews

RT @konradski: Whaddayaknow - turns out Wi-Fi CAN interfere with a plane's navigation systems http://t.co/ospQCU2S

This story has been voted 5 times in the last 24 hours!

20 hours ago, NBN's Tassie upgrade to cost $1.3 million

NBN users opt for 100Mbps - Communications - News - ZDNet Australia: NBN users opt for 100Mbps - Communications ... http://t.co/btB9gKWg

NBN users opt for 100Mbps http://t.co/xKqEb4bE via @zdnetaustralia

Biometric bugs too dangerous for public? http://t.co/8JLz5tdF via @zdnetaustralia

Exploring: http://t.co/rT7RPZLA

War talk dominates #AusCERT 2012 - http://t.co/SlBpMj0c - #security #cyber

Travel Tech Q&A: Skyscanner's Ewan Gray http://t.co/vYexrDwu #ipad

Exploring: http://t.co/YNVjdrct

Exploring: Travel Tech Q and A: Skyscanner's Ewan Gray: Ewan Gray, Skyscanner's director for Asia ... http://t.co/bNLCyobv #ICTChallenge

This story has been voted 12000 times in the last 24 hours!

3 days ago, Is Bill Gates a great leader?

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar