Welcome | Sign In
ECommerceTimes.com
Security

Microsoft Puts Price on Worm Writers' Heads

Print Version
E-Mail Article
Reprints
Microsoft Puts Price on Worm Writers' Heads

In a research note, ThreatFocus Security said one possible positive side effect of the bounties could be to slow the rate of information exchange about exploits and partially written malicious code among hackers.


Hoping to use cold, hard cash to crack two frustrating investigations, Microsoft (Nasdaq: MSFT) has set up a US$5 million "reward fund" to pay bounties to those who track down writers of malicious code.

The company launched the program by offering to pay two $250,000 bounties for information that leads to the capture and conviction of the authors of the SoBig and Blaster worms.

This is believed to be the first time a company has offered a cash reward to help track down a computer criminal. The move underscores the software giant's efforts to keep the public's focus on hackers rather than on flaws in its products.

Little Help

Microsoft said the Federal Bureau of Investigation (FBI), the U.S. Secret Service and Interpol, the international police organization, will help administer the bounties as part of their ongoing investigations into the worms' origins.

Microsoft general counsel Brad Smith said worms and viruses are not attacks on a particular software system, but instead "criminal attacks on everyone who uses the Internet."

"Even as we work to make software more secure and educate users on how to protect themselves, we are also working to stamp out the criminal behavior that causes this problem," he said. "These are real crimes that hurt a lot of people."

No Honor Among Thieves

Patrick Gray, a former FBI investigator who is now director of forensics and emergency response at Internet Security Systems (Nasdaq: ISSX), called the move a "fresh approach to an old problem."

"The hacking community is a criminal community, and there's no honor among thieves," Gray told the E-Commerce Times. "If they can make a buck by pointing fingers, they will."

Gray noted that hackers were helpful in leading investigators to "Mafiaboy," the Canadian teen charged with a massive denial-of-service attack on eBay (Nasdaq: EBAY), CNN.com and others. "They want to remain cloaked in anonymity," he said. "They don't want to be in the spotlight."

He applauded Microsoft's effort to keep the focus on hackers. "We've been focusing on buggy software, but if the lock on my front door is weak, that doesn't mean you can come try to push it open every day," he added.

Difference Makers?

Although some analysts expressed skepticism about whether the reward will be enough to prompt hackers to turn each other in, they said Microsoft could gain positive publicity, which its security efforts sorely need, as a result of the move.

"Microsoft has recognized it needs to attack this problem on as many fronts as it can," Gartner (NYSE: IT) vice president John Pescatore told the E-Commerce Times. "Fixing the product is going to take a lot of time, and there's a lot of legacy software that's going to be out there for years to come. They need to keep reminding people that hackers are causing the problems they're experiencing."

Less Talk

In a research note, ThreatFocus Security said one possible positive side effect of the bounties could be to slow the rate of information exchange about exploits and partially written malicious code among hackers.

"Hackers may be more inclined to think twice about whom they share information with for fear of being turned in by someone they don't know that well," the company said. "But even if they do catch the people who wrote those two viruses with these rewards, it's unlikely to stop the flood of exploits."


Print Version E-Mail Article Reprints More by Keith Regan


More by Keith Regan

Yahoo Slaps Fresh Coat of Gloss on Microsoft Deal Defense
June 30, 2008
With its shareholders meeting set to take place in less than five weeks, Yahoo has put together a 32-page presentation, emphasizing why the investors should vote to keep the current board in place. The company also reiterated why it chose to partner with Google instead of letting Microsoft buy part of it.
French Court Stings eBay With $63M Judgment Over Knockoff Sales
June 30, 2008
eBay is planning to appeal a ruling by a French court that ordered it to pay $63 million to the luxury goods maker Louis Vuitton Moet Hennessey. The court also barred the online auctioneer from selling four brands of perfume on its Web sites accessible in France.
New Auto Loan Leads Marketplace Shifts Into Drive
June 30, 2008
Reply.com's move into the auto finance market is a logical one the company, as automotive advertising spending is moving online in increasingly greater amounts. The company is partnering with the Detroit Trading Company to create a massive repository of auto finance leads online.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network