RSA Europe 2010: Botnets beaten, but threats remain high
Covering RSA in San Francisco last March required only a brief BART commute. With this week’s RSA Europe 2010 requiring a transatlantic flight, I’m covering the security show in London from the security of my home in California. At RSA Europe some notable successes fighting cybercrime were heralded but the threat remains as does the need to stay on guard.
The main headline was Microsoft’s release of Volume 9 of its Security Intelligence Report, which documented a dramatic decline in the number of computers globally infected by the Waledac virus. As Jeremy Kirk of IDG News Service reported, Microsoft needed to clean only 29,816 computers infected by Waledac in the second quarter of this year, versus 83,580 computers in the first quarter. The drop-off was attributed to the unusual but apparently effective Microsoft strategy of suing to stop Waledac in order to shut down botnets used to spread it, said Adrienne Hall, general manager of Microsoft’s Trustworthy Computing initiative, in an address at RSA Europe yesterday, and in a blog post the same day.
Microsoft obtained a temporary restraining order (TRO) from a U.S. District Court in February to shut down 300 Internet domains considered to be the command and control center of the botnet. It was an “ex parte” TRO, meaning the petitioners — Microsoft, among others — were able to get the order without having to notify the apparent operators of the botnet in advance. That seems to have done the trick.
“There are clear indications that aggressive, creative disruption efforts by the software industry, law enforcement agencies, government entities, and academics are having an impact on botnets,” Hall wrote on her blog. Besides the Waledac takedown, Hall said Microsoft worked with authorities in Spain who made arrests in March in the case of the Mariposa botnet that reportedly controlled 12.7 million PCs running Windows. The report also revealed that since 2006, Microsoft has seen a 75 percent increase in the use of Microsoft’s automated update service that patches vulnerabilities once they are discovered.
“Despite these successes, we must accept that information technology is complex and many people are unwilling or unaware as to how they can protect their data and their machines,” Hall stated.
That lack of attention to prevention prompted discussion elsewhere at RSA Europe. Regulations should be in place to require businesses to have certain security technologies and practices in place, said Ira Winkler, president of the U.S.-based Internet Security Advisors Group, an occasional source for posts on this blog, and a presenter at the London conference. Noting a general aversion to regulation by some businesses, Winkler said security regulation is needed to make best practices the norm. He likened it to government regulations requiring auto makers to install air bags and anti-lock brakes in cars.
Of course, some network security measures are mandated by U.S. law such as the HIPAA privacy regulations on the health care industry, and the Sarbanes-Oxley regulations on publicly-traded companies.
But Winkler said, according to the U.K. Web site ComputerWeekly.com, that there should be a law that would require that software patches to fix a security vulnerability must be implemented within a week of their release.
“Many businesses hate compliance, but like it or not, compliance is their friend,” Winkler told his RSA audience.
Having reported on patch management before, I know that IT staff has to prioritize which patches to apply based on the threat various vulnerabilities pose to their organization. It depends on what systems they run, what applications they use and — basically — what business they are in. A basic one week deadline to apply all patches across the board probably wouldn’t be practical, but Winkler’s proposal is a good place to start.
I’ll be digging through more of the Security Intelligence Report for my next post.




