Microsoft buys Komoku, maker of rootkit detection products

Analysis
Mar 24, 20083 mins

Microsoft has acquired Komoku, maker of rootkit detection products. Financial terms of the acquisition were not disclosed.

Komoku creates both hardware and software approaches to rootkit detection. Its CoPilot product is a PCI card that monitors a computer’s memory and file systems. The Gamma software product looks for odd operating system behavior that indicates the presence of a rootkit. Microsoft plans to integrate Gamma with its Forefront enterprise security software and with Windows Live OneCare, its PC anti-malware product.

Komoku customers include the Department of Homeland Security, the Department of Defense and the Defense Advanced Research Projects Agency. These agencies also reportedly granted the security startup $2.5 million in funding. The Washington Post says that Microsoft will keep the company’s president and CTO, William Arbaugh, but will not continue to sell Komoku as a separate product or keep the Komoku name. (Arbaugh is a former computer network specialist with the National Security Agency and is a professor at the University of Maryland.)

While Microsoft has announced its plans for the Komoku software, it has not announced its plans for the CoPilot PCI card. This is a little odd in that Komoku is best known for its hardware approach. Still, it is unclear that hardware is even the answer to rootkit detection. About a year ago, at the Black Hat DC conference, respected rootkit researcher Joanna Rutkowska showcased several ways to outwit hardware rootkit detection methods. Software rootkit detection can also be outwitted.

In any case, Microsoft can’t go wrong by adding well-respected rootkit detection to Forefront and OneCare and by adding a rootkit researcher to its staff. Symantec and others have been working on this problem for years – in both the labs and in the marketing zone.

This is not to say that any vendor will actually solve the rootkit problem. One of the issues with security research is that those with the most money to conduct such research are the ones that benefit most by security failures. Should a vendor find a way to truly protect computing resources, the vendor would also find that they’ve killed off their livelihood. 

Go to the Microsoft Subnet home page for more news, blogs, opinion.  More Micronet blog posts:

Microsoft, IBM commit to unified communications interoperability test

Microsoft fixes CardSpace validation flaw 

Users complain of problems downloading Windows Vista SP1

Microsoft puts Windows Server 2008 Terminal Services to the test

Microsoft Windows Mobile gets security seal of approval

Microsoft gets closer to the Eclipse open source foundation

Microsoft says Hyper-V is on track to ship in August

Microsoft, Intel pump $20M into parallel computing initiative with universities

Yahoo to Microsoft: We can make billions of dollars without you

All Micronet blog posts

Sign up for the bi-weekly Microsoft newsletter. (Click on News/Microsoft News Alert.)