Spyware poses a significant threat on the Net

February 3rd, 2006

Spyware is alive and well on the Internet. That's the overall message of a new study by University of Washington computer scientists who sampled more than 20 million Internet addresses, looking for the programs that covertly enter the computers of unwitting Web surfers to perform tasks ranging from advertising products to gathering personal information, redirecting Web browsers, or even using a victim's modem to call expensive toll numbers.

They examined sites in a set of popular Web categories, such as game sites, news sites and celebrity-oriented sites. Within these, they found that:

-- More than one in 20 executable files contained piggybacked spyware.
-- On average, one in 62 Internet domains performed drive-by download attacks – a method for forcing spyware on users who simply visit a Web site.
-- Game and celebrity Web sites appeared to pose the greatest risk for piggybacked spyware, while sites that offer pirated software topped the list for drive-by attacks.
-- The density of spyware seemed to drop from spring to fall of last year, but remained "substantial."

The research is being presented today as the opening paper for the 13th Annual Network and Distributed System Security Symposium in San Diego, Calif.

"For unsuspecting users, spyware has become the most 'popular' download on the Internet," said Hank Levy, professor and holder of the Wissner/Slivka Chair in the UW's Department of Computer Science & Engineering and one of the study's authors. "We wanted to look at it from an Internet-wide perspective – what proportion of Web sites out there are trying to infect people? If our numbers are even close to representative for Web areas frequented by users, then the spyware threat is extensive."

The consequences of a spyware infection run the gamut from annoying to catastrophic.

On the annoying end, where most spyware falls, the stealthy programs can inundate a victim with pop-up advertisements. More malicious programs steal passwords and financial information. Some types of spyware, called Trojan downloaders, can download and install other programs chosen by the attacker. In a worst-case scenario, spyware could render a victim's computer useless.

In conducting the study, the UW researchers – Levy, associate professor Steven Gribble and graduate students Alexander Moshchuk and Tanya Bragin – used a computer program called a Web crawler to scour the Internet, visiting sites to look for executable files with piggybacked spyware. The team conducted two searches, one in May and the other in October, examining more than 20 million Web address. They also did additional "crawls" of 45,000 Web addresses in eight subject categories, looking for drive-by download attacks.

In the first two crawls, the researchers found that approximately one in 20 executable files contained piggybacked spyware. While most of those were relatively benign "adware" programs, about 14 percent of the spyware contained potentially malicious functions.

In terms of drive-by download attacks, the researchers found a 93 percent reduction between May and October – a finding they say may in part be attributed to the wider adoption of anti-spyware tools, automated patch programs such as Windows Update and the recent spate of civil lawsuits brought against spyware distributors.

Despite that drop, the public should still be vigilant, they said.

"Plenty of software on the Web contains spyware, and many Web sites are infectious," Gribble said. "If your computer is unprotected, you're quite likely to encounter it."

There are a few steps that people should take to protect themselves, according to Gribble.

"First, everybody should install one or more anti-spyware programs," he said. "There are several high-quality free or commercial software packages available."

It's also important to keep those tools up-to-date so new threats can't get around one's cyber defenses.

Finally, Gribble said, people need to use common sense.

"You should download software only from reputable sources," he said. "And it's a good idea to avoid the more shady areas of the Web."

Source: University of Washington


print this article email this article download pdf blog this article bookmark this article     Digg this Stumble it share on Facebook share on Reddit add to delicious save to Yahoo! bookmarks
4.3/5 after 13 votes


February 3rd, 2006 all stories
Technology /

Comments: 0
Rank: 4.3/5 after 13 votes

  • Stumble this up

  • Digg this

  • Share it:
  • share on Facebook
  • share on MySpace
  • share on Slashdot
  • rss-newsfeed
  • share on Google
  • share on Reddit
  • add to delicious
  • save to Yahoo! bookmarks
  • share on Windows Live
  • Add to Mixx!
Rating: 4.3/5 after 13 votes

  • Related Stories

  • A 'reunion' that left her embarrassed
    created Feb 04, 2009 | popularity not rated yet | comments 0
  • Digital TV likes clear signal path
    created Dec 31, 2008 | popularity not rated yet | comments 0
  • 94 percent of spam-advertised online scams are hosted on individual Web servers
    created Aug 06, 2007 | popularity not rated yet | comments 0
  • Symantec Cracks Down on Piracy
    created May 22, 2007 | popularity not rated yet | comments 0
  • Security Bigwigs Patch Their Programs
    created May 13, 2007 | popularity not rated yet | comments 0

Tags


  • Physicists Demonstrate Quantum Memory with Matter Qubits
    Physicists Demonstrate Quantum Memory with Matter Qubits
    Physics / General Physics
    created Jul 03, 2009 | popularity 4.4 / 5 (16) | comments 1
  • 'Holey' Nanosheets for Wastewater Dye Removal
    Nanotechnology / Nanomaterials
    created Jul 01, 2009 | popularity 5 / 5 (5) | comments 1
  • Jellyfish Robot Swims Like its Biological Counterpart
    Jellyfish Robot Swims Like its Biological Counterpart
    Electronics / Robotics
    created Jun 26, 2009 | popularity 4.4 / 5 (7) | comments 1
  • Could Maxwell's Demon Exist in Nanoscale Systems?
    Could Maxwell's Demon Exist in Nanoscale Systems?
    Physics / General Physics
    created Jun 24, 2009 | popularity 4.4 / 5 (18) | comments 29
  • Living Safely with Robots, Beyond Asimov's Laws
    Living Safely with Robots, Beyond Asimov's Laws
    Electronics / Robotics
    created Jun 22, 2009 | popularity 4.6 / 5 (52) | comments 40
  • Other News

    Japan demands 119 million dlrs in tax from Amazon: report

    Technology / Business

    created 2 hours ago | popularity not rated yet | comments 0

    Japanese authorities told a sales affiliate of US retail giant Amazon.com to pay about 119 million dollars in tax for unreported income over a three-year period, a newspaper said Sunday.


    Iconic skyscrapers find new luster by going green (AP)

    Iconic skyscrapers find new luster by going green

    Technology / Energy

    created 3 hours ago | popularity 1 / 5 (1) | comments 0

    (AP) -- When owners of the Empire State Building decided to blanket its towering facade this year with thousands of insulating windows, they were only partly interested in saving energy. They also needed ...


    UK spy chief's family details posted on Facebook

    Technology / Internet

    created 3 hours ago | popularity not rated yet | comments 0

    (AP) -- He's the spy who came in from the beach.


    Downturn dating: Hearts flutter as markets stutter (AP)

    Downturn dating: Hearts flutter as markets stutter

    Technology / Internet

    created 3 hours ago | popularity not rated yet | comments 0

    (AP) -- Credit the recession for "staycations" and bringing us more game-night parties at home. But also give it a shout for spurring more first dates.


    Omg! Positive tone boosts Yahoo celeb site to top

    Technology / Internet

    created 22 hours ago | popularity 2.5 / 5 (2) | comments 0

    (AP) -- Think of the most popular brands in celebrity news, and you'll probably come up with a small list that includes Entertainment Tonight, US Weekly and People.