New search engine to track down viruses

July 25, 2006

The hundreds of thousands of computer users whose PCs have been torn asunder by viruses could now have a new weapon in their arsenal against online attacks. A new search engine has been launched that will exclusively hunt down the pesky malware that make the lives of so many Net users a misery. Using a simple Google search, users will able to enter keywords into the Malware Search engine and track down live malware samples.

Malware -- the term is an amalgamation of "malicious" and "software" -- is the irritating software designed specifically to infiltrate and damage a computer system, and includes such beasties as Trojan horses, spyware, viruses and worms.

The engine has been developed by HD Moore, a well-respected software engineer who works as the director of security research at the Austin-based BreakingPoint Systems and who was responsible for creating the Metasploit hacking tool and the MoBB (Month of Browser Bugs) project. According to an interview in eWEEK, Moore was partly motivated to create by the announcement that Websense Security Labs were using the Google SOAP (Simple Object Access Protocol) Search API to find dangerous .exe files, or executables, that were sitting on Web servers. Although Google SOAP is free for anyone to use, Websense were only sharing the results of searches on private security mailing lists. Moore decided to take a more altruistic approach and, together with researchers from the Offensive Computing project, created Malware Search using open-source programs.

The engine would be simplicity itself to use -- in a user-friendly Web interface, Internet users just need to enter the names of the malware they want tracked down, such as "Bagle," "SoBig" or "MyDoom." The engine will then hunt through hundreds of thousands of Web sites to track down the ones that are hosting the malicious executables. The engine's site closely resembles Google's design, and as with Google, will bring up search results of the Web sites that were purposefully or inadvertently hosting the malware searched for. Broader searches can also be performed using more general search-terms such as "e-mail" or "Trojan." So far, the engine is limited to Google-based queries, but this may be expanded at some stage in the future.

Malware Search differs from other similar programs such as Netsense in that it is open source, making it more freely and widely available than its predecessors. Members of many of the online software interest forums such as Slashdot showed eager encouragement for the engine and saw potential uses in both the workplace and at home. IT managers for non-technology companies would be able to determine if any glitches in the behavior of their internal networks was due to malware sitting in one of the company's computers. At the broader level, Internet hosting providers would be able to keep tabs on their customers to see if any servers were hosting malware, and let the servers' operators know that their sites may have been breached. As one poster on Slashdot enthused, "The combination of this system and using Google for internal searches could make Google a sudden major competitor in the anti-malware campaign."

The program identifies specific malware without the Google application programming interface, using instead code string "fingerprints" from malware samples that the Malware Search programmers already have access to. According to Moore, the engine has already been programmed with 300 malware signatures, and there are plans to add a further 6,000 in a future bug update.

On the Net: http://metasploit.com/research/misc/mwsearch/index.html

Copyright 2006 by United Press International


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 3 /5 (20 votes)


July 25, 2006 all stories

Comments: 0

3 /5 (20 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Student team - building a satellite - want to join - problem:i'm a biotech student.
    created 23 hours ago
  • Motor Driver
    created Nov 13, 2009
  • Thermocouple Probe Selection
    created Nov 12, 2009
  • Ansys beam element contours
    created Nov 12, 2009
  • More from Physics Forums - General Engineering

Other News

Google digital book ambitions hinge on settlement (AP)

Google makes concessions on digital book deal (Update)

Technology / Internet

created 4 hours ago | popularity 5 / 5 (1) | comments 2

(AP) -- Google Inc. will loosen its control over millions of copyright-protected books that will be added to its digital library if a federal judge approves a revised legal settlement addressing the earlier ...


Aircraft that can see for themselves

Aircraft that can see for themselves (w/ Video)

Technology / Engineering

created 4 hours ago | popularity 5 / 5 (3) | comments 0

(PhysOrg.com) -- Australian researchers have made two important advances in the development of unmanned aircraft capable of seeing for themselves as they fly fast and low over dangerous terrain.


Cars sit in traffic on a highway

Netherlands to levy 'green' road tax by the kilometre

Technology / Hi Tech

created 14 hours ago | popularity 3 / 5 (4) | comments 2

The Dutch government said Friday it wants to introduce a "green" road tax by the kilometre from 2012 aimed at cutting carbon dioxide emissions by 10 percent and halving congestion.


Cryptographic voting debuts

Cryptographic voting debuts

Technology / Computer Sciences

created 23 hours ago | popularity 5 / 5 (3) | comments 5

(PhysOrg.com) -- Last week, in Takoma Park, Md., a new cryptographic voting system that could ensure accurate vote counts was used for the first time in a real election. MIT’s Ron Rivest, the Viterbi Professor ...


Digital cloud may rise over London

Digital cloud may rise over London (w/ Video)

Technology / Hi Tech

created 23 hours ago | popularity 2.5 / 5 (8) | comments 3

(PhysOrg.com) -- An international group of artists, engineers and architects have proposed an enormous "digital cloud" to turn London's skyline into an overhead display of data and images.