Welcome | Sign In
MacNewsWorld.com
ECT News Exclusives

TWO-PART EXCLUSIVE INTERVIEW
Hunting Down Virus Writers with F-Secure's Mikko Hypponen

Print Version
E-Mail Article
Reprints
Hunting Down Virus Writers with F-Secure's Mikko Hypponen

"The biggest sin Microsoft has ever done is simply that they've become too popular, making them target number one," F-Secure director of antivirus research Mikko Hypponen told the E-Commerce Times. "I actually believe Microsoft has done a pretty good job after 2001 in trying to improve the security of their products at all levels and being able to respond fast to new vulnerabilities."


In part 1 of this interview, F-Secure director of antivirus research Mikko Hypponen spoke about getting his start in computer security 13 years ago and the changes he has seen over the years.

In this continuation of his chat with the E-Commerce Times, Hypponen talks about what it might take to nab malware writers -- and why a virus-free future might be a dream that never becomes reality.

E-Commerce Times: Have you had any run-ins with virus or worm writers?

Mikko Hypponen: Some, yeah. As an example, back in 1999 when our company was still called Data Fellows, one virus group registered the domain "datafellowes.com" and started sending mail around in my name, using the address mikko.hypponen@datafellowes.com instead of the real datafellows.com address. For example, they were sending out infected Word files as articles to various editors, as well as sending requests for virus sample to fellow researchers. Pretty nasty stuff. I'm happy there haven't been many incidents like this.

ECT: What would it take to catch more malware writers?

Hypponen: Global Internet police that would have the expertise and the jurisdiction needed to go after the virus writers, hackers and spammers that are rerouting their attacks through dozens of countries, including far-away places that have little or no legalization or authorities to track down crimes like these.

ECT: Do you think a global Internet police force can be created, or are there too many politics involved?

Hypponen: I really hope we could get something like this running, but obviously it won't be easy. Let's start by having countries like the USA and China agreeing on the rules of such an international Net police force. It should be downhill from there.

ECT: How can companies and individuals defend against new worms that do not require any interaction on the part of the user?

Hypponen: Different types of firewalls, both hardware and software, at various levels is really the only solution. Any type of reaction-based solution simply will not work, and this includes traditional antivirus.

ECT: Why don't reaction-based solutions work to defend against new worms?

Hypponen: They do, against e-mail worms and the like. They don't work against automatic network worms, which are simply too fast. But firewalls typically handle those.

ECT: If they're ineffective, why is it such a booming market?

Hypponen: Antivirus scanning is an easy concept to understand, so people like it. And unlike generic protection software or firewalls, it will actually tell you which virus it stopped, which people also find useful. And they do stop a majority of the current threats nicely.

ECT: What is currently the safest computer configuration for a home user?

Hypponen: Probably a Mac. That's what I would recommend. Coupled with Xbox for games, you can't really beat it, and no virus problems!

ECT: Why do you think Macs are so protected?

Hypponen: It's mostly about market share. Virus problems used to be much worse on Macs back in the late 1980s, when [Apple] had a much bigger percentage of the user base. The Mac system has vulnerabilities and security holes just like Windows. Or Linux. But attackers go after the masses.

ECT: Speaking of the masses, how do you think Microsoft is doing in terms of improving the security of its systems?

Hypponen: The biggest sin Microsoft (Nasdaq: MSFT) has ever done is simply that they've become too popular, making them target number one. I actually believe Microsoft has done a pretty good job after 2001 in trying to improve the security of their products at all levels and being able to respond fast to new vulnerabilities.

ECT: As SCO has shown us, a single company can be the target of anger. Do you think there will be more incidents like this in the future, when companies are "punished" by irate virus writers?

Hypponen: Definitely, and we've already seen similar attacks against RIAA and Microsoft. [In April], two Netsky variants will start a DDoS attack against these sites:

www.edonkey2000.com
www.kazaa.com
www.emule-project.net
www.cracks.am
www.emule.de
www.cracks.st
www.cracks.am
www.keygen.us

ECT: Do you think a "superworm" capable of spreading worldwide and wreaking major havoc is likely to arise?

Hypponen: Oh, yes. In fact, the Witty worm found [in late March] wasn't that far away from something like that. We got lucky because it only affected a minority of the world's computers, those running BlackIce firewall. If a worm like that had been exploiting a really common vulnerability, such as ASN.1, it would have happened already.

ECT: Why haven't virus writers been targeting common vulnerabilities like ASN.1?

Hypponen: Can't really explain that, except that most virus writers don't have skills to write their own exploits for that vulnerability, and public exploit code hasn't been circulating. Yet. Otherwise this would probably be a really tempting vulnerability for them, as it's very common.

ECT: How can corporations and individuals be prepared to respond?

Hypponen: Hardware and software-based firewalls are supposed to keep threats like these outside. Combining several layers of firewalls with constant OS patching and up-to-date antivirus is your best bet. Or running different systems than everybody else.

ECT: What kind of systems do you mean?

Hypponen: Like replacing Outlook with Eudora, or running Opera instead of Internet Explorer. You could also replace Microsoft Office with OpenOffice. These are the kind of tactics that bring more variety.

ECT: Is it possible to create a system that would prove to be a silver bullet for computer and network security?

Hypponen: Nope. Because this is not a technical problem. It's a social problem.

ECT: What are some of the social issues?

Hypponen: To fight the bored kids writing viruses for kicks, we should focus more on education early on in schools. Kids should be told that viruses are not cool and that they are illegal and you will go to jail if you write them.

To fight the more organized activity, the majority of which is coming from places like ex-Soviet Union states, we should bring real opportunities to the skillful programmers living in places where they can't support themselves by doing legal stuff. Internet crime gangs are a social problem, just like real-world crime gangs are a social problem.

How to fix that? You tell me.


Print Version E-Mail Article Reprints More by Elizabeth Millard


Related News Alerts

Microsoft Activate Alert | Search Archives

More by Elizabeth Millard

Ken Xie of Fortinet on Fighting Content Threats
November 25, 2004
"Integrating independent security systems together and keeping them all up-to-date and able to coordinate their actions in the face of a fast-moving attack is a daunting if not intractable task," Fortinet CEO Ken Xie told ECT News. "To deal with today's and tomorrow's blended threats requires a more integrated, holistic approach to security."
Microsoft Files More Lawsuits over Spam
September 24, 2004
Going after spammers rather than focusing merely on developing antispam technology is an important step, John Movina, spokesperson for the Coalition Against Unsolicited Commercial Email, said. He told The E-Commerce Times that the United States has weaker criminal laws against spam than other countries, so it's vital to find other means to stop spammers.
French Firms Aim To Beef Up Linux Security
September 24, 2004
The consortium plans to make bringing Linux up to the Evaluation Assurance Level 5 (EAL5), which is part of an internationally recognized security certification called Common Criteria, its first effort. EAL5 satisfies major security requirements in commercial as well as defense and government applications.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network