Skip to navigation

PCPro-Computing in the Real World Printed from www.pcpro.co.uk

Register to receive our regular email newsletter at http://www.pcpro.co.uk/registration.

The newsletter contains links to our latest PC news, product reviews, features and how-to guides, plus special offers and competitions.

Latest News

Storm worm thunders into February malware chart

Posted on 1 Mar 2007 at 12:48

The deluge from the Storm worm places it at the top of the malware charts in February, according to findings from security appliance vendor Fortinet.

The worm, also known as Tibs, accounted for 3.91 per cent of all malware detected in the month. Only phishing emails were more prevalent than the worm.

According to Guillaume Lovet, threat response team leader at Fortinet, no less than 36 different variants of the Storm Worm were seen active this month.

'The overwhelming presence of the Storm worm is not without consequence, as it is being leveraged to generate and relay massive amounts of spam,' said Lovet.

'However, the battle against spam is not lost. A purely factual analysis of the situation tends to prove that in the final race to arms against content analysis filters, spammers are losing ground.'

The company found that on 8 February, one variant of the Storm worm accounted 60 per cent of all Tibs-related detections.

Lovet said that one very observable consequence of the worm was an increase in the volume of spam emails occurring since the end of 2006.

The Storm worm, alongside another worm named 'Stration', were purely meant to create large-sized botnets, more or less centralised. Stration's net consists in syndicated smaller traditional IRC botnets while Tibs implements a peer-to-peer botnet.

'Reducing the number of infected machines would effectively tackle the spam problem, at least, in the proportions it has taken today,' said Lovet. 'The problem is the number of infected machines, on the contrary, is growing everyday. The reasons for that are multi-fold, but the consequence is that we are left trying to cope with massive amounts of spam.'

Lovet added that content analysis is not the only means to block spam.

'Analysing the envelope rather than the content of the letters is a strategy frequently implemented in anti-spam filtering systems,' he said. 'For instance, it may consist in comparing the incoming IP address to real time block lists or reputation systems.'

He said that although such approaches are often purely reactive - leaving windows of opportunity opened for rogue IP addresses to send out spam - it could also help reduce the amount of bulk mails reaching end-users' boxes.

Author: Rene Millman

Be the first to comment this article

You need to Login or Register to comment.

(optional)

advertisement

Latest Blog Posts Subscribe to our RSS Feeds
Latest Reviews Subscribe to our RSS Feeds
Latest Real World Computing

advertisement

Sponsored Links
 
SEARCH
SIGN UP

Your email:

Your password:

remember me

advertisement


Hitwise Top 10 Website 2008