Showing posts with label Malware. Show all posts
Showing posts with label Malware. Show all posts

Saturday, November 26, 2011

Intel Introduced Doubtful Security Plan

After Chipzilla had bought the worldwide-known insecurity company McAfee, lots of industry experts wondered why, and recently Intel finally released the results of its collaboration.

Intel has developed a security system called Deepsafe. According to the giant, this system will work outside the operating system at the chip level, watching the hardware for signs of malware being active. The system in question is expected to be quite good at tackling rootkit malware attacks, because they also happen outside the operating system. For example, McAfee’s own threat report quoted the statistics which mentioned the number of rootkit infections discovered in the 6 months of this year being up 32% year-on-year.

At the same time, media reports revealed that the industry observers aren’t quite sure that the new idea of the company will make much difference in this field. For instance, Wendy Nather, which works as a security analyst from the 451 Group and is also known as a former IT security director at UBS, explained that Intel has actually had the security modules the new system is based on in their chipset for a while now. The only problem is that venders could not be even bothered to use them, as this demands development where they thought there was not much market interest.

The security system updates would be a bit more disruptive than the current security software patches – in fact, it would be more about changing the foundations of a building from underneath it. As for the first McAfee product based on this security system, it is Deep Defender, and it’ll be out there in the stores in the beginning of 2012. Wendy Nather pointed out that Intel is simply doing the same things as McAfee has already been doing now and moving them into the chipset. As you can understand, this doesn’t sound too exciting.

Meanwhile, the real area in which chip-level security would be very interesting is embedded systems. This is because they are being used virtually everywhere – from smart meters to mobile devices, in which, as you know, a lot of money are being invested in order to secure them. In short words, Deepsafe is a system which softly hints that the technology isn’t actually being targeted at personal computers at all. Instead, it can mean Intel’s move into the mobile market.

Monday, November 7, 2011

Duqu Hackers Moved Operations Abroad

Hackers who developed the latest doomsday virus named Duqu seem to have moved their illegal operations to Belgium. This country, known for being the birthplace of French fries, and also the rudest word in any language, is reported to have become the new headquarters of operations for the software developers who created this malware.

The hackers have begun using a server located in Belgium in order to gather information stolen from the computers infected with the Duqu malware. This started after security experts closed down their operations in India. Thus far, virus called Duqu has nations and security observers in a panic, since it could become another big Internet threat after the Stuxnet virus, which is considered to have infected the nuclear program of Iran.

Worldwide-known security company Symantec claimed that its experts had identified a sample of Duqu virus, which was designed to communicate with a certain server at Combell, the biggest web-hosting organization in Belgium. Symantec explained that the company had already notified Combell that one of their servers had been used for malicious activity. Combell immediately shut down the website.

It was a couple weeks ago that Duqu first surfaced online. It was spotted by experts from the Hungary’s Laboratory of Cryptography and System Security. The scariest part about the virus was that the latter exploited a hole in Windows operating system and had code similar to Stuxnet malware. The industry observers believe that Duqu has been developed to help lay the groundwork for cyber attacks on important infrastructure like pipelines, power plants, or oil refineries.

One of the unnamed Combell employees admitted that the server in question had been running continuously for almost a week. It was leased through the end of October 2012. He also told local media that it looked fishy, as someone tracking the server appeared to be intentionally deleting information that would log details about its communications. Meanwhile, the mail log itself had virtually no entries, which means that the intruders keep deleting information not to leave traces.

Security experts also admit that when the hackers moved to Belgium, they went further and modified the original method used to communicate with the infected machines, which made it harder for the outfits to detect infected equipment based on previous communication patterns.