. Military Space News .
Teamwork crucial to fighting cyber crime: Microsoft

Microsoft provides computer security allies with an "exploitability index" that gauges the likelihood hackers will target various vulnerabilities to help security firms prioritize responses.
by Staff Writers
San Francisco (AFP) July 27, 2009
Longtime computer security rivals are joining forces to battle increasingly sophisticated online attacks by cyber criminals.

"The attacks are getting more complex, and if we want to get ahead of attackers the call is to work together in a community approach," said Microsoft Security Response Center director Mike Reavey.

"One of the things becoming clear is that customers want vendors to work together, and they want information and protection out faster."

Microsoft used a premier Black Hat security conference taking place this week in Las Vegas as a stage to unveil enhancements to the software giant's computer defense collaboration efforts.

Microsoft released a new tool designed to make it easier for software security firms to model hacker threats and craft defenses.

The Redmond, Washington-based technology firm also unveiled a guidebook to de-mystify the realm of software security updates and vulnerability patches.

"There is a sea of information out there and we want to help customers navigate those waters," Reavey told AFP. "The guide walks them through what we do."

A Microsoft Active Protections Program launched at Black Hat last year has grown to 47 members that share information to minimize time hackers have to craft and launch attacks on newly discovered software weaknesses, Reavey said.

"By working together, the security vendors get free vulnerability information, Microsoft knows their products will be protected from widespread exploitation when the disclosure goes out, and customers win by remaining protected," TippingPoint security researcher Jason Avery said in a release.

"Everyone wins."

Microsoft provides computer security allies with an "exploitability index" that gauges the likelihood hackers will target various vulnerabilities to help security firms prioritize responses.

Microsoft also shares lessons learned while analyzing software for flaws.

"What we are seeing is they are working well with us and we are working well together," Reavey said of allies in the software security world.

Security industry teamwork was crucial in countering a Conficker virus that plagued the Internet early this year.

Microsoft rallied a task force to stamp out Conficker, also referred to as DownAdUp, and the software colossus has placed a bounty of 250,000 dollars on the heads of those responsible for the threat.

The worm, a self-replicating program, takes advantage of networks or computers that haven't kept up to date with security patches for Windows.

It can infect machines from the Internet or by hiding on USB memory sticks carrying data from one computer to another.

Conficker could be triggered to steal data or turn control of infected computers over to hackers amassing "zombie" machines into "botnet" armies.

Tools to remove Conficker virus and prevent its spread have been released, but computers without properly updated software could still be vulnerable.

"As the security climate evolves, it has become readily apparent that a new, more comprehensive approach is needed," Microsoft said in a security report released on Monday.

"The vision for a truly safer and more trusted Internet can only be realized through broad industry collaboration, technology innovations, and social, economic, political, and information technology alignment."

Share This Article With Planet Earth
del.icio.usdel.icio.us DiggDigg RedditReddit
YahooMyWebYahooMyWeb GoogleGoogle FacebookFacebook



Related Links
Cyberwar - Internet Security News - Systems and Policy Issues



Memory Foam Mattress Review
Newsletters :: SpaceDaily :: SpaceWar :: TerraDaily :: Energy Daily
XML Feeds :: Space News :: Earth News :: War News :: Solar Energy News


US government lacks tech talent for cyber defense: study
San Francisco (AFP) July 22, 2009
Bureaucracy and a shortage of employees with technology prowess have left the US government without the talent it needs to defend against cyber attacks, a study warned Wednesday. "The results of this research are troubling and, in many ways, familiar," said the authors of the report, which is intended to check the status of the federal cybersecurity workforce. "The overriding finding of ... read more







The content herein, unless otherwise known to be public domain, are Copyright 1995-2009 - SpaceDaily. AFP and UPI Wire Stories are copyright Agence France-Presse and United Press International. ESA Portal Reports are copyright European Space Agency. All NASA sourced material is public domain. Additional copyrights may apply in whole or part to other bona fide parties. Advertising does not imply endorsement,agreement or approval of any opinions, statements or information provided by SpaceDaily on any Web page published or hosted by SpaceDaily. Privacy Statement