Commentary: Microsoft can help kill fake antivirus threat

By Munir Kotadia on Oct 21, 2009 1:10 PM
Filed under Security

Redmond should whitelist legitimate security firms.

Earlier this week, Symantec revealed that 42 million fake antivirus applications were downloaded last year.

It seems consumers are being duped into paying between $30 and $100 for software that basically hands full control of their computer over to cybercriminals.

The problem, according to Symantec, is that it's almost impossible for a consumer to tell the difference between a legitimate security application and a fake one. There is also no way of making a blacklist of fake apps because new ones are springing up on a regular basis.

"You really can't tell the difference anymore," said Rob Pregnall, a senior manager of Symantec's endpoint security. "They change all the time. If we could say, 'look for the one with the squiggly face in the top left corner,' it would be different by 11am - they would have changed it."

Below is a screenshot of one fake security warning that appeared on my laptop earlier this year. In this particular case it had virtually no chance of fooling me because it was displaying Windows dialogue boxes and fonts on my MacBook. But as you can see, it is pretty convincing.

Pregnall suggested that users rely on the same 'sixth sense' that helps them differentiate between legitimate emails and spam. Unfortunately, even savvy users are vulnerable to social engineering attacks - and these criminals spread their nets fairly wide so even if they only hook a few fish each time, they make a healthy profit.

Symantec's research claims 42 million fake AV apps were downloaded in 2008 and victims paid between US$30 and US$100 for each one. If we stick to the lowest price point, it means these apps made US$1.26bn!

According to Gartner figures, in terms of revenue alone, the fake antivirus product in 2008 generated more money than Trend Micro (US$938m) and almost as much as McAfee (US$1.47bn). Symantec still towers over the rest with 2008 revenues of almost US$3bn.

I can't help but be impressed by the fake AV makers for being so successful in a market so competitive it has already beaten off the likes of Microsoft, which recently launched a free antivirus application, Microsoft Security Essentials, to replace its unsuccessful OneCare Live product.

A solution

Ironically, I believe Microsoft could save the world from fake security applications by introducing a whitelist for apps from legitimate security firms.

This would mean that Symantec, Trend, AVG, Kaspersky and the rest would have to work with Microsoft to ensure their products were recognised as 'genuine' security applications.

Pregnall agrees whitelists are the future but is under no illusion that the problem will be easy to fix - especially if it means Symantec would have to start playing nice with Microsoft.

"I think the whitelisting argument is going to get considerable consideration in the future. There are obviously huge challenges in resourcing it and with different applications, files, patch updates etc - to keep away annoying alerts.

"However, reputation and whitelisting is definitely part of the way forward," he said.

I asked Microsoft about where it stands on the whitelisting front and about the potential obstacles to developing such a solution but as yet, Redmond has remained silent.

This might be understandable, as the company is preparing to launch Windows 7 tomorrow. I will keep asking them and try to report back to you next week.

In the meantime, I'd love to know what you think. Would whitelisting solve the issue? Is there a better way? How can you tell a fake security app from a real one? Do you care?

 
Follow us on Facebook and Twitter
 
Commentary: Microsoft can help kill fake antivirus threat
"whitelisting creates a new problem - what amount of source code would microsoft need to be able to identify the product, and what would the manufacturer feel about providing the info? For new ..."
 
 
 
 
Comments: 2
spook1958
Oct 21, 2009 4:21 PM
Most of the fake security apps download themselves to clients computers and that is a dead giveaway. Only a very small percentage of customers actually fall for the messages and buy the product. So whilst 42 million fakes are downloaded, probably less than 10% result in a sale and since all payments are by credit card the transactions get stopped once people like us advise the clients of the situation. Very few would end up with a successfull sale.

Ian

plhau98
Oct 24, 2009 12:09 AM
whitelisting creates a new problem - what amount of source code would microsoft need to be able to identify the product, and what would the manufacturer feel about providing the info?

For new users, not particularly technology savvy, would they download and accept the product, or would they reject it?

How many resellers have had clients download and install some piece of software (and really, you have to use the term lightly, not software, more bloat or adware) onto their system, then blame legit software when the system fails?

There have been some horror stories out there - I have witnessed a few surprising actions by the end users, ranging from turning off the AV package as it was impacting their internet speed, to believing that god would stop viruses on their computer... That particular one had over 85 viruses on their computer, including a couple that reset their bookmarks to "unsavory" sites, and changed their home page to something that I don't think they knew how to do. They learnt the hard way.

In order for software to be legit, the end users need to be educated to come to a reseller for software, don't expect that because the site is telling them they need it, that they actually do.

Resellers are there for a reason. They spend time training their staff to understand the technologies and new releases, they are an end user's friend, business advisor, and the last bastion between the end user and frivolous spending on a package that they don't want or need.
Comments have been disabled for this article.
 
 
Top Stories
In pictures: HTC One vs Samsung Galaxy S4
Two Android titans battle it out.
 
Dell's fiscal silver lining
Remaking itself into an enterprise company.
 
In pictures: Google I/O 2013
Evolution not revolution.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Latest Comments
Polls
Is your business doing as well now as it was at this time last year?


   |   View results
Yes
  31%
 
No
  53%
 
The same
  15%
TOTAL VOTES: 346

Vote now
CRN Magazine

Issue: 315 | May 2013

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.