New Service Alerts You to Zombies On Your Computer   - 1,322 Views,

Summary: A new service is being offered by security company Sophos, which purports to alert businesses if a computer on their network has been compromised by being zombied. While what it actually does is tell you whether a computer on your network ...

Previous Article « 3 New Windows Security Bulletins for July, Many Systems Affected
Read Next Article » iPod as Criminal Mastermind Tool

  Follow Anne on Twitter     Friend Anne on Facebook

A new service is being offered by security company Sophos, which purports to alert businesses if a computer on their network has been compromised by being zombied. While what it actually does is tell you whether a computer on your network has suddenly been found sending spam and/or listed on an anti-spam blacklist, which isn’t the same thing (it doesn’t actually check your computers for zombieware, for example), for many businesses they are funcationally equivalent. And in this time of trying to get computer owners to take some responsability for the bad actions of their naughty computers, it’s still a nifty idea.

Here’s Sophos’ information about the service:

Sophos ZombieAlert Service notifies companies about their spammer-controlled computers

New automated service identifies exploited and hijacked computers on business networks
Lynnfield, MA - Sophos, a global leader in network security, announces the availability of Sophos ZombieAlert™, a new alert service that identifies “zombie� computers on an organization’s network. Zombie computers are infected machines that give control to unauthorized and remote users, allowing them to send spam from the computer or to launch email-based Denial-of-Service (DoS) attacks against websites.

SophosLabs™, Sophos’s global network of virus and spam analysis centers, estimates more than 50 percent of all spam today originates from zombie computers. In May, the Sober-Q Trojan horse and Sober-N worm worked in tandem to infect and hijack computers around the world, programming them to spew out German nationalistic spam during an election. As spammers become more aggressive, collaborating with virus writers to create armies of zombie computers, legitimate organizations with hijacked computers are being identified as a source of spam. This not only harms the organization’s reputation, but can also cause the company’s email to be blocked by others.

ZombieAlert advises service subscribers when any computer on their network is found to have sent spam to Sophos’s extensive global network of spam traps, and provides rapid notification to customers if their Internet Protocol (IP) addresses are listed in public Domain Name Server Blackhole Lists (DNSBL). This information helps customers locate, disinfect, and protect these systems from future attacks.

“Aside from consumers, organizations such as educational institutions and government agencies are most at risk because they often have complex environments with remote and home users, which makes it far more challenging to provide effective security,� said Gregg Mastoras, senior security analyst at Sophos. “Our global network of threat analysis centers, provide around the clock visibility into new and emerging threats, including compromised computers. This alert service gives organizations the opportunity to remedy the situation and clean their systems.�

“Sophos is the first vendor we know of to offer an on-the-fly alert service that advises organizations that they are being used to host zombies,” said David Ferris of Ferris Research. “This service is unique and very timely. I would anticipate that competitors would soon follow suit.”

For Internet Service Providers (ISPs), the problem is equally as critical since consumers are largely targeted. This service enables ISPs to identify and alert consumers of the threat while providing the opportunity to recommend that end-users to practice safe computing habits.

“Our IT support staff spends a lot of effort and has good success protecting desktop systems and servers,â€? said Alan Pfeiffer-Traum, enterprise system administrator and electronic mail postmaster at the University of Houston. “It’s a real challenge to extend that protection to computers that faculty and students bring with them to campus every day, not to mention those that access the campus VPN. Despite our efforts, zombies happen. ZombieAlert is a very effective tool to catch those hijacked computers in the act. I especially appreciate that I don’t have to depend on received complaints to be alerted - I can say we detected the abuse through our own monitoring.â€?

New Service Alerts You to Zombies On Your Computer

 Follow Anne on Twitter

 Twitter Explained in Plain English

 Friend Anne on Facebook

Previous Article « 3 New Windows Security Bulletins for July, Many Systems Affected
Read Next Article » iPod as Criminal Mastermind Tool

Read more:

»  Killing Network Spam Zombies Made Easy

»  New Zombies Predicted to Increase Spam

»  Cingular Wireless Customers Can Receive AMBER Alerts by Phone (News Release)

»  MySpace to Post Operation Amber Alerts

For additional similar stories check out our archives on Reviews, Spam, Spam Blockers

NOTE: We never, ever, ever will recommend any product or service on this site that we have not regularly used ourselves and do not wholeheartedly believe in. That said, in some cases after being very pleased with a product or service, we may enter into a relationship with the provider of that product or service such that if someone purchases that product or service based on our recommendation, we may get a small payment. Such payments go towards the upkeep of the Internet Patrol.

 

No Comments »

No comments yet.

RSS feed for comments on this post.

Leave a comment

Warning! All comments which contain URLs and are clearly just spam to generate a link back to the URL will be deleted on sight. Don't bother wasting your time!

If you are going to include a URL in your comment,
please keep it under 25 characters in length,
or use TinyURL to shorten it before including it in your comment.

Line and paragraph breaks are automatic, your email address is never displayed.
HTML allowed: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <cite> <code> <del datetime=""> <em> <i> <q cite=""> <strike> <strong>

(required)

(required)


If you have not posted a comment here before, we apologize for having to ask you to enter the letters and numbers you see in the image above to validate your comment, but we are being attacked by thousands of comment form spams every day! You only need to do this once; once you have successfuly posted a comment here you will not be asked to do this again. Thank you for your understanding!

 
 This article first appeared on 7/13/2005
The Internet Patrol
Patrolling the Internet for You!