...that which we call conficker by any other name would taste as sour.
david harley, tom kelchner, and mary landesman have all posted their responses to an infosecurity article questioning the apparent lack of consistency in malware naming.
they all say more or less the same thing about the deluge of modern malware making harmonization of names impossible and to a certain extent they're right, but to a certain extent they're also wrong - not so much in the technical details of their answer but more in the way they're framing the problem that the infosecurity article was underlining.
now the truth is i had actually planned on writing about malware naming some time ago in response to another of david harley's articles in which he basically says malware names are irrelevant. i can see where he's coming from with that, and probably you can too. a malware detector doesn't care what the name of the malware is, only whether it's there or not - and the consumer of the malware detector generally won't care that much about the name either (certainly not whether it's the same name that all the other vendors use). in the consumer's worst case scenario all they really need is some sort of unique identifier, be it a number, a GUID, or some made up nonsense word (oh, wait, that's what they get now) in the event that they need to call up the vendor for support.
but there's a problem with this line of thinking and i'll demonstrate it with a little thought experiment. let's take all the bones in the human body and replace their current identifiers (such as scapula, ulna, radius, etc) with numbers, or GUIDs, or made up nonsense words. now try having an intelligible discussion about bones you've broken over your lifetime with someone. can you imagine how much more difficult that would be? obviously replacing their current names with the made up nonsense words would just pose difficulty in adjusting to new names but GUIDs would be far too unwieldy for people to use, and numbers would have numerical relationship baggage that would confuse the issues. let's take one more step in this thought experiment, however. let's say there are 50 different people, each with their own different set of replacement identifiers for the bones in the human body, and let's say that they collectively are trying to advise people on bone health. how well is that really going to work? not very well, obviously.
while it is true that malware today is far too numerous to harmonize the naming for each and every instance, we can't let the great become the enemy of the good. if the anti-malware world revolved exclusively around the production and consumption of malware detectors then names really would be unimportant and irrelevant, but the fact is in such a world people like david harley and tom kelchner and mary landesman wouldn't be blogging about such things because those blogs would also be irrelevant.
the thought experiment above demonstrates when names are important and why consistent names are important. names are important when you're dealing with people rather than just technology. they are important when you are trying to communicate information about threats, trends, etc. to people. people need names for things, and frankly they need to be fairly simple names - that's why storm, loveletter, and code red catch on while waledac, virut, and sality wallow in obscurity, and why people keep misspelling conficker. heck, it's why meteorologists name significant weather formations like hurricanes using human given names like harry or katrina. people also need for multiple authorities to agree on the names for things or else they can't integrate data from multiple sources and are left disoriented and confused.
again, we can't let the great (harmonizing the naming of all malware instances) become the enemy of the good (harmonizing the naming of the relative handful of malware instances the industry considers significant enough to write about in things like year-end threat reports). it may be impossible to coordinate names for each malware instance in existence and entirely pointless even if it were possible, but the same does not hold true for the small set of malware that vendors write about by name. just so we're clear, i'm not suggesting that such coordination need take place before releasing detection for the aforementioned malware. what i have in mind is something not unlike the now defunct common malware enumeration with the exception of using names instead of numbers - a post hoc harmonized second name (a common name or layman's name) for those few pieces of malware that the industry feels they need to communicate to the masses about.
of course, after all that is said and done, even if naming were consistent i fully realize that different vendors reports would list different sets of malware and to that end people still need to understand that such reports reflect not the actual threat landscape but what the vendor has seen of the threat landscape. to that end there should still be overlap between the sets of malware used by different vendors in their reports, and if there isn't that suggests sampling bias pronounced enough to render those models of the threat landscape irrelevant.
devising a framework for thinking about malware and related issues such as viruses, spyware, worms, rootkits, drm, trojans, botnets, keyloggers, droppers, downloaders, rats, adware, spam, stealth, fud, snake oil, and hype...
Showing posts with label malware naming. Show all posts
Showing posts with label malware naming. Show all posts
Sunday, January 10, 2010
Thursday, January 25, 2007
eEye on malware naming
y'know, when you're in a position where you're supposed to be an authority on a subject and you're talking about something seemingly related to that subject, it behooves you to either know what you're talking about or stop talking...
in marc maiffret's case neither of those paths were taken... it's amazing to me that the chief technology officer at eEye would say something like this:
it's difficult to take anything he says seriously after such an incredible gaffe but it's also difficult to let such clear (and frankly surprising considering his position) false authority syndrome slide...
you see, marc would have us believe that the vendors are fighting over who gets to name what and that because they're making "really good money" that they have no incentive to address the naming confusion and give users what they "are actually asking for"... apparently in marc's experience if you just put your mind to it you should be able to get 20-30 companies who operate independently (necessarily so since they're producing signatures for use with different technologies) to co-ordinate the naming of hundreds of malware samples per day while not compromising their top priority of getting detection capabilities (which necessarily require a name, any name, good or bad, to identify what is detected) to users as fast as possible...
that was sarcasm, of course... you can't co-ordinate malware naming without slowing down the process of getting signatures to customers and thus compromising that top priority - and i'm pretty sure that most people would choose a speedy signature turn-around (which directly aids in prevention) over harmonized naming (which doesn't)... while you're waiting for for those 20-30 companies to figure out if they already have a copy of your to-be-co-ordinated sample and which of their many samples that is, your analysts have already finished their analysis and have created signatures to be pushed out to customers...
what they can do (and the main CME page indicates they have done on occasion) is rename the malware after the fact, either to adopt the name other companies are using or to append the CME identifier to the name... unfortunately, this still requires time and effort to co-ordinate a harmonized name and thus cannot possibly be done for each of the hundreds of samples anti-virus companies process each day - especially when most of those hundred samples are complete flops in the wild (making the work to harmonize their names wasted effort)... even without explicitly renaming their samples, the CME lists the various names associated with particular CME id's and that resolves much of the naming ambiguity end users are likely to encounter...
so next time you see someone attributing the malware naming mess to lack of interest or petty rivalry, take a moment to consider the realities of the situation and ask yourself how or even if those logistical problems can be overcome (without fundamentally changing the anti-malware landscape, since obviously naming wouldn't be a problem if there were magically only one company)...
ADDENDUM: i've been informed by marc maiffret that he was misquoted in the article in question, at least a far there being nothing like the CVE in the malware world (maybe other things too?)... as such, i apologize for characterizing marc as suffering from false authority syndrome (and for being asleep for a year or more) since it's no longer clear that's the case... it seems the article's author, scott m. fulton, may be more responsible for the false picture that article painted... i do stand by my criticism of the notions put forth in that article though - the problems associated with malware naming are not easily overcome, nor trivially attributable to character flaws in the vendors...
in marc maiffret's case neither of those paths were taken... it's amazing to me that the chief technology officer at eEye would say something like this:
"In the vulnerability world, we have CVEs [Common Vulnerabilities and Exposures] as a way to know that we're all talking about the same vulnerability regardless of what we might have named it in our product. In the anti-virus world, there's not really anything like that."has he been asleep for the past year or more?* because the CME (common malware enumeration) has been around since october 2005 (actually 2005 this time)...
it's difficult to take anything he says seriously after such an incredible gaffe but it's also difficult to let such clear (and frankly surprising considering his position) false authority syndrome slide...
you see, marc would have us believe that the vendors are fighting over who gets to name what and that because they're making "really good money" that they have no incentive to address the naming confusion and give users what they "are actually asking for"... apparently in marc's experience if you just put your mind to it you should be able to get 20-30 companies who operate independently (necessarily so since they're producing signatures for use with different technologies) to co-ordinate the naming of hundreds of malware samples per day while not compromising their top priority of getting detection capabilities (which necessarily require a name, any name, good or bad, to identify what is detected) to users as fast as possible...
that was sarcasm, of course... you can't co-ordinate malware naming without slowing down the process of getting signatures to customers and thus compromising that top priority - and i'm pretty sure that most people would choose a speedy signature turn-around (which directly aids in prevention) over harmonized naming (which doesn't)... while you're waiting for for those 20-30 companies to figure out if they already have a copy of your to-be-co-ordinated sample and which of their many samples that is, your analysts have already finished their analysis and have created signatures to be pushed out to customers...
what they can do (and the main CME page indicates they have done on occasion) is rename the malware after the fact, either to adopt the name other companies are using or to append the CME identifier to the name... unfortunately, this still requires time and effort to co-ordinate a harmonized name and thus cannot possibly be done for each of the hundreds of samples anti-virus companies process each day - especially when most of those hundred samples are complete flops in the wild (making the work to harmonize their names wasted effort)... even without explicitly renaming their samples, the CME lists the various names associated with particular CME id's and that resolves much of the naming ambiguity end users are likely to encounter...
so next time you see someone attributing the malware naming mess to lack of interest or petty rivalry, take a moment to consider the realities of the situation and ask yourself how or even if those logistical problems can be overcome (without fundamentally changing the anti-malware landscape, since obviously naming wouldn't be a problem if there were magically only one company)...
ADDENDUM: i've been informed by marc maiffret that he was misquoted in the article in question, at least a far there being nothing like the CVE in the malware world (maybe other things too?)... as such, i apologize for characterizing marc as suffering from false authority syndrome (and for being asleep for a year or more) since it's no longer clear that's the case... it seems the article's author, scott m. fulton, may be more responsible for the false picture that article painted... i do stand by my criticism of the notions put forth in that article though - the problems associated with malware naming are not easily overcome, nor trivially attributable to character flaws in the vendors...
Monday, October 10, 2005
what the Common Malware Enumeration really is
i was not the least bit impressed by what i read in the comments to Schneier on Security: Computer Malware to Have Uniform Names... clearly people don't understand what the CME is or what it will be able to do...
first and foremost it is NOT a new naming scheme, it won't replace existing names or displace existing naming conventions... anti-virus companies will continue to name viruses in exactly the same way as they have been - the Common Malware Enumeration won't change that... at best the CME will provide a well coordinated alias for malware of significant interest...
the CME will not solve the naming problem... the naming problem is a byproduct of the commercial anti-virus environment - many competing organizations working in parallel on their own products necessitates that they come up with names themselves in order to get signatures to their customers as quickly as possible... waiting for some centralized body to give the malware a standard name means that they'd be leaving their customers exposed to the threat without protection for longer (because of the "deconfliction" process) which would ultimately hurt their bottom-line...
the CME isn't necessarily going to improve the situation for users... not only are average users not going to be aware of what the CME is or what the CME number for a particular peice of malware can be used for, but it will likely have a similar effect on the anti-virus community that project vgrep had - it's presence will make naming consistency seem less important... it won't actually be less important, CME's will be numbers and thus will be next to unusable by real people except as an index to use when looking something up - names will still be used when discussing things or calling up tech support, etc... names are what people actually remember, not numbers, and with less motivation to be consistent with other organizations when it comes to naming the naming problem is likely to get worse instead of better...
this won't lead to better protection, it won't even guarantee less confusion... it'll be a big help to those of us who know what's what (and hopefully it won't go in the brain-dead direction project vgrep did by requiring registration in order to do lookups) but that's about it...
first and foremost it is NOT a new naming scheme, it won't replace existing names or displace existing naming conventions... anti-virus companies will continue to name viruses in exactly the same way as they have been - the Common Malware Enumeration won't change that... at best the CME will provide a well coordinated alias for malware of significant interest...
the CME will not solve the naming problem... the naming problem is a byproduct of the commercial anti-virus environment - many competing organizations working in parallel on their own products necessitates that they come up with names themselves in order to get signatures to their customers as quickly as possible... waiting for some centralized body to give the malware a standard name means that they'd be leaving their customers exposed to the threat without protection for longer (because of the "deconfliction" process) which would ultimately hurt their bottom-line...
the CME isn't necessarily going to improve the situation for users... not only are average users not going to be aware of what the CME is or what the CME number for a particular peice of malware can be used for, but it will likely have a similar effect on the anti-virus community that project vgrep had - it's presence will make naming consistency seem less important... it won't actually be less important, CME's will be numbers and thus will be next to unusable by real people except as an index to use when looking something up - names will still be used when discussing things or calling up tech support, etc... names are what people actually remember, not numbers, and with less motivation to be consistent with other organizations when it comes to naming the naming problem is likely to get worse instead of better...
this won't lead to better protection, it won't even guarantee less confusion... it'll be a big help to those of us who know what's what (and hopefully it won't go in the brain-dead direction project vgrep did by requiring registration in order to do lookups) but that's about it...
Tags:
anti-virus,
cme,
malware,
malware naming
Wednesday, July 21, 2004
this public roasting is long overdue
check out
Billgates
and
Fewster.1781
notice anything amiss? no? well you should...
both of these are examples of anti-virus companies FAILING to comply with a long standing naming standard that (among other things) states that viruses must not be named after real people unless you know for sure the virus was written by them.... rod fewster is an anti-virus professional and did not write the virus named after him - i dare say bill gates didn't write any virus named billgates either...
both of these examples are quite old, but they don't outdate the naming convention of which i speak... further, it doesn't take a rocket scientist to figure out what's wrong with letting viruses be named after real people...
not only are these companies showing a distinct lack of concern for the reputations of these people, they're also showing a distinct lack of concern for the public at large... naming standards are made for good reasons, not the least of which being reducing confusion and making it easier for people with virus problems to find information on the virus they have...
and it's not like virus names don't get changed - they do, quite regularly, it's the only way to coordinate a common name used across multiple products... but those 2 examples have been sitting around for nearly a decade now... where's the effort to make your life easier? where's the concern for the customer? certainly doesn't look like it's anywhere near these 2 companies right now...
(thanks to art kopp for digging up these examples...)
Billgates
and
Fewster.1781
notice anything amiss? no? well you should...
both of these are examples of anti-virus companies FAILING to comply with a long standing naming standard that (among other things) states that viruses must not be named after real people unless you know for sure the virus was written by them.... rod fewster is an anti-virus professional and did not write the virus named after him - i dare say bill gates didn't write any virus named billgates either...
both of these examples are quite old, but they don't outdate the naming convention of which i speak... further, it doesn't take a rocket scientist to figure out what's wrong with letting viruses be named after real people...
not only are these companies showing a distinct lack of concern for the reputations of these people, they're also showing a distinct lack of concern for the public at large... naming standards are made for good reasons, not the least of which being reducing confusion and making it easier for people with virus problems to find information on the virus they have...
and it's not like virus names don't get changed - they do, quite regularly, it's the only way to coordinate a common name used across multiple products... but those 2 examples have been sitting around for nearly a decade now... where's the effort to make your life easier? where's the concern for the customer? certainly doesn't look like it's anywhere near these 2 companies right now...
(thanks to art kopp for digging up these examples...)
Tags:
anti-virus,
eset,
kaspersky,
malware naming,
virus
Thursday, June 17, 2004
let's play the name game
ok i'll preface this by saying this was sparked by a debate currently going on in alt.comp.virus.source.code...
if you don't know already, anti-virus companies generally do not call a virus by the name the virus' author gave it... they rename the virus... that renaming results in something you may have seen before - different companies issuing virus alerts for a particular virus with different names...
there are those that say it makes no sense to do this... they say it's stupid, it pisses off the virus writers and it creates confusion among end users...
however, there are some important points to realize:
so clearly some viruses have to be renamed... but do all of them have to be renamed?
it's been suggested that you could simply use your best judgment to tell if the author supplied name was suitable or not - maybe even use a search engine since obviously a person isn't going to see the significance of many references from far off lands... the thing is, a search engine isn't perfect in that regard either... more importantly, though, a search engine is bound to turn up some kind of reference (whether the virus author intended it or not) for all sorts of possible names so in practice the anti-virus researchers would probably find themselves renaming most viruses anyways... and should it really be the anti-virus company's job to go to the trouble of verifying the suitability of the name provided by the author? is that really the most productive use of their time and your money? i don't think so...
there is a valid complaint, however... sometimes the renaming process gets personal, the renamer chooses a name specifically to piss of the virus author (some have even bragged about doing this)... that is unprofessional and companies should not tolerate that kind of behaviour from their employees - they shouldn't be picking fights with virus writers, they should be doing their best to avoid contributing to any of the virus writers' possible motives for writing viruses...
there is another valid complaint... not all the companies seem to rename a given virus to the same new name, and this certainly does cause confusion... to a certain extent it's understandable - if 2 researches in different companies are trying to decide on a new name for a virus at about the same time (give or take a couple of days) then they're bound to decide on different names... hopefully those names get changed later to be more consistent, and i'd certainly like to see that happen as fast as possible (i'd like to see anti-virus companies making a visible effort to minimize the confusion associated with this sort of thing)... sometimes the names don't get changed at all, though, and for the end user that is simply not acceptable... if you find your anti-virus vendor doing that, vote with wallet, make your feelings heard where they'll feel it the most...
if you don't know already, anti-virus companies generally do not call a virus by the name the virus' author gave it... they rename the virus... that renaming results in something you may have seen before - different companies issuing virus alerts for a particular virus with different names...
there are those that say it makes no sense to do this... they say it's stupid, it pisses off the virus writers and it creates confusion among end users...
however, there are some important points to realize:
- not all viruses are named by their author, so these clearly require naming by the anti-virus vendor...
- not all author supplied names are unique (for a variety of reasons) and so such viruses clearly need to be renamed to avoid confusing them with previous viruses that have the same author supplied name...
- some author supplied names refer to people, places, companies or brands and the anti-virus companies really don't want to be issuing alerts for the george bush virus or the corn flakes virus - it puts them in a difficult legal position...
- some author supplied names have political, religious, or obscene references in them, and that's also something anti-virus companies don't want to put into virus alerts for similar reasons...
so clearly some viruses have to be renamed... but do all of them have to be renamed?
it's been suggested that you could simply use your best judgment to tell if the author supplied name was suitable or not - maybe even use a search engine since obviously a person isn't going to see the significance of many references from far off lands... the thing is, a search engine isn't perfect in that regard either... more importantly, though, a search engine is bound to turn up some kind of reference (whether the virus author intended it or not) for all sorts of possible names so in practice the anti-virus researchers would probably find themselves renaming most viruses anyways... and should it really be the anti-virus company's job to go to the trouble of verifying the suitability of the name provided by the author? is that really the most productive use of their time and your money? i don't think so...
there is a valid complaint, however... sometimes the renaming process gets personal, the renamer chooses a name specifically to piss of the virus author (some have even bragged about doing this)... that is unprofessional and companies should not tolerate that kind of behaviour from their employees - they shouldn't be picking fights with virus writers, they should be doing their best to avoid contributing to any of the virus writers' possible motives for writing viruses...
there is another valid complaint... not all the companies seem to rename a given virus to the same new name, and this certainly does cause confusion... to a certain extent it's understandable - if 2 researches in different companies are trying to decide on a new name for a virus at about the same time (give or take a couple of days) then they're bound to decide on different names... hopefully those names get changed later to be more consistent, and i'd certainly like to see that happen as fast as possible (i'd like to see anti-virus companies making a visible effort to minimize the confusion associated with this sort of thing)... sometimes the names don't get changed at all, though, and for the end user that is simply not acceptable... if you find your anti-virus vendor doing that, vote with wallet, make your feelings heard where they'll feel it the most...
Tags:
anti-virus,
malware naming,
virus
Subscribe to:
Posts (Atom)