Notes
Slide Show
Outline
1
Spyware
  • Benjamin Edelman
  • February 2006
2
Agenda
  • Spyware –


  • What it is
  • Where it comes from
  • How to keep it out
  • Where it’s going
3
Why Care What’s On Your Network?
  • Reliability
  • Performance
  • Productivity
  • Security
4
Installation Methods
  • Security holes
  • Bundles
  • Drive-by downloads (ActiveX)
  • On request
5
Installation Methods
  • Security holes
  • Bundles
  • Drive-by downloads (ActiveX)
  • On request
6
Security Hole Exploit - Apr. 2005 - 1/6
7
Security Hole Exploit - Apr. 2005 - 2/6
1 minute after exploit
8
Security Hole Exploit - Apr. 2005 - 3/6
3 minutes after exploit
9
Security Hole Exploit - Apr. 2005 - 4/6
4 minutes after exploit
10
Security Hole Exploit - Apr. 2005 - 5/6
7 minutes after exploit
11
Security Hole Exploit - Apr. 2005 - 6/6
8 minutes after exploit
12
Installation Methods
  • Security holes
  • Bundles
  • Drive-by downloads (ActiveX)
  • On request
13
Grokster - Oct. 2004 - 1/6
14
Grokster - Oct. 2004 - 2/6
15
Grokster - Oct. 2004 - 3/6
16
Grokster - Oct. 2004 - 4/6
17
Grokster - Oct. 2004 - 5/6
18
Grokster - Oct. 2004 - 6/6
19
Installation Methods
  • Security holes
  • Bundles
  • Drive-by downloads (ActiveX)
  • On request
20
Pacerd @ Iowrestling - Apr. 2005 - 1/3
21
Pacerd @ Iowrestling - Apr. 2005 - 2/3
22
Pacerd @ Iowrestling - Apr. 2005 - 3/3
maximizing license and scrolling to page three
23
Installation Methods
  • Security holes
  • Bundles
  • Drive-by downloads (ActiveX)
  • On request
24
Claria @ Ezone - Apr. 2005 - 1/3
25
Claria @ Ezone - Apr. 2005 - 2/3
26
Claria @ Ezone - Apr. 2005 - 3/3
27
Distribution methods
  • Pay-per-install
    • Effects
  • Affiliate relationships
28
Distribution methods
29
Distribution methods
30
Advertisers
  • American
      Express
  • Citibank
  • Expedia
  • JP Morgan
      Chase
  • Netflix
  • Orbitz
  • Priceline
  • Sprint PCS
  • Travelocity
  • Vonage
  •        … many more
31
180solutions Showing Google AdSense Ads
32
180solutions Serving
Google AdWords Ads
33
Columbia House Promoted By
Icannnews / MyGeek / Azoogle / Yfdmedia / aQuantive Atlas
34
Understanding the Chain of Redirects
35
Columbia House Promoted by Lengthy Chain
36
Responses to Spyware
  • Remedial removal (Ad-Aware and kin)
  • Client-side blocking (MS Anti-Spyware)
  • Lock down local PCs.  Deny users Local Administrator rights.
  • Lock down network.  Deny users access to bogus sites.
  •    à Combination of the above ??
37
Can You Trust Your Anti-Spyware Vendor?
  • Hard task.  Imperfect detection / removal even when make best effort.
  • Threats, cease & desist letters, business partnerships with spyware/adware providers.
38
Why spyware has been hard to stop
  • Profit motive
  • Naïve users
  • “Consent”
  • Complexity befuddles regulators
  • Long chains of relationships
39
Spyware Less Hopeless Than Spam?
  • Less spyware is offshore?
  • Easier to track installation paths?
  • Clear business motive, easy to see and track advertisers?
  • No intermediary SMTP servers, no “hot potato” duties.
  • Less risk of false positives / blocking legitimate communications?


40
Spyware
  • Benjamin Edelman
  • www.benedelman.org