Longtime computer security rivals are joining forces to battle increasingly sophisticated online attacks by cyber criminals.
“The attacks are getting more complex, and if we want to get ahead of attackers the call is to work together in a community approach,” Microsoft Security Response Center director Mike Reavey said.
“One of the things becoming clear is that customers want vendors to work together, and they want information and protection out faster,” he said.
Microsoft used a premier Black Hat security conference taking place this week in Las Vegas as a stage to unveil enhancements to the software giant’s computer defense collaboration efforts.
NEW TOOL
Microsoft released a new tool designed to make it easier for software security firms to model hacker threats and craft defenses.
The Redmond, Washington-based technology firm also unveiled a guidebook to demystify the realm of software security updates and vulnerability patches.
“There is a sea of information out there and we want to help customers navigate those waters,” Reavey said. “The guide walks them through what we do.”
A Microsoft Active Protections Program launched at Black Hat last year has grown to 47 members that share information to minimize time hackers have to craft and launch attacks on newly discovered software weaknesses, Reavey said.
“By working together, the security vendors get free vulnerability information, Microsoft knows their products will be protected from widespread exploitation when the disclosure goes out, and customers win by remaining protected,” TippingPoint security researcher Jason Avery said in a release.
“Everyone wins,” he said.
Microsoft provides computer security allies with an “exploitability index” that gauges the likelihood hackers will target various vulnerabilities to help security companies prioritize responses.
Microsoft also shares lessons learned while analyzing software for flaws.
“What we are seeing is they are working well with us and we are working well together,” Reavey said of allies in the software security world.
VIRUS
Security industry teamwork was crucial in countering a Conficker virus that plagued the Internet early this year.
Microsoft rallied a task force to stamp out Conficker, also referred to as DownAdUp, and the software colossus has placed a bounty of US$250,000 on the heads of those responsible for the threat.
The worm, a self-replicating program, takes advantage of networks or computers that haven’t kept up to date with security patches for Windows.
It can infect machines from the Internet or by hiding on USB memory sticks carrying data from one computer to another.
Conficker could be triggered to steal data or turn control of infected computers over to hackers amassing “zombie” machines into “botnet” armies.
Tools to remove Conficker virus and prevent its spread have been released, but computers without properly updated software could still be vulnerable.
A Chinese freighter that allegedly snapped an undersea cable linking Taiwan proper to Penghu County is suspected of being owned by a Chinese state-run company and had docked at the ports of Kaohsiung and Keelung for three months using different names. On Tuesday last week, the Togo-flagged freighter Hong Tai 58 (宏泰58號) and its Chinese crew were detained after the Taipei-Penghu No. 3 submarine cable was severed. When the Coast Guard Administration (CGA) first attempted to detain the ship on grounds of possible sabotage, its crew said the ship’s name was Hong Tai 168, although the Automatic Identification System (AIS)
An Akizuki-class destroyer last month made the first-ever solo transit of a Japan Maritime Self-Defense Force ship through the Taiwan Strait, Japanese government officials with knowledge of the matter said yesterday. The JS Akizuki carried out a north-to-south transit through the Taiwan Strait on Feb. 5 as it sailed to the South China Sea to participate in a joint exercise with US, Australian and Philippine forces that day. The Japanese destroyer JS Sazanami in September last year made the Japan Maritime Self-Defense Force’s first-ever transit through the Taiwan Strait, but it was joined by vessels from New Zealand and Australia,
CHANGE OF MIND: The Chinese crew at first showed a willingness to cooperate, but later regretted that when the ship arrived at the port and refused to enter Togolese Republic-registered Chinese freighter Hong Tai (宏泰號) and its crew have been detained on suspicion of deliberately damaging a submarine cable connecting Taiwan proper and Penghu County, the Coast Guard Administration said in a statement yesterday. The case would be subject to a “national security-level investigation” by the Tainan District Prosecutors’ Office, it added. The administration said that it had been monitoring the ship since 7:10pm on Saturday when it appeared to be loitering in waters about 6 nautical miles (11km) northwest of Tainan’s Chiang Chun Fishing Port, adding that the ship’s location was about 0.5 nautical miles north of the No.
SECURITY: The purpose for giving Hong Kong and Macau residents more lenient paths to permanent residency no longer applies due to China’s policies, a source said The government is considering removing an optional path to citizenship for residents from Hong Kong and Macau, and lengthening the terms for permanent residence eligibility, a source said yesterday. In a bid to prevent the Chinese Communist Party (CCP) from infiltrating Taiwan through immigration from Hong Kong and Macau, the government could amend immigration laws for residents of the territories who currently receive preferential treatment, an official familiar with the matter speaking on condition of anonymity said. The move was part of “national security-related legislative reform,” they added. Under the amendments, arrivals from the Chinese territories would have to reside in Taiwan for