On mySimon: Sonic Scrubber Household Cleaning Tool
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Nov 4, 2003 11:04:00 PM

Microsoft will work with law enforcement to track down writers of worms, viruses and other malicious code, and is ponying up $5 million to fund the search.

As first reported by CNET News.com, the initiative's first two bounties--to the tune of $250,000 each--will be for information leading to the arrest and conviction of the people responsible for releasing the MSBlast worm and Sobig virus, both of which wreaked havoc online over the summer.

News.context

What's new:
Microsoft sets aside $5 million to fund the search for those who released the MSBlast worm and the Sobig virus.

Bottom line:
The initiative marks the latest move by Microsoft and law enforcement to curtail attacks that plague the Internet.

Track the players

Microsoft executives were joined by representatives from the FBI, the Secret Service and Interpol at a press conference Wednesday that announced the new fund.

"These are not just Internet crimes, cybercrimes or virtual crimes. These are real crimes that disrupt the lives of real people," Brad Smith, general counsel at Microsoft, said in a press conference.

The rewards will be open to residents of any country, subject to that country's laws, Microsoft said. People with information can report it to law enforcement online to Interpol, to the Internet Fraud Complaint Center or to FBI, Secret Service or Interpol field offices.

Dubbed the Anti-Virus Reward Program, the initiative marks the latest move by Microsoft and law enforcement to put a stop to the repeated waves of attacks that have hit the Internet in the past decade. The two rewards posted on Wednesday could also jump-start federal law enforcement's seeming stalled investigation into the attacks that infected hundreds of thousands of computers in August and September.

The U.S. Department of Justice, the FBI and Microsoft had earlier announced the arrests of two men who are suspected of modifying and releasing minor variations of the MSBlast worm, but have made little progress in catching the original author or the person or group responsible for the Sobig virus. Those attacks were serious enough to hurt Microsoft's bottom line and help security companies post more profits.

Click here to Play

Top security experts take ZDNet's Digital Defense Test 2003.

MSBlast, also known as Blaster and Lovsan, spread to as many as 1.2 million computers, according to data from security company Symantec. The worm compromised computers by using a serious vulnerability in Windows systems for which Microsoft had released a patch a month earlier. A variant of the worm, MSBlast.D, was intended to protect machines against the original program, but it ended up being so aggressive that the avalanche of data it produced shut down networks.

The Sobig.F virus spread through e-mail on Aug. 19, compromising users' computers with software designed to turn the systems into tools for junk e-mailers.

Calling all bounty hunters?
The rewards may motivate security researchers into becoming amateur bounty hunters, but real leads are likely to come from those close to the actual miscreants involved, Peter Nevitt, director of information systems for Interpol, said in a CNET News.com interview.

"It is less likely that we will have bounty hunters and more likely that we will have people that will break ranks within those in the know," he said.

Keith Lourdeau, acting deputy assistant director for the FBI's Cyber Division, said that while rewards have been used in the past to garner information, there's no quantitative measure of how successful the tactic is.

Audiocast
arrow Foundstone's CTO: Offering
reward for
virus writers could
be beneficial
play audio

"In the cases that I know of, including bank robberies and major theft cases, offering a reward has generated a lot of information," he said. Sifting through the massive amounts of information will be the job of law enforcement.

The decision to offer rewards for only the two latest threats doesn't preclude additional bounties to be made for other Internet attacks, such as the MSBlast.D worm, also known as Nachi and Welchia.

"We wanted to earmark $5 million so there would be ample resources for the near future," said Microsoft's Smith, who said that tapping into the fund will be done case by case. "We need to make decisions (about rewards) on a variety of criteria. The severity of the virus is one criteria; another is timeliness."

Smith said he hopes that Microsoft's move will put worm and virus writers on notice.

"These people are the saboteurs of cyberspace sitting behind their computer screens," he said. "This is a broad problem and we need to act, not only with determination, but with a long-term resolve."

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 46 Talkback(s)
RE: Microsoft to offer bounty on hackers
Looks like the computer security group (and believe me I laugh when I say this - Microsoft, releasing Live Onecare for protection) needs help. Isn't it about time the suited industry with their colleg... (Read the rest)
Posted by: OgreMHDW Posted on: 02/14/09 You are currently: a Guest | | Terms of Use
Makes Sense  ndelc | 11/04/03
Well...  Yen_z | 11/04/03
i agree  stephen732@... | 11/04/03
So...  vdraken | 11/05/03
Reality Check  Quiller | 11/05/03
Robin Hood???  JimSatterfieldW | 11/05/03
ROBIN HOOD???  beepster | 11/05/03
Makes not sense, just makes it more exciting for virus writers  DonnieBoy | 11/04/03
The Myth of Code Security at MS  AbsolutelyNot | 11/05/03
Medieval  Harry Bardal | 11/04/03
Medieval?  stephen732@... | 11/04/03
Will the criminal trial be televised?  David Mohring | 11/04/03
WILL THE CRIMINAL TRIAL BE TELEVISED?  beepster | 11/05/03
Don't fix it - buy silence  madmanx | 11/04/03
The Real reason  eyadmask | 11/04/03
Irrelevancies  Octol | 11/04/03
wish I knew  lmaxwell | 11/04/03
$250,000 is cheap  Iain_Peters | 11/05/03
A better idea  jellyclock | 11/05/03
An even Better idea!  Octol | 11/05/03
Why not address the issues Octol?  jellyclock | 11/05/03
What issues?  JimSatterfieldW | 11/05/03
Truth hurts, doesn't it?  Jack-Booted EULA | 11/05/03
MS Creates MicroCop The Bounty Hunter  DragonBRockin | 11/05/03
Clueless as to real problem  Quiller | 11/05/03
Re: Clueless as to real problem  DragonBRockin | 11/05/03
Greed Wins  Quiller | 11/05/03
Quiller YOUR AN IDIOT!!!  DragonBRockin | 11/05/03
To simple minds there's only 1 solution  JMVella | 11/05/03
Correct  JimSatterfieldW | 11/05/03
free copies of windows instead of cash  blahblahblah | 11/05/03
Hunt and Kill  Quiller | 11/05/03
Terminator HK 900  Quiller | 11/05/03
Hmm... If only the protocols were tested in Open Source  hackman_z | 11/05/03
New Profession  dwest_z | 11/05/03
They forgot to mention one thing !  NT Admin | 11/05/03
Hey MS offer $250,000 bonuses to your staff  Tammee | 11/05/03
Total costs  voska | 11/05/03
My thoughts exactly...  Yen_z | 11/05/03
Based on the Ex-Microserfs I know  AbsolutelyNot | 11/05/03
Well its about time!  Mad Scientist | 11/05/03
Dirty money from a dirty company!  orlando@... | 11/05/03
Bollogni No 2  michael-t | 11/05/03
Reward to Break the System  michael-t | 11/05/03
Lets hope what MS has done does not lead to more nasty programs.  shakey_z | 11/06/03
RE: Microsoft to offer bounty on hackers  OgreMHDW | 02/14/09

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here