Internet consumer advocacy group Stopbadware.org released data on "badware" Web sites on Tuesday, saying that Google was one of the top five networks responsible for hosting these dangerous Web sites.
The numbers show that China is now a top source of malicious Web sites -- China-based networks hosted more than half of the malicious Web sites tracked by the group -- but Google's appearance on the list is perhaps more remarkable. Google is a sponsor of Stopbadware.org, and it is the company that provides the raw data that is analyzed by the group.
A year ago, Google did not appear on Stopbadware.org's list of the top 10 sources of badware, but recently scammers and online criminals have turned to Google's Blogger service to host malicious or spyware-related Web pages, security experts say.
"Because it's free and because it's on a blog and you can post links to whatever you like, people have found ways to take advantage of this and create large numbers of free blogs that have bad links on them and in some cases even bad code," said Maxim Weinstein, manager of Stopbadware.org.
In March, Google was the top badware network tracked by Stopbadware. These latest numbers were compiled at the end of May.
The other four top networks for badware were based in China, led by a China Telecom network with 48,834 infected sites. Google was hosting 4,261 infected sites in May, Stopbadware.org said.
Last year most of the top networks were based in the U.S., but now Stopbadware.org says that U.S. networks account for just 21 percent of infected sites. "The U.S. ... was right on the world average" when one factors in the number of Internet users, Weinstein said.
Networks based in western Europe, in contrast, had far fewer badware sites. ""European hosts are either being targeted less or are doing a better job of security," he said.
Google did not respond to requests for comment on these numbers, but Weinstein said that the company has become very aggressive in cracking down on badware, which Stopbadware defines as spyware, malware or deceptive adware.
Most malicious Blogspot sites are taken down within the day, he said.
Still, Google has its critics.
"The security community has known about Google's problems for at least a year or two now, and unfortunately Google has not responded with anything other than hand waving," said Robert Hansen, CEO of SecTheory.org, a Web security consultancy.
Google could make it harder to host malicious code on Blogspot, but that would cut down on the number of things that its users could do with the site, Hansen explained. "Google allows full unrestricted JavaScript. MySpace.com takes a lot of precautions to not allow that by contrast ... it's much harder to put malicious JavaScript on MySpace than it is Blogspot."
This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.
Download now »Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.
Download now »
The emergence of WLANs has created a new breed of security threats to enterprise networks.
Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation
Effectively address data protection challenges, implementing solutions that help store and protect businesscritical data while cutting costs and improving efficiency and reliability.
Download now »
Sign up to receive Security Resource Alerts
This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.
Download now! »Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.
Download now! »Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.
Download now! »