July 18, 2006

Researcher posts Google-based malware

'Malware Search' tool uses engine to find knows viruses and worms

A well-known security researcher has released code that can be used to mine Google Inc.'s database for malicious software.

The tool is similar to one developed by Web filtering vendor Websense Inc. last week, but which was not released to the general public. Websense said that making this software public could lead to its being misused by attackers.

Using a database of digital fingerprints of known malware -- called "signatures" -- the Malware Search tool uses the popular search engine to find a number of known worms and viruses. It was developed by HD Moore, the researcher best known as the developer of the widely used Metasploit hacking tool. Moore's tool was posted early Monday.  

Though Google is widely used to search the Internet for Web pages and office documents, the search engine also can peek through the binary information stored in the normally unreadable executable (.exe) files that are run by Windows computers. Google won't say when it added this feature, but it has gained the attention of security researchers over the past three months.

Moore built his tool to help shed some light on how much malware was actually being indexed by Google, he said. His findings: not much.

When the security researcher examined a sample of about 4G bytes of executable code, he found that very few of the programs were malicious. "You can search for malware, but it's not a big risk," he said.

Of the approximately 2,400 samples he examined, 125 contained malware. More than 90 of these popped up as part of malicious e-mail messages stored in online e-mail archives. The rest of the samples came from Web sites that were actively distributing malware.

So any attacker that might be looking to find new sources of malware using Moore's tool will probably be disappointed.

"Attackers have much better sources of malware and the items in the Google index are not recent or useful," he said. "If anything, the Google index is a great tool for determining who distributes malware -- the actual malware in question is not that interesting."

Though some have speculated that Google's ability to search through executable files might allow it to create its own shareware and freeware search service, Moore said that Google has not yet indexed enough files for this to be useful.

Three months ago, Google had indexed about 30,000 executable files. That number has now risen to about 112,000 samples, he said.

"Considering that they're Google, you'd expect better results," Moore said. "If they could grow their index of executables to some sort of useful amount, then this would be really useful," he said.

However, without some way of weeding out malicious software, this kind of service could be misused by attackers to trick users into downloading worms or viruses masquerading as legitimate downloads, Moore said.

Google declined to comment for this article except to say that it is aware that users can find malicious executables via its search engine, and is making an effort to shield users from this code.



 

Close

On Twitter now

Security

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Security Resource Alerts

Subscribe to the Security Central Newsletter

Stay informed of the latest security threats and fixes.

White paper

Log Management: How to Develop the Right Strategy for Business and Compliance

This white paper provides guidance on how to develop a strategic approach to managing and monitoring logs, a key function required for compliance with many regulatory mandates and a critical defense against security threats.

Download now! »

White paper

The Essential Series: Security Information Management

Learn about the processes and technologies that support security information management (SIM) operations, as well as the business case for SIM. The series examines different options for implementing SIM and gives you evaluation criteria for selecting the best option for your organization.

Download now! »

White paper

Aberdeen: Choosing and Consuming Managed Security Services

Learn the strategies, actions, and capabilities that Best-in-Class organizations employ and technologies they choose to obtain superior performance against various security performance metrics. This report provides guidelines for identifying which security solutions to consume as a MSS and defines best practices for choosing and managing MSSPs.

Download now! »
©1994-2009 Infoworld, Inc.