Microsoft fails to credit Kelihos takedown partner
- 30 September, 2011 05:37
- Comments
Microsoft grabbed headlines Wednesday with its report about the successful takedown of the Kelihos botnet, but while the company detailed the achievements of its Digital Crimes Unit, it failed to mention the major role security firm Kaspersky Lab played in the operation.
Microsoft's Kelihos takedown announcement centered on the fact that its specialized team of lawyers succeeded in naming defendants in a botnet-related federal court complaint for the first time -- such cases usually involve unknown parties.
The named defendants were Alexander Piatti and his Czech-based company dotFREE Group SRO, which operated a second-level domain (SLD) registration service in the .cz.cc name space. This service was abused by the botnet's operators to set up hosts for their control infrastructure. A temporary restraining order was obtained by the Digital Crimes Unit in the U.S. District Court for the Eastern District of Virginia, forcing VeriSign to suspend the cz.cc domain.
Microsoft did not disclose any technical details about how Kelihos was hijacked from its original operators because Kaspersky Lab handled that part of the operation. The security company's experts explained Thursday in a lengthy blog post how they took control of the botnet, but they probably didn't appreciate being left out of the story in the first place.
"Hey @msftmmpc [Microsoft Malware Protection Center] why didn't u mention all truth about Hlux/Kelihos botnet taking down?" Dmitry Bestuzhev, head of Kaspersky Lab's global research and analysis team for Latin America, wrote on Twitter.
"Kaspersky Lab played a critical role in this botnet takedown initiative, leading the way to reverse-engineer the bot malware, crack the communication protocol and develop tools to attack the peer-to-peer infrastructure," said Tillmann Werner, a senior virus analyst with Kaspersky in Germany. "We worked closely with Microsoft's Digital Crimes Unit (DCU), sharing the relevant information and providing them with access to our live botnet tracking system," he added.
Even the antivirus vendor's co-founder and CEO, Eugene Kaspersky, linked to his company's blog post with the message: "The flipside of the Microsoft's takedown of Kelihos (Hlux) botnet."
Kaspersky Lab currently operates the only server where computers infected with this malware connect to, which effectively puts it in control of the botnet. The company has the resources to keep this so-called sinkhole operational for a long time, but the end goal is to reduce Kelihos' size as much as possible.
Sending commands to clean the infected systems remotely would be illegal in most countries, so this won't be an easy task. Microsoft has added detection for the Kelihos malware family to its Malicious Software Removal Tool (MSRT), which is distributed to computers worldwide via Windows Update, but the effects have yet to show.
The software giant claims that not crediting Kaspersky Lab in its original announcement was the result of poor communication between the two companies. "Due to an unfortunate miscommunication between Microsoft and Kaspersky prior to the announcement, Microsoft was operating under the belief that it was Kaspersky's desire to not be proactively mentioned in the announcement --- as some partners commonly request and which we understand and respect given the sensitivity of these situations," said Richard Boscovich, a senior attorney with the Microsoft Digital Crimes Unit.
"However, we were very glad to see Kaspersky subsequently come forward with their role in the operation, because we very much want to give them the credit they deserve. Their research and unique, in-depth insight into the botnet was invaluable in this case and we are grateful for their support and determination to make the Internet safer for everyone," he added.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- The Big Six: The CIO Executive Council’s Frameworks for IT Value and Leadership
- Process-Driven Master Data Management for Dummies
- Top Reasons to Implement an SOA Governance Strategy: A List for IT Executives
- The Pathways ICT Leadership Development Program Brochure and Curriculum 2012
- 3PAR Storage: Tailor-Made for Virtual Infrastructures
-
Apple aims iPads at High Schools
-
Face Time - Interview with John Brennan and Robert DiStefano
-
Google Jumps Into Social Bookmarks Game
-
NBN build gaining momentum daily: Quigley
-
Face Time - Interview with John Brennan and Robert DiStefano
-
EMC 15-Minute Guide to Smarter Backup Transform your future
Backup and recovery has become fundamental part of business and an essential element of information management. Information is useless to customers, employees, or business partners can't access it when it is needed. Availability and integrity of information, of the lack of, can directly impact revenues and profits - as well as company reputations. Read more. -
Stopping Fake Antivirus: How to Keep Scareware off Your Network
This paper provides insight into where fake antivirus comes from and how it is distributed, what happens when a system is infected with fake antivirus, and how to stop this persistent threat from infecting your network and your users. -
Oracle x86 Rack Servers Optimized for Rapid Deployments and Operational Efficiency
Business-critical and mission-critical workloads demanding applications and databases require stable and secure environments. When these types of workloads are deployed on x86 servers, the need to ensure business continuity, maximum uptime, and consistent processing means that IT managers and business unit managers are looking at enterprise x86 servers in a new way: They realize that the business depends on these servers and that x86 server platforms for the enterprise are no longer expendable, as they might have been when servers were dedicated to a single application or when they were deployed as small Web servers that could be easily taken offline and replaced.
-
Cryptography for Internet and Database Applications
-
The Internet for Dummies 4E Australian Edition
-
Implementing and Administering Security in a Microsoft Windows Server 2003 Network (70-299)
-
Photoshop Cs4 After the Shoot
-
Mastering the SAP Business Information Warehouse, Second Edition
-
Professional SQL Server 2005 Clr Programming with Stored Procedures, Functions, Triggers, Aggregates, and Types
-
Information Technology
-
Microsoft Office Project 2007 for Dummies
-
Introduction to Information Systems








Comments
Post new comment