significant chunk all Internet connected computers. As a whole, the set of malwareinfected computers have the ability to collect all of the client data of hundreds of millions of computers, though in practice data collected is usually limited to obviously
profitable data like credit card numbers. 33 Most of these infected computers are organized into large botnets—networks of infected computers remotely controlled by a single entity. The Conficker botnet, one of the biggest currently, now controls several
million infected computers. 34 Botnets like Conficker perform a variety of illicit activities including sending spam, committing click fraud, subjecting servers to denial of
service attacks, and stealing financial information. One recent study of spam distribution determined that the Storm botnet was responsible for twenty percent of all spam
sent in the first quarter of 2008, and Storm was just the biggest of many botnets at the
time. 35
The direct impact of most of these activities on any given infected user is usually relatively small: outgoing spam only costs the user bandwidth, credit card theft is generally insured by the credit card company, and click fraud costs a user nothing directly.
But the potential for greater abuse of personal data, both individually and collectively,
is difficult to overstate given the vast number of malware-infected computers, the complete access of the malware to the infected computers’ data, and the increasing sophistication of the criminal organizations that run them. 36 A recent report by two of this
volume’s co-editors, Ron Deibert and Rafal Rohozinski, and their respective teams, on
the use of a small botnet to surveil a wide variety of embassies and other highly sensitive sites in southeast Asia, demonstrates the potential for harm represented by the
botnet surveillance. The Information Warfare Monitor found clear evidence that
the botnet, which they call GhostNet, had wide ranging abilities on the client: from
copying locally stored files to watching the physical spaces through the webcams. 37
The study presented only circumstantial evidence pointing to Chinese involvement—
the servers commanding the botnet were mostly located in China, and the infected
sites were all of high, regional value to China. But the documentation of this particular
botnet demonstrates that it would be straightforward for China or another state (or private) actor to perform wide-scale client-side surveillance through a botnet.
To protect oneself from viruses, bots, worms, and other such malware, most experts
recommend installing anti-virus systems on all client computers. But this anti-virus
software is itself highly intrusive, operating at the most fundamental levels of the operating system, incurring significant performance penalties, and attempting to avoid the
notice of malware (which is itself trying to detect the anti-virus systems to disable
them). Anti-virus tools have the capability to do the same sorts of harm that a piece
of malware can do, including both stealing data from and disabling the host computer.
Trust in Symantec and the other anti-virus vendors not to snoop or harm the computer
is mostly well founded, but fake anti-virus systems have now become one of the most
common types of malware precisely because of the need to trust anti-virus systems and
the difficulty of determining which anti-virus systems to trust.
46
Hal Roberts and John Palfrey
Précédent

- 63/635

Suivant