check out the funds are released. Typically, theseguarantors take 2-3% of the transaction value for their services. The emergence of these servicesshows a developing sophistication in the market,driven by economics more than technology or the demands of organized crime. It also showsthere are participants who value their long-termreputation. These are worrying signs.
Continuous improvement
Another sign of growing sophistication is thecontinuous improvement in the quality of productson sale in the shadow economy. Malware writerswork hard to test their products against anti-virussoftware. They offer guarantees that a given virusor trojan will not be detected using current anti-virus programs. If vendors update their software,then the malware author will supply a new version.Conventional anti-virus programs rely on“signatures” to detect malware. A signature issimilar to a DNA fragment that identi
fi
es the virusand separates it from legitimate data. Anti-virusprograms scan email attachments and other
fi
lesto check that they contain no known signatures.As new malware comes to light, anti-virus vendorsissue signature updates. However, they can only
fi
nd a new signature after a new virus is in the wildand is released on the Internet. Worse, malwareauthors can also download the signatures and testtheir creations against the latest updates. Schipka’sresearch suggests that malware authors canproduce new, unique malware every 45 secondsin order to keep it undetected.This is where the MessageLabs service is sovaluable. As malware developers get moresophisticated, they
fi
nd it easier to stay one stepahead of signature-based detection. MessageLabsuses signatures, but also has a second line of defense: its proprietary Skeptic™ engine. Thisheuristic scanner can detect malware withoutsignatures. Moreover, the bad guys can’t buy it anduse it to test their malware. The only people whohave access to Skeptic are MessageLabs and theonly people who bene
fi
t from it are MessageLabscustomers. Ultimately, says Schipka, “The only thingyou can rely on is very good, well-managed heuristicdetection.”
The free market and the future of online crime
The shadow economy has all the attributes of a traditional economy – division of labor, pricecompetition, marketing and so on – acceleratedto Internet speed and carried out online. AdamSmith, the pioneering political economist, in hisWealth of Nations, foresaw that the division of labor could increase productivity and quality. Similarly,competition drives down prices and tends to driveinnovation. While it is interesting to observe theseclassical economic principles at work, they holda terrible warning: malware is going to get morecommon and more virulent. Companies that relyon the Internet and email, need the best protectionthey can get.
WHITE PAPER: The Online Shadow Economy: A Billion Dollar Market For Malware Authors
There is asophisticated online black market with tensof thousands of participants.Malware authorscan produce new,unique malwareevery 45 secondsin order to keep it undetected.
2
Division of labor in the shadow economy
Leave a Comment