Quantcast
Last updated on May 31, 2012 at 17:56 EDT

Is China Leaving the Internets Back Door Open?

June 24, 2008
Repost This

To: TECHNOLOGY EDITORS

Contact: Katie Hallen of 463 Communications, +1-202-463-0013 x213, for StopBadware.org

Chinese Networks Are Hosting Majority of the Internets Malware Sites, StopBadware.org Report Finds

CAMBRIDGE, Mass., June 24 /PRNewswire-USNewswire/ — The majority of the Internets malware-infected websites are located on Chinese networks, finds a new report released today by StopBadware.org, the university-based research initiative aimed at protecting users from dangerous software. The report also identifies the 10 network blocks that contain the largest number of badware sites. Six of the 10 are located in China.

(Photo: http://www.newscom.com/cgi-bin/prnh/20080624/DC25925)

Sites that infect visiting PCs represent some of the worst of digital pollution, said Jonathan Zittrain, StopBadware.org co- director and Professor of Law at Harvard Law School. Malware is a global problem that requires cooperation across industries and across national borders.

As China strives to hone its image in preparation for the Beijing Olympics, 52 percent of the more than 200,000 infected sites StopBadware.org analyzed in late May were hosted by Chinese networks. U.S.-based networks accounted for 21 percent of bad sites. The data were provided by Google’s Safe Browsing team and are searchable by URL in the StopBadware.org Badware Website Clearinghouse.

The analysis also revealed the Internets 10 most infected network blocks:

Network block name & Country Number of infected sites

description

CHINANET-BACKBONE

No.31, Jin-rong Street China 48,834

CHINA169-BACKBONE CNCGROUP

China169 Backbone China 17,713

CHINANET-SH-AP China

Telecom (Group) China 9,445

CNCNET-CN China Netcom

Corp. China 6,058

GOOGLE – Google Inc. U.S. 4,261

DXTNET Beijing

Dian-Xin-Tong Network

Technologies Co., Ltd. China 3,604

SOFTLAYER – SoftLayer

Technologies Inc. U.S. 3,507

THEPLANET-AS –

ThePlanet.com Internet

Services, Inc. U.S. 3,166

INETWORK-AS IEUROP AS France 2,878

CHINANET-IDC-BJ-AP IDC,

China Telecommunications

Corporation China 2,357

The owners of these network blocks play a variety of roles in the Internet ecosystem. Some directly control the infected servers on their networks, while others lease equipment and/or bandwidth to customers who control their own servers. Google, which is a sponsor of StopBadware.org, hosts free blogs on its network through its popular Blogger service. Malicious users sometimes exploit these free blogs as a means to link to or distribute malware. Google disables the blogs as soon as they detect the bad content, but the dead blogs remain in the list of infected sites until Googles automated malware detection system has an opportunity to rescan them.

Maxim Weinstein, manager of StopBadware.org, says the country and network data are a helpful step in understanding the distribution of malware, but we should be careful about assigning blame.

Our goal in releasing this report is not to point fingers or to imply that network owners or governments are at fault for the malware on their networks, but rather to start a conversation. When different links in the Internet chain talk to each other and share information, it leads to solutions that in turn lead to a safer Internet for all of us.

He points, for example, to his teams success last year, when a similar StopBadware.org report revealed U.S.-based web hosting company iPowerWeb as home to over ten thousand infected sites, making it the most infected network at the time.

When we published that report, says Weinstein, it prompted iPowerWeb to ask for help. With support from StopBadware.org and data from Google, the company was able to clean up all those sites and secure its servers against future attacks. Weinstein notes that, based on the latest data, iPowerWeb is hosting so few infected sites that it is not even in the top 250 most infected networks.

On Friday, StopBadware.org researchers will present related research at the Workshop on the Economics of Information Security, hosted by the Tuck School of Business at Dartmouth College.

To read a full copy of the StopBadware.org report, go to: http:// dev.stopbadware.org/pdfs/ StopBadware_Infected_Sites_Report_062408.pdf

About StopBadware.org

StopBadware.org is a partnership among academic institutions, technology industry leaders, and volunteers committed to protecting Internet users from threats to their privacy and security caused by bad software. StopBadware.org is led by Harvard University’s Berkman Center for Internet & Society and Oxford Universitys Oxford Internet Institute. Consumer Reports WebWatch serves as an unpaid special advisor. The initiative is supported by Google, PayPal, Lenovo, AOL, Trend Micro, and VeriSign. For more information, please visit http:/ /www.stopbadware.org.

SOURCE StopBadware.org

(c) 2008 U.S. Newswire. Provided by ProQuest Information and Learning. All rights Reserved.