Standardised malware naming for the new year

Posted by   Virus Bulletin on   Nov 25, 2004

An end to the virus-naming problem?

A new initiative that aims to standardise malware naming may be in operation as early as January 2005.

The US Department of Homeland Security's Computer Emergency Readiness Team, US-CERT, is set to coordinate a Common Malware Enumeration initiative among anti-virus vendors, according to a letter sent to The SANS Institute and signed by representatives of the DHS, Symantec, Microsoft, McAfee, and Trend Micro. Rather like Mitre Corp's Common Vulnerabilities and Exposures (CVE) list, US-CERT will maintain and coordinate a database of malware identifiers.

The letter stated: 'By building upon the success of CVE and applying the lessons learned, US-CERT, along with industry participants... hopes to address many of the challenges that the anti-malware community currently faces.' With such an enormous task ahead, the enumeration project will make a start with just the 'major' threats.

The letter acknowledged that the task would not be a straightforward one, saying, 'There are significant obstacles to effective malware enumeration, including the large volume of malware and the fact that deconfliction [sic] can be difficult and time-consuming.'

Further details of the scheme were not available, but a pilot is planned for January 2005.

VB doubts whether the anti-virus industry's most contentious issue will be laid to rest without a hefty struggle, but awaits the introduction of the scheme with interest.

Read some views on the thorny issue of virus-naming:

- What's in a name? (Nick FitzGerald, June 1998)

- What's in a name? (Jakub Kaminski, Nov 2001)

- A virus by any other name - virus naming updated (Nick FitzGerald, Jan 2003)

- That which we call Rose.A (Sarah Gordon, March 2003)

- Hunting the UNICORN (Andrew Lee, May 2004)

- VGrep

Posted on 25 November 2004 by Virus Bulletin

 Tags

twitter.png
fb.png
linkedin.png
hackernews.png
reddit.png

 

Latest posts:

VBSpam tests to be executed under the AMTSO framework

VB is excited to announce that, starting from the Q3 test, all VBSpam tests of email security products will be executed under the AMTSO framework.

In memoriam: Prof. Ross Anderson

We were very sorry to learn of the passing of Professor Ross Anderson a few days ago.

In memoriam: Dr Alan Solomon

We were very sorry to learn of the passing of industry pioneer Dr Alan Solomon earlier this week.

New paper: Nexus Android banking botnet – compromising C&C panels and dissecting mobile AppInjects

In a new paper, researchers Aditya K Sood and Rohit Bansal provide details of a security vulnerability in the Nexus Android botnet C&C panel that was exploited in order to gather threat intelligence, and present a model of mobile AppInjects.

New paper: Collector-stealer: a Russian origin credential and information extractor

In a new paper, F5 researchers Aditya K Sood and Rohit Chaturvedi present a 360 analysis of Collector-stealer, a Russian-origin credential and information extractor.

We have placed cookies on your device in order to improve the functionality of this site, as outlined in our cookies policy. However, you may delete and block all cookies from this site and your use of the site will be unaffected. By continuing to browse this site, you are agreeing to Virus Bulletin's use of data as outlined in our privacy policy.