The (correct) detection of light grey software

Roel Schouwenberg Kaspersky Lab

As brought up in my article in Virus Bulletin (see VB, October 2005, p.6), a new type of 'malicious' software is on the rise which can be considered as 'light grey'.

Since then some of these programs have made the news, with the introduction of the WMF exploit by people wanting to promote their light grey software being the main headliner. Several security vendors have dubbed these programs as adware or spyware, but is this classification actually correct? There is more than meets the eye.

As ICT is evolving we are seeing an increase in requests to detect 'regular' programs, such as Skype for instance, which is known to be almost impossible to block on the network level. What kind of implications does this have? Which way should the AV industry move in order to protect not only its customers but also itself from a legal point of view?

This paper presents a view on these questions, along with some proposed answers.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

Virus Bulletin

In this month's magazine:
  • Social networking meets social engineering
  • Flying solo
  • Geneva convention
  • 7th German Anti Spam Summit 2009
  • Anti-phishing landing page: turning a 404 into a teachable moment
  • An update on spamming botnets: are we losing the war?
  • Windows Server 2008 Standard Edition SP2 x86
Virus Bulletin 10 2009
Subscribe now!
Virus Bulletin currently has 190,364 registered users.