July 30, 2008 12:39 PM PDT

Most drive-by malware comes from China, Google says

SAN JOSE, Calif.--A analysis by Google of Web sites that have malware found most of the malicious drive-by activity is due to computers in China, an engineer for the search giant said at the Usenix security conference on Wednesday.

About 67 percent of all the sites that secretly drop malicious software onto visitors' computers are located in China, as are 64 percent of the compromised servers, said senior staff engineer Niels Provos during a presentation here at the event.

"Web based malware is a significant problem and...there is no real good proactive defense against this," Provos said.

Between January and October 2007, Google's malware analysis of 66 million unique URLs found 3.5 million had malware, he said. There was a 90 percent detection rate and the false positive rate was 0.1 percent, according to Provos.

The analysis is part of Google's efforts to steer Web surfers clear of sites with malicious software that can install malware on their computers and turn them into zombies on a botnet, which is a growing problem on the Internet.

The company is using its Web site crawling system that feeds up search results when someone "googles" something to analyze the sites that come up.

Google is creating a list of sites that may be harmful to users and putting a warning next to those sites when they appear in Web search results, Provos said. The company began doing this about two years ago.

Twelve percent of the malware infections were due to ads, based on search traffic, he said.

"We're trying to prevent people from going to places where there is bad content, but at the moment there is nothing I can tell my mother that 'this is what you can do to be safe,'" he said.

Recent posts from News - Security
Brazilian charged in U.S. in connection with operating botnet
Psychological profiling on the Web
Security expert: DNS attacks are happening
Malicious Flash ads attack, spread via clipboard
Hacker exposes alleged Olympics age fraud
Add a Comment (Log in or register) 4 comments (Page 1 of 1)
by Tui Pohutukawa July 30, 2008 1:44 PM PDT
"At the moment there is nothing I can tell my mother that 'this is what you can do to be safe".

Oh no, there is. Tell her to get a Mac, and she will be safe. Let me say to the MSFT trolls that will undoubtedly show up here any minute: If you don't believe me, you've obviously never used a Mac.
Reply to this comment View reply
by fredtheviking July 30, 2008 2:32 PM PDT
Mac are not likely more secure than Vista. Macs don't have as many threats, because there aren't many Macs out there and are not worth the effort.
Reply to this comment
by radiocam July 30, 2008 11:39 PM PDT
so does anyone know how i can keep web sites in china out of my google search results by default? there must be a way. as also to keep away from all servers located in china?
i don't like getting into the self-censorship game, but i'm weary of battle....
Reply to this comment
Powered by Jive Software
advertisement
  • About News - Security

  • Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader
Google
Yahoo
MSN

Most popular stories

  1. Google's search secret: It gets rid of you

  2. Developer creates copy-paste tech for iPhone

  3. Will Wright on the origins of 'Spore'

  4. Palm Treo Pro: Not digging it

  5. American Airlines launches in-flight Wi-Fi

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

advertisement
On MovieTome: TRANSFORMERS 2 SPOILERS!
Advanced
search
Advanced
search
Visit other CBS Interactive sites