If the rumors are true, Microsoft is stepping up considerably to join the fight against cyber crime. Allegedly, Microsoft is developing a real-time feed that records current cyber threats and gives necessary steps to safeguard against them.
Microsoft has already had success in taking down botnets. By doing this, the company collects plenty of useful data about the threats that these botnets pose. The procedure works like this: Microsoft basically swallows the botnets. This, in turn, sends botnet-infected hosts to addresses which are under Microsoft’s control. This captures the contaminated hosts and takes them offline.
Previously these details had not been shared, but now this info can be given to the government and private organizations, CERTs, & ISPs. Whilst the amount of attacks will not likely decrease thanks to this real-time feed, the impact of a feed like this will be amazing. The amount of damage from a cyber attack will probably be greatly lessened because IT security professionals will be able to more rapidly respond to a threat.
Even more importantly than a reduction in damage, a live threat feed could mean that the IT security industry overall will start to share more information. It’s been a long-standing belief that sharing confirmed threat data could lead to copycat attacks. However, this isn’t a valid concern. Cyber criminals have already been sharing tips and tricks and ways to get around security systems. It only makes sense for the IT security industry to be sharing their expertise in how to fight these cyber criminals.
Let’s hope that security professionals soon discover that sharing information is more valuable than secrecy. And let’s hope that Microsoft’s move is a first step in this change of attitude.
