ACMA: 30,000 Australian PCs infected every day

 

Regulator working on new zombie-tracking portal for ISPs.

View larger image
The Ruxcon conference in Melbourne on the weekend drew 500 of the country's most 'l33t' ...
View larger image
The latest security techniques and technologies were presented, queried and debated at length, ...
View larger image
A lock-picking demo took it back to where it all began and inspired punters to try their hand at ...

See all pictures here »

Australia's communications regulator has reported that there are approximately 25,000 to 30,000 computers compromised by malware every day in Australia.

The Australian Communications and Media Authority (ACMA) expected the total number of infected machines in Australia this year to soar past four million.

Zombie computers, infected by malware or other exploits, are often part of a wider network of "botnets", used to commit cyber crimes such as spam, phishing, or denial of service attacks.

Information about these exploited machines is being tracked in Australia by the Australian Internet Security Initiative (AISI) and the spam intelligence database (SID). The AISI aggregates information from a number of sources to inform ISPs about the number of compromised computers.

The voluntary program has secured the participation of universities, 90 ISPs ( including the "big four") and hundreds of virtual ISPs, Chaffe said.

In the 2008/2009 financial year, the ACMA reported 1.57 million incidents, which almost doubled the following year to 4.09 million incidents, according to ACMA e-security operations staffer Mark Chaffe.

This will increase significantly in the 2009/2010 financial year, as some 25,000 to 30,000 new infected computers are being reported daily, Chaffe told attendees at the Ruxcon technical security conference in Melbourne on the weekend.

"In some ways it's fantastic because we're getting more coverage, finding more compromises," Chaffe told attendees.

"But the inverse of that [is that] it's a bit disheartening to know there's 25,000 to 30,000 compromised computers on the internet and it doesn't look like it's changing.

"It's just always ramping up."

ISP portal in development

The ACMA usually emails these reports to internet service providers, including a 'repeated sightings report' for computers that have been infected several times over a short period of time.

But iTnews can reveal that more detailed information will soon be made available to ISPs via a one-stop information portal.

The portal will provide additional information to ISPs on already reported compromises - the details of which is yet to be finalised. ISPs will also be able to update their IP address ranges on the portal.

A spokesman for ACMA told iTnews the data will not be offered on the portal in "real-time."

"There will be a delay from when the compromise is detected to when it will be available via the portal," he said. "The timing depends on the source."

The portal will be restricted to AISI participants oand will be password protected, amongst other security measures.

Other measures

The AISI program covers 90 percent of Australia's residential broadband customers, but the ACMA only sees the IP address and the time of the attack and sees no personal customer information, Chaffe said.

The regulator cannot force ISPs to take actions against customers, but Chaffe highlighted recent proposals by the IIA for ISPs to quarantine infected PCs in a "walled-garden" environment.

"It could be very restrictive, and [the subscriber] would have to call the ISP to get out," he said. "Or it may be as simple as to apply updates and escape out."

The other half of AISI is the spam detection program SID. By integrating the two, the ACMA can identify which computers and botnets are being used for spam.

SID currently receives about two million spam messages a day, sourced directly from the public.

Chaffe said this was especially valuable because important information can be extracted from the messages that made it through user's spam filters.

Copyright © iTnews.com.au . All rights reserved.


"...in fact @Hubert, in my experience it is the same people who get infected over and over and over. I, like probably many here, have not had an infection for many years. Edited by ace: 28/11/2010..."
By Ace
 
 
 
Comments: 5
Thysce
Nov 25, 2010 10:58 AM
Is this a discovery of 10,000 more than the 20,000 conroy said to have been infected by spams and scams coming through the portal?
Spud
Nov 26, 2010 12:43 PM
"Australia's communications regulator has reported that there are approximately 25,000 to 30,000 computers compromised by malware every day in Australia."

Quick question: how many of those computers were running OSX? FreeBSD? Solaris? Linux? Correct: zero. It is not 25,000 to 30,000 _computers_ being compromised; it is _specifically_ 25,000 to 30,000 _Windows_-based computers being compromised.

A little accuracy never hurt anyone. Unless you are just a Microsoft shill, how about some accurate reporting, letting people know that their _computers_ have never been the problem, their choice in operating systems has.

BrianOz
Nov 27, 2010 12:28 PM
Does anyone else have a problem with the maths in this report?

Something just doesn't work out - if 30,000 infected are being reported daily, that's 1.8 million PCs every 2 months!

In just under 2 years, 20 million PCs would be infected - that's right, every computer in Australia. Something has to be wrong with those numbers!

As per Spud's posting, I would really like a breakdown by OS type and if possible, main browser. That could be used to force vendors to clean their acts up so could actually be constructive. If Microsoft is indeed the cause of most of this security load, as I suspect they are, perhaps legislation could be introduced to either get them to foot the bill or clean their act up. Just a thought for the future ... vendor pays security!!

HubertCumberdale
Nov 27, 2010 1:53 PM
BrianOz wrote:
In just under 2 years, 20 million PCs would be infected - that's right, every computer in Australia. Something has to be wrong with those numbers!

Not necessarily, could be the same 30,000 PCs getting infected by different malwares.
Ace
Nov 28, 2010 11:34 AM
...in fact @Hubert, in my experience it is the same people who get infected over and over and over. I, like probably many here, have not had an infection for many years.

Edited by ace: 28/11/2010 11:34:44 AM
Comments have been disabled for this article.
 
 
 
Top Stories
Australian miners send drones to work
In-depth: Unmanned aerial vehicles in the resources sector.
 
The New Zealand telco problem
Opinion: Could Telstra save Kiwi telcos?
 
IT price probe to 'name and shame' gougers
Industry ducking the issue, committee claims.
 
Sign up to receive iTnews email bulletins
   FOLLOW US...

Latest VideosSee all videos »

Latest Comments
Polls
Should the Government enact new legislation to protect copyright holders in the digital age?

   |   View results
Yes
  20%
 
No
  80%
TOTAL VOTES: 507

Vote