Linux desktop growth could spur new malware activity
Experts say the platform, while generally secure now, could be vulnerable
April 20, 2006 12:00 PM ETComputerworld - When the Indiana Department of Education began installing PCs running Linux in schools last year, it installed open-source antivirus software on servers to scan incoming e-mail. But it didnt bother installing antivirus software on the desktop computers.
I hate to admit this, but I wasnt worried, said Forrest Gaston, a consultant managing the project for the state. Despite heavy student usage of the Internet, Gastons optimism has so far been borne out: It hasnt been an issue, he says.
Besides Linuxs low cost, its relative immunity from viruses, spyware, worms and other malware has long been one of the open-source operating systems key attractions to potential desktop users. Vendors who will be at next weeks Desktop Linux Summit in San Diego certainly tout it.
There are almost no viruses for Linux. Certainly, Ive never seen one, said Tom Welch, chief technology officer at Linspire Inc., a San Diego desktop Linux vendor and co-sponsor of the show.
Jeffrey Jaffe, the chief technology officer at Novell Inc., another show co-sponsor, feels much the same way. In a recent blog entry, Jaffe wrote that since joining Novell late last year and switching to Linux, viruses have become things of the past. Novell is pushing its SUSE Linux for corporate desktop use.
Even vendors hawking Linux antivirus products acknowledge that the operating system does not suffer today. Our product is more used to filter Windows viruses than actual Linux viruses, said Ron OBrien, an analyst at U.K.-based antivirus software maker, Sophos PLC.
But experts warn that could change if Linux begins to win a mass audience on the desktop, bringing in millions of users who are less proficient technically and less security-conscious than todays typical Linux user.
Windows was the only game in town, but now Linux is offering a more tempting prize, said John F. Andrews, president of open-source market research firm Evans Data Corp. in Santa Cruz, Calif.
Earlier this month, Evans released survey data showing that 11% of developers reported seeing malware on their Linux systems, with more than a third of those having three or more infections. While still low compared with infection rates among Windows users, they are the highest totals ever reported in Evans survey, which has been conducted twice per year since 2002.
Earlier this month, a cross-platform virus emerged that could theoretically infect both Windows and Linux. The virus, called Virus.Linux.Bi.a/Virus.Win32.Bi.a, has not been used in any known attacks.
But experts such as Johannes Ulrich, chief technology officer at the SANS Institue, a Bethesda, Md.-based Internet security group, say such proof-of-concept code has traditionally presaged the launch of actual malware. I think well see an increase in virus activity as Linux becomes more mainstream, Ulrich said.
Additional Resources


White Papers & Webcasts
Mitigating Litigation Risk with Email Management Tools
Does your company have an email retention policy that protects it when litigation occurs? IDC discusses effective email retention policies and the role...
Managing And Protecting Your Ever Increasing Mobile Assets
Learn best practices for desktop and application virtualization, computer security, and computer life-cycle management....
Protecting Content During Business Disruption: Are You Covered?
Learn how ECM is helping Tulane University and the 13th Judicial Circuit Court implement disaster readiness programs....
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
Beyond PCI Checklists: Securing Cardholder Data with Tripwire's Enhanced File Integrity Monitoring
How do organizations pass their PCI DSS audits yet still suffer security breaches? Paying attention to PCI DSS checklists only partially secures the...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Authentication as a Service by Forrester Research
Authentication-as-a-Service: understand the benefits of two factor authentication and the best ways to implement it....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
