Linux desktop growth could spur new malware activity
Experts say the platform, while generally secure now, could be vulnerable
Computerworld - When the Indiana Department of Education began installing PCs running Linux in schools last year, it installed open-source antivirus software on servers to scan incoming e-mail. But it didnt bother installing antivirus software on the desktop computers.
I hate to admit this, but I wasnt worried, said Forrest Gaston, a consultant managing the project for the state. Despite heavy student usage of the Internet, Gastons optimism has so far been borne out: It hasnt been an issue, he says.
Besides Linuxs low cost, its relative immunity from viruses, spyware, worms and other malware has long been one of the open-source operating systems key attractions to potential desktop users. Vendors who will be at next weeks Desktop Linux Summit in San Diego certainly tout it.
There are almost no viruses for Linux. Certainly, Ive never seen one, said Tom Welch, chief technology officer at Linspire Inc., a San Diego desktop Linux vendor and co-sponsor of the show.
Jeffrey Jaffe, the chief technology officer at Novell Inc., another show co-sponsor, feels much the same way. In a recent blog entry, Jaffe wrote that since joining Novell late last year and switching to Linux, viruses have become things of the past. Novell is pushing its SUSE Linux for corporate desktop use.
Even vendors hawking Linux antivirus products acknowledge that the operating system does not suffer today. Our product is more used to filter Windows viruses than actual Linux viruses, said Ron OBrien, an analyst at U.K.-based antivirus software maker, Sophos PLC.
But experts warn that could change if Linux begins to win a mass audience on the desktop, bringing in millions of users who are less proficient technically and less security-conscious than todays typical Linux user.
Windows was the only game in town, but now Linux is offering a more tempting prize, said John F. Andrews, president of open-source market research firm Evans Data Corp. in Santa Cruz, Calif.
Earlier this month, Evans released survey data showing that 11% of developers reported seeing malware on their Linux systems, with more than a third of those having three or more infections. While still low compared with infection rates among Windows users, they are the highest totals ever reported in Evans survey, which has been conducted twice per year since 2002.
Earlier this month, a cross-platform virus emerged that could theoretically infect both Windows and Linux. The virus, called Virus.Linux.Bi.a/Virus.Win32.Bi.a, has not been used in any known attacks.
But experts such as Johannes Ulrich, chief technology officer at the SANS Institue, a Bethesda, Md.-based Internet security group, say such proof-of-concept code has traditionally presaged the launch of actual malware. I think well see an increase in virus activity as Linux becomes more mainstream, Ulrich said.


- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Driving Secure Enterprise File Sharing and Syncing in the Enterprise
- GroupLogic's new activEcho is the industry's only secure Enterprise File Sharing and Synching solution that balances the need for simplicity for the end...
- The Enterprise File Sharing Option
- Enterprises and IT departments need to address several critical security issues when considering file sharing and syncing products. Many of today's solutions do...
- Security Strategies to Virtualizing Internet-Facing Applications
- The IT organization at Intel has set a goal to transition their enterprise to a private cloud for their Office and Enterprise applications....
- Cloud Security Planning Guide
- Cloud security considerations span protecting hardware and platform technologies in the data center to enabling regulatory compliance and defending cloud access through different...
- Cloud Security Vendor Round Table
- This vendor round table guide will help you to evaluate different cloud technology vendors and service providers based on a series of questions... All Security White Papers
- Live Webcast
Data Privacy and Protection in Production Environments: New Research from Ponemon Institute - Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Data Privacy and Protection in Production Environments: New Research from Ponemon Institute
- Date: Wednesday, June 13, 2012, 1:00 PM EDT / 10:00 AM PDT
In a recent study conducted by Ponemon Institute, fifty-five percent of respondents... - Security Certifications 101 - BlackBerry and all those acronyms what do they mean and why they matter?
- FIPS, Common Criteria, CAPS, AISEP, NFC, NIST, Fraunhofer SIT, CESG, DSD - these are just some of the government and industry certifications which...
- BlackBerry PlayBook OS 2.0 Security Overview
- The presentation provides an overview of BlackBerry PlayBook OS 2.0 security capabilities and features, including: BlackBerry® Balance™ technology, BlackBerry® Bridge, data-at-rest protection, and...
- BlackBerry NFC Security Overview
- The presentation on NFC security will provide an overview of the security protections built into the BlackBerry platform to protect users, application developers...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts