The (correct) detection of light grey software presented at Virus Bulletin 2006

by Roel Schouwenberg (Kaspersky lab),

Tags: Security


Summary : "As brought up in my article in Virus Bulletin (see VB, October 2005, p.6), a new type of
'malicious' software is on the rise which can be considered as 'light grey'.
Since then some of these programs have made the news, with the introduction of the WMF exploit
by people wanting to promote their light grey software being the main headliner.
Several security vendors have dubbed these programs as adware or spyware, but is this
classification actually correct? There is more than meets the eye.As ICT is evolving we are seeing an increase in requests to detect 'regular' programs, such
as Skype for instance, which is known to be almost impossible to block on the network level. What kind of
implications does this have? Which way should the AV industry move in order to protect not
only its customers but also itself from a legal point of view?
This paper presents a view on these questions, along with some proposed answers.