Home
BYTE Newsletter
Keep up with all the BYTE News and Reviews

Subscribe

Google Snaps Up VirusTotal Malware Scanning Service

Comments | Mathew J. Schwartz, InformationWeek | September 10, 2012 01:20 PM


Microsoft SkyDrive Vs. Dropbox, Google: Hands-On
Microsoft SkyDrive Vs. Dropbox, Google: Hands-On
(click image for larger view and for slideshow)
Google announced Friday that it's acquired VirusTotal, which offers a free scanning service to assess whether a website, URL, or piece of code is malicious. While terms of the deal weren't disclosed, VirusTotal will now function as an independent group at Google, and said it will keep existing relationships with security firms and researchers intact.

Google's acquisition of VirusTotal is a bid by the company to strengthen its Web security posture. "Security is incredibly important to our users and we've invested many millions of dollars to help keep them safe online," said a Google spokeswoman via email. "VirusTotal also has a strong track record in Web security, and we're delighted to be able to provide them with the infrastructure they need to ensure that their service continues to improve."

"Here's a little secret. Having a huge index of suspected and confirmed malware is really handy for protecting hundreds of millions of users," tweeted Google's Justin Schuh, who's part of the Google Chrome security team.

Launched in 2004, Spain-based VirusTotal offers on-demand scanning of any URL or file, aggregating detection capabilities offered by command-line versions of about 40 different antivirus scanning engines, file characterization tools and datasets, and website scanning engines.

But a blog post from the "VirusTotal Team" that announced the company's acquisition by Google, said that the company had often faced resource challenges, which of course Google--a long-term business partner--will singlehandedly overcome. "This is great news for you, and bad news for malware generators because [the] quality and power of our malware research tools will keep improving, most likely faster; and Google's infrastructure will ensure that our tools are always ready, right when you need them," according to the VirusTotal blog post.

[ Are you paying attention to the right things? Read 6 Password Security Essentials For Developers. ]

Google has increasingly been going on the offensive when it comes to spotting malware. Earlier this year, the company said it would begin warning users when their accounts appeared to be targeted by state-sponsored attackers. More recently, the company has also begun alerting users when it detects unusual access patterns to their email.

Early reaction from the antivirus industry to the deal has been positive. Eva Chen, CEO of Trend Micro, said in a blog post that the deal "is excellent news," because it will create an even more massive, on-demand repository of known-bad code. "Google's massive infrastructure is much more stable than the existing stand-alone VirusTotal infrastructure and we believe it will be [a] much more reliable source and so a benefit for the industry as a whole," she said.

In addition, Chen suggested that Google itself could now serve as a clearinghouse for malware samples, replacing what's now more of an ad hoc approach involving lots of behind-the-scenes sharing. "In the current system, security vendors get samples from their AV testing group, who in turn get these from other AV vendors," she said. "The problem with this is that whoever submits more samples get a higher detection rate and that skews the system. Overall, I think it's much better for everyone if the security vendors ... get these sample feeds directly from Google."

Some Google fans are already envisioning new ways in which the VirusTotal malware database might be extended. "Whoa, Google just bought VirusTotal ... Could it contribute to the Bouncer in the future perhaps?" read a tweet from Android Police, referring to Google's automated code-review service, which it uses to help keep malware out of its Google Play application marketplace.



Related Reading


More Insights




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events