EU proposal would task ISPs with blocking infected addresses

By Sharon Fisher | Published July 1, 2008, 6:47 PM

A paper will be published later this year with far-ranging recommendations for reducing cybercrime in Europe, including a statutory scale of damages against ISPs that do not respond promptly to requests to shut out compromised machines.

A subset of the paper, entitled "Security Economics and European Policy," was presented by one of its four authors, Tyler Moore, a researcher and Ph.D student at the University of Cambridge. Other authors included Ross Anderson and Richard Clayton, also of the University of Cambridge; and Rainer Bohme, TU Dresden.

The group offered a set of 15 recommendations, including a cybercrime equivalent to NATO, and improvements to security, as well as more publicity about security breaches.

The paper (PDF available here) is a follow-up to meetings in April and last fall by the Council of Europe, which called for ISPs to share information and respond to government data requests more quickly, and similar requests from the European Union.

"People who leave infected machines attached to the network, so that they can send spam, host phishing websites and distribute illegal content, are polluting the digital environment," the report's authors wrote, "and the options available are broadly similar to those with which governments fight environmental pollution (a tax on pollution, a cap-and-trade system, or private action). Rather than a heavyweight central scheme, we think that civil liability might be tried first."

EuroISPA, a pan-European association of nine European ISP associations that is composed of about 1,000 ISPs, is generally supportive of improving security but is unsure or even against some of the specific proposals made by the Council of Europe, as a recent review indicates (PDF available here). EuroISPA includes ISPs from Austria, Belgium, Czechoslovakia, Finland, France, Germany, Ireland, Italy, and the UK.

Many countries have agreed to support the Council of Europe's Conventions on Cybercrime, but a number of others -- including some thought to be harboring botnet herders and other criminals using technology for extortion and denial of service attacks --- have not yet agreed to it. These countries include Andorra, Azerbaijan, Georgia, Liechtenstein, Monaco, Russia, San Marino, and Turkey.

A number of European countries and organizations have faced cyberattacks in the past year or so, including Estonia, and gambling operations threatened with takedowns just before major sporting events.

The "Security Economics" paper as presented did not go into a great deal of detail about how the proposals would be implemented, such as how a machine would be blocked or what recourse an innocent person with a hijacked machine might have.

Comments

I find it ironic that a page devoted to overall Internet Security chooses to use PDF as a format.

Score: 0

|

> The EU is talking out of it's arse again.

Oh poor diddums! Did the big bad EU fine Microsoft? Booo! If you read the paper or even the article it's by some university researchers not the EU. Anyway, the more Americans hate the EU the more we're reminded of the merits of doing things peacefully. Carry on invading! You'll get the bill in the end.

Score: 0

|

The EU is talking out of its arse again. They may as well start issuing licenses after passing an approved intaweb test. Make the users learn how to protect their machines and fine the users who don't. of course this will lead to internet tax and a annual computer MOT to make sure its all running smooth and isn't bug ridden.

Score: 0

|

There's no way this is ever going to work. They must understand that they're shooting at a moving target and sometimes that target is invisible.

Score: 0

|

Everyone in the world should just refuse to do anything that the EU tells them to do!
The EU is way too powerfull, we need to stop the EU before they rule the world!

Score: 0

|

Yeah, send in US troops. Let's join the land of the free!

Score: 0

|

Nobody hates the EU as much as we so-called Europeans.

Score: 0

|

Exactly !!

95% of European citizens don't want Europe, because it's going to mimick the U.S.A.

We don't want the Europe that will going to mimick the U.S.A. and it's so called "freedom", we want to live in REAL freedom and no faked up freedom filled with billions of methods that are just anti-freedom.

Score: 0

|

Europe loves to mimic the USA. There would be no Europe as you know it, if it were not for the USA.
Now tell me that you'd rather have had Uncle Adolph and his pals running things for the past 50 years.

Score: 0

|

..and you'd be the first person screaming if they didn't get there in time.

Score: 0

|

Yea yea ... the USA won the war single handedly.
Their motives were not driven by the thought of buying oil from the Germans at all.

"There would be no Europe as you know it, if it were not for the USA."

There would not be no USA as you know it, if the Europeans hadn't populated it.

If your so good what happened in Vietnam ? run out of bullets ?

Score: 0

|

For the record, is this a joke? "Buying oil from the Germans"???

Score: 0

|

"People who leave infected machines attached to the network, so that they can send spam, host phishing websites and distribute illegal content, are polluting the digital environment". Two outta three ain't bad, but how exactly is illegal content "polluting" the net? Other than the numerous trojans contained in illegal software, I can't see the analogy.

Score: 0

|

In theory it will block botnets (spam, viruses etc) and p2p-based attacks. Hope it will work.....well

Score: 0

|

Should be mandatory for any business to run their DNS requests through OPENDNS.com and register every single bad phishing or virus spam domain so we can get rid of this altogether.

OpenDns is the fastest DNS servers I have ever used and block everything I ask them to and more...Pitty we could not block stupid poeple, unfortunately its impossible...

Score: 0

|

Can Linux do BitLocker better than Windows 7?

Betanews kicks off a new series with a look at how the Linux operating system's FDE stacks up against BitLocker, the Windows feature that today commands a $120 premium.

Firefox 3.5: The need for speed

This has been the big payoff week for Mozilla's developers, who worked overtime to squeeze out the last drop of performance from their new JavaScript engine.

'GeoHot' gets a shower, cleans up nice, reveals new iPhone 3G S jailbreak

Either puberty has been very kind to the author of the new 'Purple Ra1n' jailbreak tool, or George Hotz may also have some adequate Photoshop skills.

What's Next: Obama gives 'Einstein' the go-ahead, while China gives 'Green Dam' a thumbs-down

Plus: If you put up a Web site and name it after you and you're a federal judge, you might not want a bunch of weird nudity hanging around on it.

Why would Windows 7 customers spend $120 more for BitLocker?

For pre-orders from now until July 11, Microsoft is offering the Windows 7 Professional SKU for a very steep discount. So why invest in Ultimate?

Geeks vs. journalists: A tale of two worldviews

Recovery with Angela Gunn Why geeks think most mainstream journalism is flaky, and why the mainstream thinks geeks are trying to kill them. (They're both right.)

Fire in downtown Seattle data center knocks out businesses, online services

Small fire has global impact with payment centers, city services down.

Hybrid satellite cell phones aren't far off

The first satellite in Terrestar's hybrid cellular/satellite phone network has been launched.

SMS could be a critical iPhone vulnerability, says white-hat hacker

Mac hacker Charlie Miller knows how to get into your iPhone.

Will Oracle's Java-based Fusion middleware 'fuse' with Java?

Now that Oracle has acquired Sun Microsystems, Java developers and supporters are wondering when Oracle will formally welcome Java into the family.

All together now: iPhone and Palm Pre, likely to both grace O2's UK portfolio

European wireless network operator O2 has reportedly reached a deal to exclusively carry the Palm Pre in the UK. O2,...

Vista's dead: Microsoft kills an OS and no one cares

Carmi Levy: Wide Angle Zoom Can you kill an operating system? Microsoft is about to find out.

Kantaris Media Player 0.5.7

July 3 - 5:34 PM ET

Wine 1.1.25

July 3 - 5:30 PM ET

ChrisTV Online! Free 4.00

July 3 - 5:22 PM ET

glu 1.0.19 RC1

July 3 - 5:11 PM ET

Website-Watcher 5.1.0 Beta 10

July 3 - 1:20 PM ET