Microsoft introduces real-time threat feed
It looks as if Microsoft is ready to do its part to deter cyber crimes. Microsoft plans to offer real-time feeds that partners can use to analyze potential cyber threats and take the proper steps to boost their defenses against these attacks.
Microsoft currently has a process set up to take down dangerous botnets. Microsoft “swallows” the botnets and allows them to infect accounts that are highly controlled by Microsoft’s team. Once the botnets infect the accounts, Microsoft learns how they work and eliminates them as a threat.
This collected information is now shared with ISPs, private and government organizations, & CERTs. While real-time data may not lessen the number of attacks by malicious code, the impact of sharing this data will most likely be quite remarkable. IT security companies should be able to respond more quickly to these threats and therefore be able to reduce the amount of damage they can cause.
Another great impact a real-time threat feed could have is an improvement in overall information sharing between IT security companies. For too long IT companies have been reluctant to share threat information for the fear that it might fuel more attacks. Most experts say this an unsupported fear. The cyber criminal “community” is already sharing and gaining knowledge from each other. It’s only logical therefore that IT security professional share as much information as possible to fight the seemingly unending barrage of new cyber threats.
Microsoft’s real-time feed is a good first step toward a change for the better in IT security. Let’s hope this trend persists and that the IT security world will realize that secrecy is not more useful than sharing information!
