Measurement and Analysis of Spyware in a University Environment.
Stefan Saroiu, Steven D. Gribble, Henry M. Levy · 2004
Abstract Over the past few years, a relatively new computingphenomenon has gained momentum: the spread of "spyware. " Though most people are aware of spyware, theresearch community has spent little effort to understand its nature, how widespread it is, and the risks it presents.This paper is a first attempt to do so. We first discuss background material on spyware, in-cluding the various types of spyware programs, their methods of transmission, and their run-time behavior.By examining four widespread programs (Gator, Cydoor, SaveNow, and eZula), we present a detailed analysis oftheir behavior, from which we derive signatures that can be used to detect their presence on remote computersthrough passive network monitoring. Using these signatures, we quantify the spread of these programs amonghosts within the University of Washington by analyzing a week-long trace of network activity. This trace was gath-ered from August 26th to September 1st, 2003. From this trace, we show that: (1) these four pro-grams affect approximately 5.1 % of active hosts on campus, (2) many computers that contain spyware have morethan one spyware program running on them concurrently, and (3) 69 % of organizations within the universitycontain at least one host running spyware. We conclude by discussing security implications of spyware and spe-cific vulnerabilities we found within versions of two of these spyware programs. 1