Virus and worm nomenclature is typically left up to the security vendor which first discovers the malware. Until 2004 the process worked, more or less.
But the large scale and rapid release of multiple variants of worms in the Netsky and Bagle and MyDoom families this year led to confusion, with firms out of sync in their naming. One vendor would tag a new Bagle as Bagle.w, for instance, while others would call it Bagle.u or Bagle.t.
Most recently, confusion reigned when some security firms gave a worm an entirely new name -- "Bofra" -- while others claimed that it was only a variation of the long-running MyDoom.
"As a 'neutral third party' in the marketplace, US-CERT will coordinate with security vendors to implement a CME [Common Malware Enumeration] malware identification scheme," members of US-CERT's CEM initiative wrote in a letter to the SANS Institute's Internet Storm Center. "Limited operational capability is expected first quarter, 2005; this phase will concentrate on the most important threats, including the recent Beagle/Bagle variants."
Although there are obstacles to a common naming process -- including time constraints as anti-virus vendors rush to identify a worm and produce a defense against it -- US-CERT believes it's for the common good.
"Once all parties adopt a neutral, shared identification method, effective information sharing can happen faster and with more accuracy, making it easier to distinguish between very similar threats," the group wrote.
BP seeking Regional Desktop Coordinator in Houston, TX
Agilent Technologies seeking Marketing Manager in Melbourne, AU
US Civilian Research and Development seeking Web App Developer in Arlington, VA
Citrus Community College seeking Programmer Analyst II in Glendora, CA
Lowes seeking ITE Project Manager in Mooresville, NC
For more great jobs, career-related news, features and services, please visit our Career Center.
Make Your IT Staff Smarter With Digital Libraries
On-demand access to trusted technology information empowers IT workforces
to solve everyday technical challenges and increases productivity. Throw a valuable e-reference tool like a digital library out to a community of IT users, programmers, and business professionals, and they’ll uncover a variety of personal and corporate applications.

NOTE: Offer valid for U.S., U.S. possessions, & Canada only