• On GameSpot: Wii Fit tells 10-year-old she's fat
Click Here
advertisement
Security Watch : Don't get burned by viruses and hackers.
It wasn't me; it was the Trojan horse
By Robert Vamosi 
Senior associate editor, CNET Reviews
November 19, 2003

Remember the Twinkie defense? Well, now there's the Trojan horse defense. That's right: In three recent court cases in the United Kingdom, defendants pleaded not guilty on the basis that someone else put code on their computers (via a Trojan horse) that caused their machines to break the law.

While these cases have no direct bearing on U.S. court cases, they could lead to creative defenses for computer-related crimes in this country as well.

Pornographic Trojan horses
The first two cases involved the downloading of child pornography, while the third concerned a denial-of-service attack that caused real-world economic damage. All three defendants were acquitted.

In one of the child pornography cases, Karl Schofield of Whitley, England, was cleared of processing 14 images of child pornography on his home PC. In the other, Julian Green of Devon, England, was acquitted of storing 172 images of child pornography on his system.

The defendants pleaded not guilty on the basis that someone else put code on their computers.
In both cases, computer forensics experts found evidence of Trojan horses on the suspects' hard drives. The rogue code was allegedly deposited there via pop-up advertisements, banner ads, or Internet worms.

The third case involved a U.K. teenager named Aaron Caffrey. U.S. police discovered that his computer was responsible for the denial-of-service attack that crashed servers at the Port of Houston in October. However, Caffrey claimed that someone else put a Trojan horse on his PC that allowed his system to be controlled remotely. When investigators were unable to find evidence of such a remote-control Trojan, Caffrey claimed the Trojan had automatically erased itself.

Can't fool forensics tools
This seems suspicious to me, if only because Microsoft Windows (the operating system on Caffrey's computer) is notorious for creating duplicates or logs of all data. So either Caffrey was lying, or the authorities who investigated him were inept, as evidence of a Trojan horse should be relatively easy to find. Computer forensics tools, such as Guidance Software's EnCase, can quickly reveal hidden, partial, or even deleted files.

Caffrey also appeared to have access to Trojan horse code and a motive. He admitted he was active in script-kiddie IRC chat rooms, which are rife with code that could shut down remote computers. And he disclosed that he was infatuated with another IRC participant and took offense when another script kiddie sullied the young woman's reputation. Yet, despite his admissions, Caffrey's someone-else-did-it-then-erased-it defense proved good enough for a British jury, which acquitted him last month.

Because of this, computer crime investigators need to gain a better understanding of what particular Trojans can and cannot do.
It's only a matter of time before someone tries the Trojan horse defense in a U.S. court, most likely in a child pornography case. Because of this, computer crime investigators need to gain a better understanding of what particular Trojans can and cannot do. For example, does a given Trojan facilitate the automatic downloading of pornography, or does it simply track a user's surfing history? Further, lawyers and judges will need to learn how to explain this technical information to jurors, who will ultimately rule on a person's guilt or innocence.

Anti-adware apps
Trojan horses are truly pernicious. I do a good job of keeping my work and home computers secure, yet I still find the occasional rogue file on my hard drive, probably from sites I visit through search engines. Rather than take the chance of having your computer become infected, I recommend not only keeping your antivirus software up-to-date and using a personal firewall, but also running Spybot Search and Destroy or Ad-aware 6.0 periodically to remove Trojan horses.

Only by keeping rogue code off of your hard drive will you be certain you'll never have to invoke the Trojan horse defense.

What do you think of the Trojan horse defense? Should it hold up in court? Why or why not? Tell me about it--TalkBack to me!


CNET Security Center
Update your software and learn about firewall apps
CNET Virus Center
View current virus threats, learn how to protect your PC, and more
Antivirus applications compared
Find the right antivirus product for you
McAfee security line reviewed
Read the latest antivirus and firewall reviews from McAfee
Norton's security line examined
Read the latest antivirus and firewall reviews from Norton
Virus and security alert forums
From CNET Message Boards




11/12/03
Why Microsoft's hacker bounty is wasted
Instead of using their cash to make Windows more secure, Microsoft and others are shelling out $5 million to catch virus writers. Here's why this won't make the Net any safer.

11/5/03
Electronic checks--how secure are they?
Paper checks are giving way to something called electronic check conversion, which you're sure to encounter this holiday season. How secure is this payment method?

10/29/03
What can criminal hackers really do to your PC?
You hear a lot about the havoc criminal hackers wreak on people's PCs. But how likely is this? And what exactly can they do: Turn on your PC? Steal your data? Robert Vamosi has the answers.



More commentary
Buzz Report
Molly Wood
Taking a bite out of hype.
Security Watch
Robert Vamosi
Don't get burned by viruses and hackers.
Fully Equipped
David Carnoy
The electronics you lust for.
On Call
Kent German
Solutions for your wireless woes.
Driving It
Wayne Cunningham
What's hot and what's not in car tech.