You are here: silicon.com > Software > Security Strategy

Security Strategy

University offers spam and spyware writing course

The virus writing class of 2003 now get to create their payload...

By Will Sturgeon

Published: 8 February 2005 17:55 GMT

The controversial computer science department at the University of Calgary has once again kicked off heated debate in the security industry by offering students a course in writing spyware and the tools for sending and propagating spam.

The move follows the introduction of a widely-criticised virus writing course offered by the university in 2003.

However, the reaction to the latest addition to the syllabus has been more measured, with many in the security sector saying the right skills, taught in a controlled environment will prove a useful addition to their industry.

Steve Purdham, CEO of SurfControl, said he'd certainly look favourably upon any applicant who was a graduate of the course.

"If we're looking for an engineer to help us combat problems like spam then we'd rather have somebody who has already been taught about these things and who knows how they work."

Purdham says it does the students and the university a great disservice to assume they will abuse the knowledge rather than put it to good use.

"It's like teaching safe sex," he said. "Rather than hiding ourselves away from this stuff and mystifying it – which can actually make it more appealing – we need to understand the mechanics in order to protect ourselves.

Mark Murtagh, European technical director at Websense, said: "Any good security analyst will have used spyware and hacking tools like Trojans and keyloggers to keep them up to speed on the dangers out there. Knowledge is power, and the security space is like a game of chess - you need to be completely up to date on what's available to ensure you understand your opponents potential next move."

Murtagh said there are no guarantees that students won't be 'tempted by the dark side' but said if an individual really is intent on writing spyware or spam tools they don't have to go to the lengths of enrolling in University courses.

"This information is all freely available on the internet," said Murtagh.

But not everybody in the industry is in favour of the idea.

Pete Simpson, ThreatLab manager at Clearswift, expressed shock that the university has re-opened old wounds and criticised what he sees as the unnecessary risk of training students to use techniques which can jeopardise the safety of internet users.

"When the University of Calgary first caused controversy with the virus writing course, their dubious defence was that only by writing viral code could a student fully understand and be able to protect against real viruses, but I'm sorry, that argument really falls flat for spamming tools."

Clearswift's Simpson believes the saleability of spam tools may create too much of a financial temptation for hard-up students.

And unlike with viruses the covert nature of spyware and spam tools means it may be even more difficult to trace any abuse back to students at the university if they do stray.

The university threatens students with a fail and prosecution if they are involved in any irresponsible or criminal use of malicious code.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...

Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech


  • Jobs
Lead Operations Engineer / Senior Systems Engineer Redhat Linux

Our client`s solutions keep viruses and spyware off corporate networks and allow organisations to control and secure the use of the Web and instant ...

Java Developer / J2EE Developer (Spring, Tomcat, Jetty etc)

Our client`s solutions keep viruses and spyware off corporate networks and allow organisations to control and secure the use of the Web and instant ...

Network Support 21-23k - Trowbridge

Due to continued market growth they are in an exciting growth period and are now looking to expand this division and recruit a Network Engineer The ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: