otamalvertising

Billions of Web Ads Carried Malware in 2010

  |  February 10, 2011   |  Comments

Online Trust Alliance says it confirmed incidents of malvertising on 3,500 sites and 200 unique ad networks.

More than 10 billion online ad impressions served up in 2010 carried malware, according to recent research from Online Trust Alliance. The organization, dedicated to establishing best practices for ensuring data privacy and security online, argues that delivery of ads transferring malicious code could be prevented if ad networks and other ad third parties took care to know their business partners.

The organization estimates most of the malvertising served last year came in the form of display ads, and many of the ads emanated from outside the U.S. Based on aggregate data from ad serving firms, OTA reported in December that it confirmed nearly 19,000 incidents of malvertising last year occurring across 3,500 sites and 200 unique ad networks.

To arrive at its estimate of 10.8 billion bad ad impressions, the group estimated the number of impressions that ran on average per incident in a typical three-day period - the average number of days a malvertising campaign runs before it’s discovered and stopped. Ads carrying malicious code usually enter through unverified ad agencies submitting them into the supply chain. "Legitimate advertisers are being compromised; they're a victim as well," said Craig Spiezle, executive director of the OTA.

otamalvertising

 

"Every major ad network, whether it's Yahoo, Microsoft or Google, has experienced this," said Spiezle. The group calls malvertising a low frequency but high impact security problem. While Spiezle acknowledges the yearly estimate of 10 billion malvertising impressions is miniscule compared to the number of ad impressions that run online in total, he said the estimate is "very, very, very conservative." ComScore measured around 417 billion ad impressions in September 2010 alone. "The last thing we want is for consumers to be fearful of the ads," added Spiezle.

Typically, the bad ads carry code that captures the "fingerprint" of a user's machine, determining what software it's running, tracking key strokes, and grabbing logins and passwords. "For a machine that's exposed to this and is unprotected, anything is fair game," said Spiezle.

"We know it's well over 10 billion" impressions, said Spiezle, adding, "The challenge is this is a moving landscape." The OTA will discuss the research findings at the RSA security conference in San Francisco Monday.

Spiezle said the OTA does not know how many malvertising impressions have been intercepted by browsers or security software.

The OTA, a group founded in 2004 that counts around 80 different companies including eBay, Chase, Symantec, Microsoft, and even the U.S. Senate and U.S. Postal Service as members, publishes scorecards rating adoption of best practices by entities dealing with online data.

"This is an industry-wide issue.... This could really impact consumer trust and the vitality of interactive advertising as we know it," Spiezle said. "The supply chain was not built with a security goal in mind."

Tags:

ClickZ Live Chicago Join the Industry's Leading eCommerce & Direct Marketing Experts in Chicago
ClickZ Live Chicago (Nov 3-6) will deliver over 50 sessions across 4 days and 10 individual tracks, including Data-Driven Marketing, Social, Mobile, Display, Search and Email. Check out the full agenda and register by Friday, Oct 3 to take advantage of Early Bird Rates!

ABOUT THE AUTHOR

Kate Kaye

Kate Kaye was Managing Editor at ClickZ News until October 2012. As a daily reporter and editor for the original news source, she covered beats including digital political campaigns and government regulation of the online ad industry. Kate is the author of Campaign '08: A Turning Point for Digital Media, the only book focused on the paid digital media efforts of the 2008 presidential campaigns. Kate created ClickZ's Politics & Advocacy section, and is the primary contributor to the one-of-a-kind section. She began reporting on the interactive ad industry in 1999 and has spoken at several events and in interviews for television, radio, print, and digital media outlets. You can follow Kate on Twitter at @LowbrowKate.

COMMENTSCommenting policy

comments powered by Disqus

Get ClickZ Media newsletters delivered right to your inbox. Subscribe today!

COMMENTS

UPCOMING EVENTS

Featured White Papers

IBM: Social Analytics - The Science Behind Social Media Marketing

IBM Social Analytics: The Science Behind Social Media Marketing
80% of internet users say they prefer to connect with brands via Facebook. 65% of social media users say they use it to learn more about brands, products and services. Learn about how to find more about customers' attitudes, preferences and buying habits from what they say on social media channels.

An Introduction to Marketing Attribution: Selecting the Right Model for Search, Display & Social Advertising

An Introduction to Marketing Attribution: Selecting the Right Model for Search, Display & Social Advertising
If you're considering implementing a marketing attribution model to measure and optimize your programs, this paper is a great introduction. It also includes real-life tips from marketers who have successfully implemented attribution in their organizations.

WEBINARS

Jobs

    • Web Writer
      Web Writer (Money Map Press) - BaltimoreDo you have a passion for the markets and investing, and writing? Do you want to spend your days providing...
    • Web Production Specialist
      Web Production Specialist (Money Map Press) - BaltimoreMoney Map Press is looking for a self-starter to perform and oversee the production of daily...
    • Internet Marketing Campaign Manager
      Internet Marketing Campaign Manager (Straight North, LLC) - Downers GroveWe are looking for a talented Internet Marketing Campaign Manager...