I think there should be a government organization similar to the CDC which would work towards preventing, containing and reacting to computer malware.
Currently, there is the FBI’s cyber crime division which has to deal with a lot more than just malware. Also, as a crime fighting organization, the FBI is poorly positioned to work on prevention, which I think is the most important step. The FBI could continue to handle the investigation and prosecution of the people behind these pieces of software, while the new organization worked with OS and browser vendors and developed removal tools and other methods for removing malware, but ultimately worked towards preventing malware as much as possible. The internet today is like real viruses were before vaccines came about. The best way today to avoid malware is to not go outside (to the internet) at all.
Right now, the internet is basically in the middle of a constant, non-ending breakout of viruses, trojans, spyware and other forms of malicious software. Computers are attacked for use as spam bots, as well as for modifying web browser settings to create fake search results pages, and for many other malicious purposes.
When it comes to infectious diseases and viruses, there’s government research and staff dedicated to trying both preventative and reactive strategies against a potential outbreak. Primarily I’m thinking about this group under the CDC, which seems to fill the roll of the stereotypical CDC in popular culture.
Real viruses and infectious diseases have a very high cost, death and/or major health problems. So there is some argument that making the comparison between infectious diseases and malware is a bad idea. Also, while physical diseases and viruses can be customized or manufactured to some degree, the majority of the threat from these things is outside human control. Viruses and diseases mutate on their own in response to changing circumstances, whereas for the most part, computer malware “mutates” by being changed by real people out there.
However, the current system where commercial entities are the primary fighters against malware seems to be a bad idea. I work in IT and the fight against forms of malware today rarely relies on paid products. We have Symantec installed on every machine but I would guess less than 5% of the malware problems that I ultimately resolve are helped by Symantec, with most of them being solved by free products like Spybot, Adaware and lately Malwarebytes.
Currently information on the latest malware threats is too scattered and too much out of date. There should be a system where people encountering malware can upload their information to a centralized database which could be searched and categorized by things like files created/affected, type of malware (fake virus remover, trojan, etc) and other categories. In addition, the Computer NCPDCID could publish removal tools and review and analyze the threat profiles of operating systems and web browsers.
I think the primary benefit to having such an agency would be to unify the picture of what is going on. If you look at most security sites out there, all of the listed latest threats are given very low threat ratings, while in fact, I have been forced several times to reformat and reinstall to kill off a trojan or virus. Malware also poses security threats to internal networks and with regarding to banking and other kinds of sites used by home users. An additional benefit is that if efforts can be made against the large infection of botnets, the spam problem would be helped to some degree as well.
Malware won’t kill you but more and more it can cause big problems.