As if to underscore its call for greater industry cooperation to fight malicious online ads and content, Google allowed a scam ad to appear briefly atop search results on Tuesday for the term "Firefox."
The sponsored link purported to take Google (NSDQ: GOOG) searchers to the official Firefox Web site, but in fact took them to a different domain, firefox.mozilla-now.com, according to Sophos, a computer security company.
More Security InsightsWhite PapersPop Goes the Trademark?: Competitive Advertising on the InternetNeutralizing the Spyware ThreatWebcastsGone in 6.0 Seconds: Protecting Laptops and Data from TheftSharePoint and Compliance Regulations- The Rules and How to Avoid Violating ThemReportsCybersecurity Balancing Act3G Safeguards: Incomplete, Getting BetterVideos
InformationWeek editor, John Foley, spoke with Calvin Lui, CEO of Tumri, about their interactive ad platform. With their new technology, ads dynamically change based on geography, demographics, psychographics, media type, sites, etc.Google appears to have removed the ad as a violation of the company's advertising policies.
A company spokesperson declined to comment on the Firefox ad in question, but acknowledged that the company does look for and remove ads that violate its policies.
"Google's advertising policy requires that the Web site address displayed in the ad must match the domain of the landing page for that ad in order to ensure that users clearly understand the destination Web site being advertised," the spokesperson said in an e-mailed statement. "We use a combination of manual and automated processes to detect and enforce these policies."
But the incident underscores the problem that Google and other online companies face in trying to thwart malicious advertising, or malvertising.
Malicious ads have also been spotted this year at nytimes.com. eweek.com, mlb.com, and foxnews.com, among other Web sites and such incidents are becoming more common.
ScanSafe, a security company, on Wednesday said that a large scale malvertising attack had hit popular Web sites, including drudgereport.com, horoscope.com and lyrics.com, over the weekend.
The company said that the ads were delivered by the several advertising networks, including DoubleClick, YieldManager and FastClick.
On Wednesday at the Virus Bulletin conference in Geneva, Switzerland, Eric Davis, head of Google's anti-malvertising team, part of the company's broader anti-malware team, urged ISPs and security companies to work together to fight malicious ads and content. He pointed to the Australian government's Australian Internet Security Initiative, a program to help ISPs identify hijacked PCs (bots) and regain control over them, as an example of cooperative security.
Along those lines, Google earlier this year introduced a custom service engine for conducting background research on online advertisers. In June, the company launched anti-malvertising.com as a home for its custom search engine and as a resource for those fighting malvertising.