Worm spread shows hole in patch system

ANALYSIS

The ability of the MSBlast worm to spread has underscored the view that today's methods of patching security flaws, while necessary to lock down specific computers, are too time-consuming to react to critical vulnerabilities. The result has been that the MSBlast worm, which by most accounts is poorly programmed, has quickly propagated across the Internet.

The worm has infected at least 120,000 computers and has caused internal disruptions for many companies and Internet service providers.

The University of Florida, for instance, has had hundreds of systems infected due to a compromised PC connected to its network via a dial-up line. The incident happened despite a broad initiative by the school to lock down its systems with patches, said Jordan Wiens, a network security engineer for the university.

"It's simply not as easy (to patch) as people would like, given the resources of many small departments," Wiens said.

Microsoft confirmed that it is working with law enforcement to find the person or group who released the worm.

Microsoft has attempted to step up user education and automation to convince more consumers and enterprise customers to update their systems with the latest patch for this security flaw. However, the efforts have still left many PC users in the dark about their computer's insecurities.

The Computer Emergency Response Team (CERT) Coordination Center has found that as many as 1.4 million unique Internet addresses appear to be the sources of infections on the network. The number is likely to have been inflated by dial-up and broadband users that receive a different address every time they connect to their provider's network.

Security firm Symantec offered a more conservative number, based on its intrusion detection network. It found that more than 120,000 computers appear to have been infected in the past 36 hours.

The lesson: patching can't be relied on to keep computers secure.

"There is no one single answer," said Stephen Toulouse, security program manager at Microsoft. "We encourage defense-in-depth, but we also encourage customers to deploy the patch."

A defense-in-depth strategy calls for companies to not only secure the servers and network devices connected to the Internet, but to also secure their internal networks. In the past, a strategy of so-called perimetre security has been more common. Because holes in security are always a possibility -- and usually a given -- building redundancies into a corporate network could make the difference between a single breach and massive infection.

Patching is only one facet of a corporate security strategy and should be considered fallible as best, said Gerhard Eschelbeck, chief technology officer for vulnerability assessment firm Qualys. Only about 50 percent of Windows computers have had the patch applied in the last month, a typical half-life, a Qualys study found.

"We are already seeing the number of systems that are vulnerable on the Internet trailing down," he said.

In a study announced in July, Qualys found that half of all vulnerable systems are patched in the first month after a fix is available.

Home users typically patch their systems less often, said Jack Bates, network engineer for regional ISP BrightNet Oklahoma. He estimated that as much as 20 percent of BrightNet's user base had been infected.

"Home users do not actively keep up with Windows Update," he said. "Some are not even aware that it exists."

Instead of relying on its clients to patch their systems, BrightNet has blocked traffic to the vulnerable software addresses, or ports, and e-mail alerts will be sent to infected users. "This will require extensive man-hours from our personnel, as well as our customer's time," he said.

Intrusion detection systems have spotted PCs that the worm compromised on the networks of most major consumer Internet providers, including America Online, AT&T, Comcast, Cox Communications, SBC Communications and Verizon Communications. It's unlikely that the ISPs' systems have been infected by the worm, but a large number of clients that connect to those providers may have been compromised.

While businesses usually know of software flaws and the need to patch their systems, they don't always have time. Companies often do not patch their systems immediately, because they need time to test the fixes, said Brian Burns, manager of security operations for network device maker NetScreen.

"Microsoft patches don't receive enough QA (quality assurance) as they should," he said. "There have been times that a patch has been applied, and then the administrator has to spend hours rolling it back, because it has crashed the machine."

Microsoft has focused on providing tools for companies to further automate their management of patches. The company's Software Update Services allows companies to maintain a central service of patches internally and update systems depending on the patch's importance, a computer's level of exposure to threats on the Internet and how critical the system is.

Until companies start thinking about network security when designing their infrastructure, patching will be a difficult task, Qualys' Eschelbeck said.

"For the next four years, we are going to be stuck where we are now, because we have to pay for the sins of the past," he said.

Another problem with software patches is that they sometimes modify business applications in unexpected ways, said Rick Beers, director of supply chain technology at Corning, a manufacturing company.

That calls for a better explanation from technology makers of what might be unintended consequences of installing patches. "Other than a magic technology solution, the only solution is much more thorough documentation from the vendor," Beers said.

CNET News.com's Mike Ricciuti contributed to this report

 

Talkback

There are other solutions to prevent that your network stays vulnerable when yo have no time to patch. We developed an Intrusion Prevention System called AccessGuard (www.accessguard.nl). This product is placed in front of the network, and can detect and block intrusions from hackers and worms before they enter the network. The AccessGuard detected and blocked the first Blaster worm on the network of on of our customers in the early morning of the 9th of August. That was before the 'major alarms'. None of our customers is infected by this worm, and we had the same thing with other worms like Code Red, Nimda and Slammer.

13 Aug 03 12:16 Reply

Post your comment

In order to post a comment you need to be registered and logged in

Log in or create your ZDNet UK account below

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Membership FAQ

ZDNet UK Live

John Molloy

Apple are currently pushing to get tv content on the iPad by April 3rd. This could possibly be seen as a spoiler for that announcement I suppose....

11 hours ago by John Molloy
Andrew Donoghue

Hey - presume you mean something that builds on Apple's existing TV device? Apple have already had a couple of runs at building Apple TV and it's...

17 hours ago by Andrew Donoghue on Google's TV timing may reveal more to come
BVE2011

Google, Sony, Intel may build TV project www.zdnet.co.uk/news/emerging-tech/2010/03/18/google-sony-intel-may-build-tv-project-40088359/

ator1940

70,0000 to 90,0000 computers? A very small number considering some of these botnets are in the millions, and there are so many of them operating,...

18 hours ago by ator1940 on Microsoft says it decimated Waledac botnet
ator1940

I agree Roger, and why can't they write secure code? What will happen when they find stolen code in windows? They have a track record of...

19 hours ago by ator1940 on Microsoft lashing out at Linux, open source
ator1940

Do you think it will really take days?

19 hours ago by ator1940 on Microsoft previews Internet Explorer 9 with HTML 5 support
neilfab

@evilmanic have you seen the new hp on zdnetuk

Xwindowsjunkie

Wonder how many days it will take before somebody codes an exploitive hack for IE9?

1 day ago by Xwindowsjunkie on Microsoft previews Internet Explorer 9 with HTML 5 support
roger andre

There are some really good people in Microsoft and I wonder, how embarassing it must be for them to see how the organisation behaves from it's...

1 day ago by roger andre on Microsoft lashing out at Linux, open source
ajclarke

Great new look for ZDNET UK web-site http://bit.ly/9R5eAA to check it out @ZDNetUK #zdnet

feedfrog

Microsoft previews Internet Explorer 9 with HTML 5 support - zdnet.co.uk http://bit.ly/9FSh23

kencogold

We were just pondering on when IE will get HTML5 and CSS3 onboard! this is excellent

2 days ago by kencogold on Microsoft previews Internet Explorer 9 with HTML 5 support
riptari

RT @suziedaniels: relaunched www.zdnet.co.uk raises the bar yet again! its so fast it makes my eyes bleed.

Bob Preece

This is brilliant - I borrowed one and straight away saw that a few AP`s were set up to the wrong country. It gives interference levels on each...

2 days ago by Bob Preece on Fluke Networks AirCheck Wi-Fi Tester
_SimonArnoldme

http://www.zdnet.co.uk/news/networking/2010/03/11/european-parliament-votes-down-acta-treaty-40085614/ (Where does this leave #Debill?)

suziedaniels

relaunched www.zdnet.co.uk raises the bar yet again! its so fast it makes my eyes bleed.

eparody

Redesign complet pour ZDNet UK et AU, Twitter au centre http://www.zdnet.co.uk/ http://www.zdnet.com.au/

cdutheil

RT @eparody: Redesign complet pour ZDNet UK et AU, Twitter au centre http://www.zdnet.co.uk/ http://www.zdnet.com.au/

ABridgwater

I just joined the ZDNetUK LinkedIn group http://bit.ly/aGgPhc

gerardv

Sharepoint 2010 in photo's http://www.zdnet.co.uk/reviews/communication-and-collaboration/2010/03/04/sharepoint-2010-screenshots-40070577/

Featured white papers

Achieving PCI Compliance for:Privileged Password Management & Remote Vendor Access

For multi-store outlets, including retail, banking, grocery, gas, hospitality, convenience stores and others, reducing (or avoiding) the cost of in-store system support and maintenance while maintaining compliance with PCI and other requirements has become a strategic challenge.

Download now

Web 2.0 Security Threats: How to Protect Your Enterprise Network

Speaker: Dr. Chenxi Wang, Principal Analyst, Security and Risk Management, Forrester Research, Inc. As Enterprises are increasingly connected to the Internet and as hard organizational boundaries are fast disappearing, security professionals are facing fresh challenges in Enterprise computing.

Download now

MindManager - Tutorial for New Users - Short

This tutorial is for new MindManager users and teaches you how to get started, by creating maps, reading maps and organizing your information.

Download now