Worm spread shows hole in patch system

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS

The ability of the MSBlast worm to spread has underscored the view that today's methods of patching security flaws, while necessary to lock down specific computers, are too time-consuming to react to critical vulnerabilities. The result has been that the MSBlast worm, which by most accounts is poorly programmed, has quickly propagated across the Internet.

The worm has infected at least 120,000 computers and has caused internal disruptions for many companies and Internet service providers.

The University of Florida, for instance, has had hundreds of systems infected due to a compromised PC connected to its network via a dial-up line. The incident happened despite a broad initiative by the school to lock down its systems with patches, said Jordan Wiens, a network security engineer for the university.

"It's simply not as easy (to patch) as people would like, given the resources of many small departments," Wiens said.

Microsoft confirmed that it is working with law enforcement to find the person or group who released the worm.

Microsoft has attempted to step up user education and automation to convince more consumers and enterprise customers to update their systems with the latest patch for this security flaw. However, the efforts have still left many PC users in the dark about their computer's insecurities.

The Computer Emergency Response Team (CERT) Coordination Center has found that as many as 1.4 million unique Internet addresses appear to be the sources of infections on the network. The number is likely to have been inflated by dial-up and broadband users that receive a different address every time they connect to their provider's network.

Security firm Symantec offered a more conservative number, based on its intrusion detection network. It found that more than 120,000 computers appear to have been infected in the past 36 hours.

The lesson: patching can't be relied on to keep computers secure.

"There is no one single answer," said Stephen Toulouse, security program manager at Microsoft. "We encourage defense-in-depth, but we also encourage customers to deploy the patch."

A defense-in-depth strategy calls for companies to not only secure the servers and network devices connected to the Internet, but to also secure their internal networks. In the past, a strategy of so-called perimetre security has been more common. Because holes in security are always a possibility -- and usually a given -- building redundancies into a corporate network could make the difference between a single breach and massive infection.

Patching is only one facet of a corporate security strategy and should be considered fallible as best, said Gerhard Eschelbeck, chief technology officer for vulnerability assessment firm Qualys. Only about 50 percent of Windows computers have had the patch applied in the last month, a typical half-life, a Qualys study found.

"We are already seeing the number of systems that are vulnerable on the Internet trailing down," he said.

In a study announced in July, Qualys found that half of all vulnerable systems are patched in the first month after a fix is available.

Home users typically patch their systems less often, said Jack Bates, network engineer for regional ISP BrightNet Oklahoma. He estimated that as much as 20 percent of BrightNet's user base had been infected.

"Home users do not actively keep up with Windows Update," he said. "Some are not even aware that it exists."

Instead of relying on its clients to patch their systems, BrightNet has blocked traffic to the vulnerable software addresses, or ports, and e-mail alerts will be sent to infected users. "This will require extensive man-hours from our personnel, as well as our customer's time," he said.

Intrusion detection systems have spotted PCs that the worm compromised on the networks of most major consumer Internet providers, including America Online, AT&T, Comcast, Cox Communications, SBC Communications and Verizon Communications. It's unlikely that the ISPs' systems have been infected by the worm, but a large number of clients that connect to those providers may have been compromised.

While businesses usually know of software flaws and the need to patch their systems, they don't always have time. Companies often do not patch their systems immediately, because they need time to test the fixes, said Brian Burns, manager of security operations for network device maker NetScreen.

"Microsoft patches don't receive enough QA (quality assurance) as they should," he said. "There have been times that a patch has been applied, and then the administrator has to spend hours rolling it back, because it has crashed the machine."

Microsoft has focused on providing tools for companies to further automate their management of patches. The company's Software Update Services allows companies to maintain a central service of patches internally and update systems depending on the patch's importance, a computer's level of exposure to threats on the Internet and how critical the system is.

Until companies start thinking about network security when designing their infrastructure, patching will be a difficult task, Qualys' Eschelbeck said.

"For the next four years, we are going to be stuck where we are now, because we have to pay for the sins of the past," he said.

Another problem with software patches is that they sometimes modify business applications in unexpected ways, said Rick Beers, director of supply chain technology at Corning, a manufacturing company.

That calls for a better explanation from technology makers of what might be unintended consequences of installing patches. "Other than a magic technology solution, the only solution is much more thorough documentation from the vendor," Beers said.

CNET News.com's Mike Ricciuti contributed to this report

 

Talkback

There are other solutions to prevent that your network stays vulnerable when yo have no time to patch. We developed an Intrusion Prevention System called AccessGuard (www.accessguard.nl). This product is placed in front of the network, and can detect and block intrusions from hackers and worms before they enter the network. The AccessGuard detected and blocked the first Blaster worm on the network of on of our customers in the early morning of the 9th of August. That was before the 'major alarms'. None of our customers is infected by this worm, and we had the same thing with other worms like Code Red, Nimda and Slammer.

via Facebook 13 August, 2003 12:16
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

dede0202

Hello ALL USERS OF THE PIRATE BAY I WOULD PUT AN EXPLANATION ON PIRACY Story Idea ILLIGALE AND SHARING THOSE THAT NET Dissent NOT WELL BUT TO CA...

58 minutes ago by dede0202 on The Pirate Bay infringes copyright, High Court decides
Sungwoo

do You know that? it can install 4G Ram. So i buy 4g and install It work! I can run call of duty 4,6,7 [Modern war... 1,2,3] Call of duty 1 was...

2 hours ago by Sungwoo on Loose Ends - Upgrading the Aspire One 522
itsajob

2. Bad idea. Making up patch cables loses you your commission from the cable supplier. 3. If you tidy up, other people can understand where the...

8 hours ago by itsajob on Ten IT jobs to save up for those rare lulls
Roberto_Store

Now On Sale, Unlocked iPhone 4S / Galaxy Note In Factory Box. Roberto-Techie(UK) ”Now on Sales” Smartphone, Android,Tablets,Gadget &...

11 hours ago by Roberto_Store on Samsung Galaxy S III lined up for sale
Paul Smyth

Is this classic FUD? One thing I would definitely have notice is a Mozilla threat to stop supporting GNU/Linux.

13 hours ago by Paul Smyth via Facebook on Firefox rapid release improves Fedora Linux
UnderINK

I agree with the previous commenter wholeheartedly. I couldn't say it better myself. This is very 'Big Brother'. And while I agree with protecting...

17 hours ago by UnderINK on European e-identity plan to be unveiled this month
Simon Bisson and Mary Branscombe

Nice to see that Turing's idea of a general purpose computer doing once-hardware-powered tasks in software is now universal ;-) Mary

23 hours ago by Simon Bisson and Mary Branscombe on Software with everything
Jason Burchell

seriously now. I've only bothered to read a small bit of the comments. do me and the rest of the world a favour. stop saying it does not work or...

1 day ago by Jason Burchell via Facebook on Music industry negotiating over 24-bit downloads
Philip Charles Cohen

Read about it and weep, John Donahoe ... In addition to Visa’s V.me, there is now MasterCard’s PayPass digital wallet soon to arrive; another...

1 day ago by Philip Charles Cohen via Facebook on PayPal takes phone-based payments to the high street
apexwm

Leslie Satenstein : Where have you ever seen Mozilla even mention this? Firefox is the most popular browser in the GNU/Linux OS, so I don't see...

1 day ago by apexwm on Firefox rapid release improves Fedora Linux
songmaster

SHleG: Do you remember building a clockwork scorpion kit (I'm pretty sure I have a photo of it somewhere) — I think it was called something like...

1 day ago by songmaster on Software with everything
Chris Wortman

Good I love Yahoo! Their search engine is getting better than Google as of late. I find more of what I want on the first page, and usually within...

1 day ago by Chris Wortman via Facebook on Linux Mint 13 ramps up for KDE release
PatrickG

openhgs has made the point for Windows 8 multiple monitors without realising it! With Windows 7 you have to switch the mouse and so your focus...

1 day ago by PatrickG on Windows 8 could speed multi-monitor uptake
Leslie Satenstein

Mozilla has threatened to stop supporting Linux. I guess that UBUNTU is going with another browser. I indicated that if Mozilla stops supporting...

2 days ago by Leslie Satenstein via Facebook on Firefox rapid release improves Fedora Linux
Andy Bolstridge

Much as I abhor Microsoft's licensing practices, this is almost certainly down to purchasing IT equipment via 3rd party consultants - you get the...

2 days ago by Andy Bolstridge via Facebook on 6 million wasted licences and £1,200 PCs: welcome to government IT
Jack Schofield

@openhgs Windows users have had multiple desktops since Linus started writing Linux. They just haven't shipped as standard because not enough...

2 days ago by Jack Schofield on Windows 8 could speed multi-monitor uptake
Jack Schofield

@Phil at Cloud4 What, Microsoft gets £1,200 per PC and £1,622 per server? Gosh, I'm amazed....

2 days ago by Jack Schofield on 6 million wasted licences and £1,200 PCs: welcome to government IT
craigsc

You guys have no idea what is going on at Autonomy. Autonomy could have been a much more profitable organization. The sales operations at Autonomy...

2 days ago by craigsc on HP cuts 27,000 staff as Autonomy chief Lynch leaves
Moley

How does this impact on dual or multi booting? Seems to me to more or less prohibit this, from Windows 8 anyway. Will Grub 2 recognise Windows 8,...

2 days ago by Moley on Windows 8 start-up speed forces USB boot workaround
apexwm

I don't understand why there cannot be a slight pause during the boot process so the user can press a key. Many operating systems do this, even if...

2 days ago by apexwm on Windows 8 start-up speed forces USB boot workaround