R E L A T E D   C O N T E N T
ADVERTISEMENT

Bugwatch: The virus avalanche

Take cover - here comes another MyDoom/Netsky/Bagle variant ...

Jack Clark, vnunet.com 17 Mar 2004
ADVERTISEMENT
Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week Jack Clark, technical consultant at McAfee Security, considers the deluge of recent virus activity and how security firms and users can protect themselves from further attacks.

The last eight weeks have been among the busiest the antivirus community has ever experienced. Between them MyDoom, Netsky and Bagle have eclipsed the volume of virus activity we saw in the whole of 2003.

But what has started this sudden virus avalanche?

At the last count there were eight versions of MyDoom, 14 versions of Netsky and 16 versions of Bagle in existence. Although it's not uncommon to see a large number of variants appear after an initial outbreak, it is unheard of for so many to appear in such a short time.

Initial thoughts are that the growing number of virus creation kits currently available on the internet could be accounting for this rush of variants. These automated kits allow computer users with few technical skills to alter the code of viruses and release new variants into the wild.

A second explanation is that virus writers are looking to stay one step ahead of antivirus vendors with each new variant released. While we might expect any savvy virus writer to disappear after writing a virus for fear of detection by the authorities, this new breed appears to be revelling in the challenge of outwitting the security companies.

For example, could each, relatively minor, modification to the Bagle virus be down to the author altering his code just enough to stay ahead of those organisations working to prevent damaging outbreaks?

Is the writer releasing a new version every time a vendor adds detection for the current variant? If so, it's an intriguing game of cat and mouse and something we rarely see from writers nowadays - especially with the increasing number of custodial sentences being handed out for internet crimes.

Even more intriguing than the ongoing battle between vendor and virus author is the suggestion that the real battle is between the authors themselves. Could the huge amount of virus activity be caused by rivalry between warring virus-writing factions?

There is certainly evidence that the Netsky and Bagle writers competed against each other, using messages hidden in the virus code to trade insults. As a Bagle variant appeared with a hidden taunt or insult, so a new version of Netsky would follow with a response.

The suggestion from some corners of the antivirus community is that Bagle's creators have become jealous of the media attention Netsky has generated - and possibly incensed by the fact that part of Netsky's payload is to remove both Bagle and MyDoom.

To further escalate the feud the most recent MyDoom variant has included comments insulting Netsky.

It's likely that a combination of all these factors explains the unprecedented volume of virus activity since the New Year. But when can we expect it to end?

In addition to the number of attacks we've seen, the writers are also finding new ways to bypass perimeter defences. Using a password-protected Zip file to hide the Bagle virus, in particular, has demonstrated that authors are increasingly thinking about how they can penetrate the network.

With many antivirus packages failing to scan these encrypted files, assuming the user is foolish enough to open an unsolicited message then the attack will be successful. Desktop antivirus protection consequently becomes extremely important.

To keep networks safe from this current wave of attacks, users and administrators need to follow the same golden rules that vendors have been trying to get across for years: regular antivirus updates, multi-layered protection, heuristic and generic detection to stop unknown attacks and, above all, education.

Employees need to use their common sense about whether or not a file looks legitimate. If you're not expecting it, don't open it.

Only time will tell whether we've seen the last of Bagle, Netsky and MyDoom, or whether we can expect more of the alphabet to be consumed as further variants appear.

2004 has already been one of the most frantic years since viruses first emerged, with vendors and businesses battling to stay one step ahead of the writers and keep their networks secure.

And there's still work to be done if vendors are to stop this particular avalanche.

See also:

Bagle.bb joins war of the wormsMass-mailing worm spreading fast  29 Oct 2004
UK losing the battleIT managers blame lack of funds to defend against rising tide of attacks  09 Sep 2004
August virus chartsNetsky, Bagle and Mydoom variants still topping the virus charts  02 Sep 2004
Virus writers turn to spamVirus writers cash in with latest breed of email threat  17 Aug 2004
Lovgate and Bagle virusesSecurity experts increase risk assessment as latest worms begin to spread  06 Jul 2004
Adapting security policies to cover all threats  05 May 2004
Internet worms'Dark forecast' as Windows users warned of new family of viruses  04 May 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
No-one can afford to skimp on antivirus tools. Computing guides you through the options.  15 Apr 2004
'Torrent' of Netsky and Bagle variants released in war of the worm writers  02 Apr 2004
Latest strain launches Hearts card game if executed  29 Mar 2004
Users are caught in the crossfire of the script kiddies' current spat  10 Mar 2004
VirusNetsky and Bagel variants continue to spring up, but virus writers' slanging match cools down  09 Mar 2004
Virus creation kits blamed as new variants Netsky.D and Bagel.G appear  01 Mar 2004
We all know how much havoc a virus can cause, but what's the real cost to home and business users when this malicious code infects our PCs?  06 Jan 2004
Part 1 of our feature looks at the history of computer viruses, and what we can expect in the future.  06 Jan 2004
McAfee VirusScan 2004The latest version of this well known anti-virus software.  17 Dec 2003

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities