R E L A T E D   C O N T E N T
ADVERTISEMENT

Bugwatch: The new nasties

Adapting security policies to cover all threats

Luis Corrons, vnunet.com 05 May 2004
ADVERTISEMENT
Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week Luis Corrons, head of PandaLabs, warns of the added workload that IT departments face from new forms of malware.

It seems that 2004 is becoming the year of 'other' malware, not just viruses and worms.

This is not to say that there have been, or will be, fewer viruses or epidemics. Rather that new threats such as diallers, spyware or spam are adding to the security workload. And these threats must be taken into account when designing security policies.

Viruses will no doubt continue to appear, possibly even more than before. But the increased presence of other malware means that good antivirus defence on its own is no longer enough. Users also need to have specific tools for specific threats.

The reason for the increase in new malware is purely financial. Many unscrupulous users have realised, for instance, the money-making potential of installing diallers. They can reconnect modem users to premium-rate phone numbers, steal bank or credit card details or sell databases to dubious marketing companies.

Spam is likely to continue causing misery. Not only is a huge amount of time wasted reading and deleting it, junk mail carries the risk of being used as a means of propagation for viruses and other malicious code.

Hacker attacks are also on the increase, facilitated by the rise in backdoor Trojans and hacking tools in recent months.

And virus creators are continuing their quest to uncover vulnerabilities in popular software to spread their creations as widely as possible. This is a strategy that has been increasing in popularity, often with devastating results.

Since January, when MyDoom appeared, we have seen a number of new worms, most notably all the variants of Netsky and Bagle. A new kind of computer virus epidemic has emerged.

The culprit in this case is not just one virus but a variety of malicious code, launched from the internet at the same time, making the probability of a computer being infected extremely high.

The reason for this change in virus writers' strategy is easy to understand, considering that antivirus companies are developing vaccines to combat new viruses very shortly after detection and, in some cases, offering specific tools to eliminate them.

It is easy to see that if many viruses appear over a short period of time, there is a far greater probability of being infected by one of them. Under these conditions, the hundreds of infected email messages reaching inboxes makes users more likely to run one of these malicious programs.

Even a slight delay in updating antivirus protection, or simply downloading an infected file from a peer-to-peer network, can considerably increase the probability of falling victim to infection.

Under these circumstances, a virus may start off with a bang, infecting a large number of computers over a short space of time. But as users can now rapidly and easily detect and eliminate them, their lifespan is cut short.

The time when a virus could hang around for years is now in the past, leaving those responsible for malicious software to look for other avenues.

See also:

SpywareAn increasing number of web users are inadvertently downloading software which can trap ID and password information for online bank accounts.  22 Sep 2004
Virus writers turn to spamVirus writers cash in with latest breed of email threat  17 Aug 2004
Spyware and TrojansSurvey of 650,000 consumer PCs found 18 million instances of spyware  16 Jun 2004
Lessons from SasserTeenagers must be taught responsible computing  26 May 2004
Internet worms'Dark forecast' as Windows users warned of new family of viruses  04 May 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
Take cover - here comes another MyDoom/Netsky/Bagle variant ...  17 Mar 2004
Research coincides with new virus outbreak  03 Mar 2004

All Hacking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
Reading, Berkshire, United Kingdom | EDS
Position # 395368 Position - Trials Engineer Location - Reading Position Details: The Trials team are responsible for the planning of all Trials activities with the client to Validate the DII(F) fixed solution (i.e. permanent ... more >
Reading, Berkshire, United Kingdom | EDS
System Integrator - Applications Hosting Location - Reading Job Description: A skilled System Integrator to integrate Microsoft based applications to support business requirements. The Candidate will possess specific experience of enterprise systems, component validation and ... more >
London, United Kingdom | Royal Borough of Kensington and Chelsea
Web Content Manager - c.£40,000 plus bonus - London   As one of the country's best-performing councils, we're always looking for new ways to improve on excellence. Providing an innovative, high-quality internet site for our ... more >
Aylesbury, Buckinghamshire, United Kingdom | Grass Roots
Business Analyst - £35,000 - £50,000 + benefits - Aylesbury    Grass Roots are one of the Sunday Times Top 100 companies to work for (2007 and 2008). Established in 1980, we're part of the ... more >
More job opportunities