R E L A T E D   C O N T E N T
ADVERTISEMENT

Bugwatch: Worm wars

Netsky and Bagle: the saga continues

David Kopp, vnunet.com 13 May 2004
ADVERTISEMENT
Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week David Kopp, head of TrendLabs Europe, considers recent developments affecting virus proliferation.

If prizes were handed out for upping the ante, then surely the latest breed of malware authors would take this year's top trophy.

They've already amassed an array of alerts from antivirus vendors and seem intent on continuing their conveyor-belt production of new viruses and variants.

In March alone, we issued six new alerts relating to worm-based viruses, showing that worms remain the number one threat to home users and corporate networks.

The majority of these warnings concentrated on two main virus sources: Netsky and Bagle. The profusion of viruses from these two sources is the product of an ongoing worm war that can be traced over a number of months.

For instance, each time a new variant of Netsky is released, a new Bagle derivative also appears. The battle is being pitched on a number of levels, including counter-insurgence operations.

Bagle, for example, is able to disable previous Netsky variants, while Netsky can neutralise previous Bagle viruses and others including MyDoom and Nachi.

It also seems apparent that the virus writers are keen to align themselves strategically.

For example, neither one exploited application vulnerabilities originally. However, as soon as Bagle did, Netsky seemed to follow suit. And the ferocity of the conflict is being amplified by changes in the arena where the cyber-battle is being fought.

One fundamental development is the growing number of users connected to the internet, and, more importantly, the number of home users connected via broadband connections.

Mass-media advertising campaigns have successfully encouraged users to seek out faster, always-on connections that facilitate quick downloads and an improved online experience.

Unfortunately, users are often unaware of the potential threats associated with this kind of connection and can therefore fail to take the appropriate steps to protect themselves.

By plugging straight into the internet without the buffer of an early warning system, home users are increasingly the target for malicious attacks and are emerging as the main vector of virus propagation.

Of course, this isn't the only development affecting virus proliferation. Money also plays its part.

Gone are the days, for example, when virus authors developed malicious code as a means of testing their technical abilities. Now many viruses attempt to steal valuable information.

Most incorporate backdoors, which enable hackers to access computers without the knowledge of the user. While inside, the uninvited guest can spread malicious code, gather email addresses for spam or pilfer credit card numbers.

While it is impossible to predict the future, it seems likely that the growing popularity of broadband connections and the apparent naivety of home users will help the continued proliferation of new viruses and prolong the bitter battle between Bagle and Netsky.

See also:

Bagle.bb joins war of the wormsMass-mailing worm spreading fast  29 Oct 2004
Broadband providers face expensive battle against attacks over coming year  28 May 2004
Lessons from SasserTeenagers must be taught responsible computing  26 May 2004
Personal use of the internet at work is leaving many firms exposed to viruses and hackers  21 May 2004
Major chipmakers now committed to Execution Protection protocols aimed at fending off viruses  18 May 2004
Sasser.ELatest variant suggests availability of virus source code, say experts  11 May 2004
Latest variant has no attachment  15 Apr 2004
SecurityThe latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack.  15 Apr 2004
Users are caught in the crossfire of the script kiddies' current spat  10 Mar 2004
MyDoom.A and Sober C lead the pack, Bagel and Netsky catching up fast  03 Mar 2004
It's cyber-handbags at dawn as worm authors turn on each other  03 Mar 2004
Infection rates soar as companies fail to update antivirus software  02 Mar 2004

All Enterprise Security Technology

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Senior C# Agile Web Developer, Online Gaming, London My Client provides adult customers with high quality gambling and gaming services in an environment that is convenient, entertaining, fair, regulated and secure. My Client is one ... more >
| Aston Carter
EMC, NetApps, West London, Media • NetApps FAS ... more >
| Abraxas
Data Analyst / MI Analyst – Leading Online Gaming Company A Data Analyst / Trafficker is sought by a leading online gaming company. The role encompasses all aspects of online advertising including data handling, communicating ... more >
| JAM Recruitment
Field Applications Engineer Power Electronics/Supplies Europe/Based Surrey Permanent Position £35-45k Basic+Bonus 10-15%+Car/Car allowance A global organisation involved with the design and development of power supplies actively requires a Field Applications Engineer to strengthen it existing ... more >
More job opportunities