- Recommend:
- 0 Comments
Worry About the Worm
Cousins to computer viruses, worms can cause more problems.
Defense Against the Worm
Computers and networks were once based largely on proprietary hardware and software, which made it difficult to create a one-size-fits-all worm. The rise of a homogeneous computing infrastructure has led to a proliferation of worms, Trilling said.
So many people and companies are standardizing on the same software and hardware, one worm can infect many systems, he said. With today's powerful software and hardware, just about any miscreant can create and test a worm, and the rise of the Internet makes it all too easy to spread it.
By January 2001, experts predict there will be 300 million Internet users, and if they're all using basically the same types of systems and software, one worm can reach them all, he said.
And just wait until more home users get broadband, he said. Most threats today hit corporations because of their always-on connections. Individuals become more vulnerable when they're connected fulltime.
Traditional virus-fighting methods can't cope with worms, Trilling said. Antivirus companies such as Symantec and its competitors will have to react much faster and work more proactively, he said. Today Symantec can respond to a new virus within 48-hours, which is plenty of time. But it won't be fast enough when new worms begin appearing daily.
An effective firewall can help defend against worms. But Trilling said antivirus vendors need to create a more automated system to create and deploy fixes faster, he said, Human beings don't operate at the speed of the Internet. The need will be to spread a cure at a faster rate than the threat moves.
And what if villainous programmers begin pumping out worms every 10 seconds? Traditional software can't handle it, he said. Corporations and users will have to stop using programs with macros, they'll have to strip executable content at the Internet gateway, before it reaches the computers.
Two new technologies could help to fight worms, too. Digital immune systems will automatically detect suspicious behavior and automatically forward samples to a company like Symantec. The company replicates the infection, creates and tests a cure, and ships it to subscribers automatically. The approach can work, but it's still reactive, he said.
A more future-looking technology is called behavior blocking. It looks at the operating system and watches what a program is doing. If a program acts weird--such as deleting files it didn't create--it can flag it as malicious. Today this approach is still prone to too many false positives, but down the road it will be more viable, he said.
Regardless of what method proves best, it's time people and companies started thinking about the worm problem more seriously, he said. It might not be a 15-year-old that launches the next one: It could be someone intent on causing more serious damage.
- « Prev
- Page 2 of 2
Would you recommend this story? YES NO
- Recommend:
- 0 Comments
-
ThinkPad Edge E420 Lenovo Style in an Affordable Package
Buy now direct from Lenovo -
ThinkPad X220 Fast and light, with great input ergonomics and battery life, this powerhouse ultraportable is best-of-breed.
Buy now direct from Lenovo -
ThinkPad X120e One of the best netbooks ever, X120e has the best netbook keyboard ever--nothing else comes close
Buy now direct from Lenovo
- 12 Criteria for Selecting the Best ERP System Replacement An ERP system is your information backbone and reaches into all areas of your business and value chain. Replacing it can open unlimited business opportunities. This white paper explains the 12 criteria that allow you to identify and select the solution that will meet these expectations.
- Leveraging Social Computing Technologies for ERP Applications This white paper details how Web 2.0 technologies support business strategies by improving efficiency, productivity, and collaboration.


















