Computer Virus Writers Moving Faster with Attacks
Posted on: Wednesday, 17 August 2005, 15:00 CDT
SAN FRANCISCO -- U.S. media companies and other corporations hit by a wave of computer viruses this week said business was back to normal on Wednesday, but analysts warned the attacks showed hackers have gained a dangerous advantage in speed in the battle over network security.
ABC news writers resorted to typewriters to prepare copy for the "World News Tonight" broadcast on Tuesday, as the network and other media companies, including The New York Times, reported disruptions. CNN broke into programing with descriptions of its problems.
"Our systems are now working and our Web site is updated," said Jeffrey Schneider, a spokesman at ABC.
Although damage was seen limited to several thousand computers, security analysts said the events showed malicious code writers are accelerating the development of viruses as soon as weaknesses become apparent.
"These guys have gotten a lot faster ... they are doing it faster than managers can keep up with," said F-Secure virus researcher Ero Carrera.
That sets up a race between technology managers who must update their systems and virus writers aiming to exploit holes before they are "patched" to fix a vulnerability.
Vincent Gullotto, vice president of the anti-virus emergency response team at McAfee Inc., estimated that thousands of machines were affected by viruses in recent days, including two called "IRCBOT.WORM" and "RBOT.CBQ."
The viruses exploited recently discovered flaws in Microsoft Corp.'s Windows 2000 operating system, causing thousands of personal computers to restart repeatedly.
The viruses also potentially exposed computers to attackers who could take control of a system, launch future virus attacks and potentially glean personal data without a user's knowledge.
Symantec Corp. put the threat of the medley of viruses at an "elevated threat" of "2" on a scale where "4" is the most severe virus-threat level, according to Alfred Huger, Symantec's senior director of engineering.
SPEED OF THREATS QUICKENS
Microsoft warned users last week of three "critical" security flaws in its software and urged users to update the software on their personal computers with "patches" to prevent them from being infected -- and within a few days, code writers had written and released viruses to exploit the flaws.
A few years ago, it would have been several weeks or months -- not days -- before a virus was released to exploit flaws in Windows, analysts said.
The Slammer worm, which came in January 2003 and was estimated to have caused hundreds of millions of dollars in damages, appeared several months after Microsoft released a patch for a vulnerability.
Just as problematic is that computer systems' protection programs are often updated more slowly than the speed of virus writers' ability to release viruses.
Malicious code writers also are starting to piggy-back on the grassroots popularity of instant messaging (IM) among office workers to deliver viruses, though the use of IM to spread viruses in recent days had not yet been established, some analysts said.
"We have seen increased used of IM (to spread viruses), but we don't believe believe any of these viruses were spread by IM," Symantec's Huger said.
Source: REUTERS/By Spencer Swartz
Related Articles
- SMIC Releases Presentation Materials from its "Analyst Day" Held on September 15, 2009
- AFGE Issues Statement Following Preview of Defense Business Board's Recommendations on National Security Personnel System
- Dot Hill to Hold Analyst Day Event at the NASDAQ MarketSite
- Orb Networks Unveils MyCasting 2.0, Turning Your Home Computer Into a Personal Broadcasting System
- Focus Enhancements to Demonstrate TALARIA(TM) Ultra Wideband Technology at Analyst Days in New York and San Francisco
- Silicon Image Holds First Annual Investor/Analyst Day
- Equinix to Host First Investor Analyst Day on May 17th in New York City
- Online Resources Provides Analyst Day Highlights
- NitroMed to Host BiDil Launch Overview Analyst Day and Webcast July 15
- Antelope Technologies and Secure Communication Systems Announce Production of Tough Hand-held Shell for the Modular Computing Core
User Comments (0)

RSS Feeds