Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
ComputerWorldNetwork WorldCIO CanadaCIO Canada Governments' ReviewJobUniverse Canada
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Unlock the potential of data with the right data warehouse solutionUnlock the potential of data with the right data warehouse solution read more
IBM Multiform Master Data Management: The evolution of MDM applicationsIBM Multiform Master Data Management: The evolution of MDM applications read more
Closing the data privacy gap: Protecting sensitive data in non-production environmentsClosing the data privacy gap: Protecting sensitive data in non-production environments read more
Yuk it Up
Act to Amend the Copyright Act
Want a copyright law that protects spyware and virus writers? If not, sign our petition to amend Bill C-61
Featured IT Quiz
IT Quiz: Test yourself to see if you have the knowledge to fit into the open source world, and compare yourself with the rest of the respondents
Featured White Papers
This white paper details Intel's current and future energy-saving initiatives to reduce costs and support business goals. Learn how Intel IT is extending its efforts to be a role model enterprise IT organization by supporting the Climate Savers Computing Initiative, which aims to drive a 50 percent reduction in computer-related CO2 emissions worldwide. No registration required.

Sign-Up for
Enterprise Infrastructure
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Routers dealt worm worries

Virus writers looking to attack the source in next malicious effort

How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.

In like fashion, vulnerability researchers predict the emergence of router worms: malware designed to automatically spread from router to router like wildfire, thereby bringing down vast segments of network infrastructure. Although the idea has existed as a possibility for almost two decades, no actual instances have yet occurred.

But like the Spanish Flu, there is an historical precedent. “Going back five years, it was very rare to see exploitation of buffer overflows in the Windows platform,” says Neel Mehta, team lead of the advanced research group at Atlanta-based Internet Security Systems (ISS). “Vendors and researchers agreed it was theoretically possible but were iffy on how it could be exploited. If you look at the evolution of security, today it seems every major threat is a Windows buffer overflow.”

Researchers for security vendor McAfee Inc. have designated router worms a major future threat. “It’s now the rage to find vulnerabilities and it was easy to find them in Microsoft operating systems. Then people started going after Apple, so you’re starting to hear more about those. When they exhaust these easy things, then they’ll start going after Cisco boxes,” says Jimmy Kuo, fellow for the McAfee Anti-Virus Emergency Response Team (AVERT).

But there are economic barriers for glory-seeking hackers looking to turn the router worm vision into reality. “The devil is in the details,” says David McMahon, director of high assurance at Bell Security Solutions (BSS). “When someone does exploit development on a Windows box, they can get a hold of a typical PC and experiment. It’s a little more difficult when you’re going against a core router that’s going to cost you a significant amount of money to purchase. It’s difficult to even get access to do the homework to develop and propagate these things. It’s going to be somewhat cost-preclusive.”

When do security experts believe router worms will emerge, in spite of the costs? “It’s speculative — when something has been a potential for 20 years and hasn’t happened, it’s hard to say it’s going to happen in the next five years,” says Kuo.

However, ISS researchers have a more precise timeline. “It doesn’t look like there are going to be any ‘super-router’ threats of router worms probably for the next 24 months,” says Michael Lynn, research analyst at ISS. “There will be some architectural changes to the Cisco Internetwork Operating System (IOS) in that time frame, and we’ve discussed some of the implications of that with Cisco.”

Cisco spokespeople were unavailable for comment at press time. In the arms race between hackers and vendors, major router users like BSS believe vendors are ahead of the game. “People who manufacture these routers will have a significant advantage running penetration tests, developing exploratory exploits and exercising some of the theoretical concepts. They’re going to have much better facilities than the average hacker,” says McMahon.

If and when router worms emerge, their effects could be devastating. “All the worms we see right now, they’re attacking network end-points such as desktops and servers. But a router worm would compromise the infrastructure in between,” says Thomas Akin, incident response manager at ISS and author of Hardening Cisco Routers. “If one were created that targeted Cisco, it could have a real effect on the stability of wide area networks.”

But ISS researchers believe the knowledge needed to create a router worm is still too specialized and confined to a very small group. “It’s become apparent routers are exploitable, and as changes are made to operating systems, they will become more exploitable. Looking forward, we do see it as a major concern but at the moment, there isn’t enough information out there publicly to make it a threat today. You’re going to see individuals attack routers long before you see router worms,” says Akin.

How should the perplexed network manager prepare to deal with a threat that may or may not materialize, perhaps in two years, perhaps five? Firstly, an attitude change is needed. “Many system administrators think of routers as a VCR or toaster, but they need to start thinking of it as a computer because it can be attacked in the same way as a computer can be,” says Lynn.

Good network hygiene is needed too. “If people want to protect themselves against router attacks, it comes down to paying the same attention to routers as their Windows system.

The two key things are patching them and monitoring the router’s configuration for changes,” says Akin. “Ideally, that process should be automated, but if not, administrators should do it manually once a month or quarterly.”

QuickLink 055213

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Events

Book Reviews

Technology Moment podcasts
IDC Case Study: Identity And Access Management Buying Criteria.
IDC analyses IAM buying criteria and deployment at Coppin State University. Coppin State replaces "first generation" IAM solution to obtain benefits needed for today's agile enterprise: ease of integration, rapid deployment, simplified compliance, flexibility.
White Papers
Closing the data privacy gap: Protecting sensitive data in non-production environments
How can IT organizations protect sensitive data, including employee and customer information, as well as corporate confidential data and intellectual property? Industry analysts recommend "de-identifying" or masking data as a best practice for protecting privacy. This white paper explains the importance of closing the data privacy gap in non-production environments, and provides guidance on effective data masking. Complimentary with registration. Sponsored by IBM.
E-mail a Friend
Unlock the potential of data with the right data warehouse solution
Once you've made the decision to implement a new data warehouse, you want to make sure you choose the one that's right for your organization. This buyer's guide provides checklists for starting points that you can use when evaluating vendors and their products. Complimentary with registration. Sponsored by IBM.
E-mail a Friend
Prepare for a more efficient SAP implementation: Take data issues off the critical path
This white paper outlines how the Preliminary Data Assessment Appliance (PDAA) from IBM can help address the challenges of integrating data from different operational applications across the enterprise to an SAP platform. Complimentary with registration. Sponsored by IBM.
E-mail a Friend