Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
Computerworld Publication PageNetworkWorld Publication PageCIO Canada Publication PageITJobUniverse.ca
- The Information, Communication and Technology (ICT) Job Board
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network"Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network" read more
From fear to value: CIO strategies for propelling business through the economic crisisFrom fear to value: CIO strategies for propelling business through the economic crisis read more
Reaping the rewards of your service-oriented architecture infrastructureReaping the rewards of your service-oriented architecture infrastructure read more
Yuk it Up
Featured White Papers
Download the Network Barometer Report, which aggregates findings from secure network infrastructure assessments conducted for more than 150 organisations around the world. It provides some surprising stats on the state of network (un)readiness prevalent today; the reasons why organisations are failing at remediating known vulnerabilities; recommendations on assessing your own infrastructure, and on ways to improve your state of readiness to support the business; and more.
Early-generation server load-balancing technology has proven to be an invaluable asset, especially for organizations hosting widely utilized Web applications. But business requirements evolve, as do the processes and technologies used to fulfill them. The many changes and trends that have taken hold since SLBs were first introduced expose the need for enterprises to step up from a simple load-balancing solution to a more comprehensive application delivery solution . This paper is intended to serve as a guide for organizations looking to replace their early-generation SLBs, providing details on the top eight criteria to use during an evaluation process.
Featured Spotlight
Keep up on who's hiring, who's downsizing and how the government is helping. News, job opportunities, recruiters and employment lawyers are all available.
Sign-Up for
Enterprise Infrastructure
eNewsletter Delivered Weekly
Click here
Page 1 of 1

Digg it Twitter

Routers dealt worm worries

Virus writers looking to attack the source in next malicious effort

How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.

In like fashion, vulnerability researchers predict the emergence of router worms: malware designed to automatically spread from router to router like wildfire, thereby bringing down vast segments of network infrastructure. Although the idea has existed as a possibility for almost two decades, no actual instances have yet occurred.

But like the Spanish Flu, there is an historical precedent. “Going back five years, it was very rare to see exploitation of buffer overflows in the Windows platform,” says Neel Mehta, team lead of the advanced research group at Atlanta-based Internet Security Systems (ISS). “Vendors and researchers agreed it was theoretically possible but were iffy on how it could be exploited. If you look at the evolution of security, today it seems every major threat is a Windows buffer overflow.”

Researchers for security vendor McAfee Inc. have designated router worms a major future threat. “It’s now the rage to find vulnerabilities and it was easy to find them in Microsoft operating systems. Then people started going after Apple, so you’re starting to hear more about those. When they exhaust these easy things, then they’ll start going after Cisco boxes,” says Jimmy Kuo, fellow for the McAfee Anti-Virus Emergency Response Team (AVERT).

But there are economic barriers for glory-seeking hackers looking to turn the router worm vision into reality. “The devil is in the details,” says David McMahon, director of high assurance at Bell Security Solutions (BSS). “When someone does exploit development on a Windows box, they can get a hold of a typical PC and experiment. It’s a little more difficult when you’re going against a core router that’s going to cost you a significant amount of money to purchase. It’s difficult to even get access to do the homework to develop and propagate these things. It’s going to be somewhat cost-preclusive.”

When do security experts believe router worms will emerge, in spite of the costs? “It’s speculative — when something has been a potential for 20 years and hasn’t happened, it’s hard to say it’s going to happen in the next five years,” says Kuo.

However, ISS researchers have a more precise timeline. “It doesn’t look like there are going to be any ‘super-router’ threats of router worms probably for the next 24 months,” says Michael Lynn, research analyst at ISS. “There will be some architectural changes to the Cisco Internetwork Operating System (IOS) in that time frame, and we’ve discussed some of the implications of that with Cisco.”

Cisco spokespeople were unavailable for comment at press time. In the arms race between hackers and vendors, major router users like BSS believe vendors are ahead of the game. “People who manufacture these routers will have a significant advantage running penetration tests, developing exploratory exploits and exercising some of the theoretical concepts. They’re going to have much better facilities than the average hacker,” says McMahon.

If and when router worms emerge, their effects could be devastating. “All the worms we see right now, they’re attacking network end-points such as desktops and servers. But a router worm would compromise the infrastructure in between,” says Thomas Akin, incident response manager at ISS and author of Hardening Cisco Routers. “If one were created that targeted Cisco, it could have a real effect on the stability of wide area networks.”

But ISS researchers believe the knowledge needed to create a router worm is still too specialized and confined to a very small group. “It’s become apparent routers are exploitable, and as changes are made to operating systems, they will become more exploitable. Looking forward, we do see it as a major concern but at the moment, there isn’t enough information out there publicly to make it a threat today. You’re going to see individuals attack routers long before you see router worms,” says Akin.

How should the perplexed network manager prepare to deal with a threat that may or may not materialize, perhaps in two years, perhaps five? Firstly, an attitude change is needed. “Many system administrators think of routers as a VCR or toaster, but they need to start thinking of it as a computer because it can be attacked in the same way as a computer can be,” says Lynn.

Good network hygiene is needed too. “If people want to protect themselves against router attacks, it comes down to paying the same attention to routers as their Windows system.

The two key things are patching them and monitoring the router’s configuration for changes,” says Akin. “Ideally, that process should be automated, but if not, administrators should do it manually once a month or quarterly.”

QuickLink 055213

Page 1 of 1
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

Events

Book Reviews

Featured Content
Improving business through smart energy and environment policy
Businesses and public entities today face increasing pressure to develop policies that are both good for the planet and good for business. A framework developed by IBM offers businesses and other organizations a comprehensive approach to energy and environmental issues. The framework helps identify and prioritize environmental efforts by breaking down problems and opportunities into seven distinct business areas, which can then be segmented into manageable projects.
E-mail a Friend