Home >> Security >> Alerts, Patches and Fixes

Routers dealt worm worries

Routers dealt worm worries By:  Rosie Lombardi On: 07 Jul 2005 For: ComputerWorld Canada Creator

How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.



Email a friend   |  









Print   |   Text + / -   |  Add a Comment   |   Views: 358   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.

In like fashion, vulnerability researchers predict the emergence of router worms: malware designed to automatically spread from router to router like wildfire, thereby bringing down vast segments of network infrastructure. Although the idea has existed as a possibility for almost two decades, no actual instances have yet occurred.

But like the Spanish Flu, there is an historical precedent. “Going back five years, it was very rare to see exploitation of buffer overflows in the Windows platform,” says Neel Mehta, team lead of the advanced research group at Atlanta-based Internet Security Systems (ISS). “Vendors and researchers agreed it was theoretically possible but were iffy on how it could be exploited. If you look at the evolution of security, today it seems every major threat is a Windows buffer overflow.”

Researchers for security vendor McAfee Inc. have designated router worms a major future threat. “It’s now the rage to find vulnerabilities and it was easy to find them in Microsoft operating systems. Then people started going after Apple, so you’re starting to hear more about those. When they exhaust these easy things, then they’ll start going after Cisco boxes,” says Jimmy Kuo, fellow for the McAfee Anti-Virus Emergency Response Team (AVERT).

But there are economic barriers for glory-seeking hackers looking to turn the router worm vision into reality. “The devil is in the details,” says David McMahon, director of high assurance at Bell Security Solutions (BSS). “When someone does exploit development on a Windows box, they can get a hold of a typical PC and experiment. It’s a little more difficult when you’re going against a core router that’s going to cost you a significant amount of money to purchase. It’s difficult to even get access to do the homework to develop and propagate these things. It’s going to be somewhat cost-preclusive.”

When do security experts believe router worms will emerge, in spite of the costs? “It’s speculative — when something has been a potential for 20 years and hasn’t happened, it’s hard to say it’s going to happen in the next five years,” says Kuo.

However, ISS researchers have a more precise timeline. “It doesn’t look like there are going to be any ‘super-router’ threats of router worms probably for the next 24 months,” says Michael Lynn, research analyst at ISS. “There will be some architectural changes to the Cisco Internetwork Operating System (IOS) in that time frame, and we’ve discussed some of the implications of that with Cisco.”

Cisco spokespeople were unavailable for comment at press time. In the arms race between hackers and vendors, major router users like BSS believe vendors are ahead of the game. “People who manufacture these routers will have a significant advantage running penetration tests, developing exploratory exploits and exercising some of the theoretical concepts. They’re going to have much better facilities than the average hacker,” says McMahon.


Sign up for our Newsletters
Rosie Lombardi Rosie Lombardi is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Articles

Related Blogs

Comments (0)

No Comments!
You are currently not logged in: Register | Login

You must be logged in to submit a comment.