SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Security >> Alerts, Patches and Fixes

Routers dealt worm worries

Routers dealt worm worries

By:  Rosie Lombardi  On: 07 Jul 2005 For: ComputerWorld Canada Creator

How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.

How is a router worm like a flu pandemic? Medical researchers say an outbreak of influenza, similar to the devastating Spanish Flu of 1918, is likely in the near future. Somewhere in the world, a flu virus may be quietly mutating. We don’t know when the virus will emerge or the scale of the pandemic. But we do know there’s an historical precedent.

In like fashion, vulnerability researchers predict the emergence of router worms: malware designed to automatically spread from router to router like wildfire, thereby bringing down vast segments of network infrastructure. Although the idea has existed as a possibility for almost two decades, no actual instances have yet occurred.

But like the Spanish Flu, there is an historical precedent. “Going back five years, it was very rare to see exploitation of buffer overflows in the Windows platform,” says Neel Mehta, team lead of the advanced research group at Atlanta-based Internet Security Systems (ISS). “Vendors and researchers agreed it was theoretically possible but were iffy on how it could be exploited. If you look at the evolution of security, today it seems every major threat is a Windows buffer overflow.”

Researchers for security vendor McAfee Inc. have designated router worms a major future threat. “It’s now the rage to find vulnerabilities and it was easy to find them in Microsoft operating systems. Then people started going after Apple, so you’re starting to hear more about those. When they exhaust these easy things, then they’ll start going after Cisco boxes,” says Jimmy Kuo, fellow for the McAfee Anti-Virus Emergency Response Team (AVERT).

But there are economic barriers for glory-seeking hackers looking to turn the router worm vision into reality. “The devil is in the details,” says David McMahon, director of high assurance at Bell Security Solutions (BSS). “When someone does exploit development on a Windows box, they can get a hold of a typical PC and experiment. It’s a little more difficult when you’re going against a core router that’s going to cost you a significant amount of money to purchase. It’s difficult to even get access to do the homework to develop and propagate these things. It’s going to be somewhat cost-preclusive.”

When do security experts believe router worms will emerge, in spite of the costs? “It’s speculative — when something has been a potential for 20 years and hasn’t happened, it’s hard to say it’s going to happen in the next five years,” says Kuo.

However, ISS researchers have a more precise timeline. “It doesn’t look like there are going to be any ‘super-router’ threats of router worms probably for the next 24 months,” says Michael Lynn, research analyst at ISS. “There will be some architectural changes to the Cisco Internetwork Operating System (IOS) in that time frame, and we’ve discussed some of the implications of that with Cisco.”

Cisco spokespeople were unavailable for comment at press time. In the arms race between hackers and vendors, major router users like BSS believe vendors are ahead of the game. “People who manufacture these routers will have a significant advantage running penetration tests, developing exploratory exploits and exercising some of the theoretical concepts. They’re going to have much better facilities than the average hacker,” says McMahon.


Sign up for our Newsletters












Print |  Views: 1250   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Rosie Lombardi Rosie Lombardi is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

Cisco's network security supremacy under siege
Cisco's network security supremacy under siegeCisco still holds the lion's share of the global network security market but Juniper and pure-play vendors such as Fortinet, McAfee and TippingPoint are closing in fast says IDC
Microsoft, researchers spar over Windows bug
Microsoft, researchers spar over Windows bugIt was the software maker's first critical vulnerability of 2008, but the company downplayed its significance. Now, subcribers to a security mailing list are told the dangers are greater than originally thought
Feeling insecure about Vista
Feeling insecure about VistaDespite assurances from Microsoft, security vendors are wary that the software giant has not given a definite timeline for releasing code to allow third-party security software to work around the Windows Vista operating system kernel protection for 64-bit systems.
Fortinet lists August’s most dangerous online threats
two viruses disguised as security software antivirus xp 2008 and xp security center have topped fortinet’s top 10 list of august’s most reported online threats. the sunnyvale, cali
Questions about Conficker
over the weekend i was interviewed by cbc’s sunday evening news show about conficker and the possibly grim outlook for pc users everywhere on april 1. maybe not my best interview, but what bugs me now is that i was just a little too late to provide more detail on how you can tell who’s been infected.
Cisco's 1-4-7 effect
if you’re a solution provider that does deals that cost you about $150,000 and go through the rfp process, you should read this.imagine a return of $1 in advisory or consultant service, $4 for implementation and services and an additional $7 in hardware sales. that would mean deal that cost you $150,000 to set up and complete earned a net profit of more than $1 million potentially. oh a

Comments (0)

No Comments!
Name: (required) eMail: (optional)

Your email address will not appear online and will be used only if the editor wishes to contact you personally for additional comments.