Monday | 13 October, 2008
CIO
Ever-evolving Malware Is Getting Nastier
For the past seven years, the most frequent way that people got infected with malware was by clicking malicious file attachments or rogue embedded Web links
Roger A. Grimes (InfoWorld) 04 June, 2007 12:34:20

Related Stories
  • +

    Adobe launches hosted services, adds Flash to Acrobat 03 June, 2008 09:02:44

    Adobe to launch Web site offering users free hosted services for document creation, sharing and storage
    Adobe this week is set to unveil the next version of its Adobe Acrobat software, which adds support for the company's Flash multimedia technology. The company also plans to launch a new Web site offering users free hosted services for document creation, sharing and storage.
  • +

    Can Macs conquer the enterprise? 11 January, 2008 10:55:53

    The field is wide open for a Macintosh insurrection on the business desktop. It could happen, but probably won't. Here's why.
    If Apple were a football team, the New England Patriots would have had some serious competition this year.
  • +

    10 things we hate about laptops 16 November, 2007 12:40:09

    Sure, laptops have revolutionized the way we compute. That doesn't mean they don't drive IT bonkers.
    Damaged. Lost. Stolen. Too big, too small. Insecure and unreliable. And just plain annoying. If you're in IT, there's just not much to like about laptops.
Additional Resources
Executive Guides
Whitepapers

Newsletter Subscription

Sign up for our CIO newsletters!
Weekly coverage of the issues that impact corporate and government information
RSS Feeds

Malware evolves in trends. Yesterday's boot virus is today's Web server exploit program. Malware follows popularity, and it morphs to get past ubiquitous defences. Understanding the growing trends in malware will help you plan better defences.

A little history first: When I began fighting hackers and malware in the second half of the 1980s, Apple viruses ruled the land. I always laugh when I hear that malware can't attack Apple PCs - for my first two years on the job, it was the only place I could find them. It's not like Apple's OS X is super-impervious to malware today; more than 100 vulnerabilities were patched in OS X last year, and there are already over 100 this year.

When the IBM PC and DOS replaced Apple as the dominant personal computing platform, DOS boot and file viruses quickly took over. Interestingly, even though boot viruses accounted for less than 5 percent of virus types, they were responsible for more than 80 percent of the infections. This was due to two reasons. First, although there were many worldwide communication networks (FIDOnet, BBS, and so on), they were not nearly as popular as today's Internet. Second, back in the day, most computer users copied each other's pirated software by copying complete disks. Stacks of floppy disks gave boot viruses a sizeable infection point.

SQL Slammer set the bar for rapid infections by infecting nearly every vulnerable SQL server in about 10 minutes. Most people don't remember that the vulnerability Slammer exploited had been patched for six months

March 1992 was the climax of boot virus awareness due to the Michelangelo virus scare. I remember the date vividly, because thanks to Michelangelo, I got into Newsweek magazine. Some people discount the Michelangelo virus as nothing but media hype, but millions of computers were infected. Even after weeks of headline warnings, hundreds of thousands of people had their computer hard drives reformatted on the day Michelangelo's payload went off.

In 1995, macro viruses took off. Looking back, I wish macro viruses were all we had to worry about. The years of 1999 and 2000 were the years of e-mail malware, such as Melissa and the Iloveyou incident. Remote-access Trojans, such as Back Orifice and NetBus, also appeared on the scene. Code Red and Nimda hit in 2001, with SQL Slammer and Blaster in 2003.

SQL Slammer set the bar for rapid infections by infecting nearly every vulnerable SQL server in about 10 minutes. Most people don't remember that the vulnerability Slammer exploited had been patched for six months.

Up to this point, malicious infections were mostly easy to clean up: Remove the malware, replace any maligned files or data, and the damage was fixed.

That all changed in 2003 with the release of worms (such as Sobig, Mydoom, Bagle, Netsky) built specifically to spread spam (as spam bots). Created because e-mail administrators were closing off all open e-mail relays, spam bots introduced professional criminals to malware in a big way. Within a few years, criminally motivated, money-stealing, identity-thieving bots made up 99 percent of all malware. Today, you don't have to ask why you are getting infected - it's an easy answer. They are trying to take your money.

This brings us to the current state of malware. Google recently released a paper entitled "The Ghost in the Browser: Analysis of Web-based Malware." Researched for more than 12 months through May 2007 by a crack team of malware analysts, including Niels Provos of [Honeyd] fame, this is one of the best malware reporting papers I've ever read. It's a quick read and should be studied by anyone who has to protect computers.

In a nutshell, Google used all the Web page data collected by the Google search engine in indexing Web sites to look for malicious code. They searched more than 7 billion URLs and found 450,000 of them infected with malware designed to infect visitors' browsers (about 0.06 percent). When a suspicious Web page was found, it was then loaded using a virtual machined honey client (such as a honeypot mimicking an end user's browsing actions). They then recorded the changes the suspicious Web site made to the visiting honey client. If the Web site installed software without the explicit permission of the mimicked end user, the site was marked as malicious. Some Web sites installed up to 50 malicious programs from a single visit.

For the past seven years, the most frequent way that people got infected with malware was by clicking malicious file attachments or rogue embedded Web links. Although I thought that some people would never stop opening every strange e-mail and clicking on every file attachment, apparently our antispam, antivirus, and anti-malware filters are doing a better job, because frustrated hackers have moved on to infecting (mostly) innocent Web sites.

When users visit an infected Web site, if they have a vulnerable browser (not just Internet Explorer) or other application (Flash, Java, and so on), the user gets infected with a criminally minded bot. Web sites were compromised one of five ways (the Google paper uses four main categories): — Poor Web site security — Vulnerable applications (PHP, CGI, ASP, SQL, and so on) — User-contributed content (for example, cross-site scripting) — Malicious advertising inclusion — Malicious third-party software component (widget) inclusion.

I don't have the space to cover the specifics in this column, but the last two types really grabbed my interest. Many Web sites are paid to include roving advertising banners and pop-ups. While these services are often maintained by legitimate, respected Web advertisers, the actual ad content is often subcontracted to a subcontractor of a subcontractor. The top-level owner has no idea that their legitimate advertising banner service has been co-opted by malware criminals. They should know — it's inexcusable — but they don't.

The last item, widgets, is just as interesting. Many Web sites borrow free widgets (traffic counters, for example), and for months or years, the widget functions as intended. The widget code is often hosted on another external server. But at a later date, the "free" widget code may be maliciously manipulated to inject malware links. It appears that in many cases, the bad guys are giving away free widgets and encouraging widespread adoption so that they can use them as infection vectors later on.

The Google paper contains many other salient points, such as the widespread use of banking Trojans several times, and how many major, trusted Web sites are infected, but I want to highlight one last topic. It's becoming more common for the Web page exploits to test the client for the presence of unpatched software, be it Windows, Internet Explorer, Firefox, RealPlayer, Shockwave Flash, Java, or QuickTime. The exploits actually scan the computers looking for a specific vulnerability, and then infect it.

The lessons to learn from this are fourfold: Malware is trending away from malicious e-mails to innocently infected Web sites — You must make sure that all client OS and applications are patched (and not just the OS) — Consider investing more in technologies that can mitigate these types of rogue threats — Educate end users about the evolving malware threat to keep them alert

Good luck, and keep your eyes open.

More about Google, CGI, IBM, Apple, Billion
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
  • +

    Cambridge lab sets quantum key world record 09 October, 2008 07:51:00

    Researchers can now shift encryption keys around at speeds of 1Mbps.
    The hugely promising security technology of Quantum Key Distribution (QKD) has moved an important step closer to commercialization with the announcement by UK-based researchers that they can now shift encryption keys around at speeds of 1Mbps.
  • +

    Palin hacking charge flawed, lawyers say 09 October, 2008 07:28:00

    Case considered a misdemeanor offence not a felony.
    David Kernell is facing five years in prison for allegedly hacking into Alaska Governor Sarah Palin's Yahoo e-mail account, but lawyers watching the case say that the felony charge against him is a bit of a stretch.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Strategies for Eliminating .PST Files

Join industry expert Martin Tuip to discover best practice strategy for the archival and removal of .PST files using email archiving. Learn how to ensure long-term email records are there when needed, and reduce the risk to your business and clients.