Viruses and Worms, Protection from Disaster

Virus damage estimated at $55 billion in 2003.Sample specs for an internal email server
"SINGAPORE - Trend Micro Inc, the world'sare:Setup #1
third-largest anti-virus software maker, said Friday* Linux: OS
that computer virus attacks cost global* Sendmail: mail server
businesses an estimated $55 billion in damages in* Fetchmail: Grabs email from external email
2003, a sum that would rise this year. Companiesaddresses
lost roughly $20 billion to $30 billion in 2002 from* F-prot: Antivirus
the virus attacks, up from about $13 billion in* SpamAssassin: Spam FilterSetup #2
2001, according to various industry estimates."* Win 2003 Server: OS
This was the story across thousands of news* Exchange: Email server
agencies desk January 2004. Out of $55 billion,* Symantec antivirus: Antivirus
how much did it cost your company? How much* Exchange Intelligent Message Filter: Spam
did it cost someone you know?I. The WhyFilterSoftware Updates
There is an average of 10-20 viruses releasedKeep you software up to date. Some worms
every day. Very few of these viruses actuallyand viruses replicate through vulnerabilities in
make ?Wild? stage. Viruses are designed to takeservices and software on the target system.
advantage of security flaws in software orCode red is a classic example. In august 2001, the
operating systems. These flaws can be as blatantworm used a known buffer overflow vulnerability
as Microsoft Windows NetBIOS shares to exploitsin Microsoft's IIS 4.0 and 5.0 contained in the Idq.dll
using buffer overflows. Buffer overflows happenfile. This would allow an attacker to run any
when an attacker sends responses to a programprogram they wanted to on the affected system.
longer then what is expected. If the victimAnother famous worm called Slammer targeted
software is not designed well, then the attackerMicrosoft SQL Server 2000 and Microsoft
can overwrite the memory allocated to theDesktop Engine (MSDE) 2000.When updating your
software and execute malicious code.People makesoftware, make sure to disable features and
viruses for various reasons. These reasons rangeservices that are not needed. Some versions of
from political to financial to notoriety to hackingWinNT had a web server called IIS installed by
tools to plain malicious intent.Political: Mydoom is adefault. If you do not need the service, make
good example of a virus that was spread with asure it is turned off (Code red is a perfect
political agenda. The two targets of this virusexample). By only enabling services you need, you
were Microsoft and The SCO Group. The SCOdecrease the risk of attack.Telecommunications
Group claims that they own a large portion of theSecurity
Linux source code threatened to sue everyoneInstall a firewall on the network. A firewall is a
using Linux operating systems (with "stolen"device or software that blocks unwanted traffic
programming source). The virus was veryfrom going to or from the internal network. This
effective knocking down SCO's website.gives you control of the traffic coming in and
However, Microsoft had enough time to preparegoing out of your network. At minimum, block
for the second attack and efficiently sidesteppedports 135,137,139,445. This stops most network
disaster.Financial: Some virus writers are hired byaware viruses and worms from spreading from
other parties to either leach financial data from athe Internet. However, it is good practice to block
competitor or make the competitor look bad inall traffic unless specifically needed.Security Policies
the public eye. Industrial espionage is a high riskImplementing security policies that cover items
high payout field that can land a person in prisonsuch as acceptable use, email retention, and
for life.Notoriety: There are some that writeremote access can go a long way to protecting
viruses for the sole purpose of getting their nameyour information infrastructure. With the addition
out. This is great when the virus writers are scriptof annual training, employees will be informed
kiddies because this helps the authorities trackenough to help keep the data reliable instead of
them down. There are several famous viruseshinder it. Every individual that has access to your
that have the author's email in the source code ornetwork or data needs to follow these rules. It
open scriptHacking Hackers sometimes writeonly takes one incident to compromise the
controlled viruses to assist in the access of asystem. Only install proven and scanned software
remote computer. They will add a payload to theon the system. The most damaging viruses come
virus such as a Trojan horse to allow easy accessfrom installing or even inserting a contaminated
into the victims system.Malious: These are thedisk. Boot sector viruses can be some of the
people that are the most dangerous. These arehardest malware to defeat. Simply inserting a
the blackhat hackers that code viruses for thefloppy disk with a boot sector virus can
sole intention of destroying networks andimmediately transfer the virus to the hard
systems without prejudice. They get high ondrive.When surfing the Internet, do not download
seeing the utter destruction of their creation, anduntrusted files. Many websites will install Spyware,
are very rarely script kiddies.Many of the virusesAdware, Parasites, or Trojans in the name of
that are written and released are viruses altered"Marketing" on unsuspecting victims computers.
by script kiddies. These viruses are known asMany prey on users that do not read popup
generations of the original virus and are verywindows or download freeware or shareware
rarely altered enough to be noticeable from thesoftware. Some sites even use code to take
original. This stems back to the fact that scriptadvantage of vulnerability in Internet explorer to
kiddies do not understand what the original codeautomatically download and run unauthorized
does and only alters what they recognize (filesoftware without giving you a choice.Do not install
extension or victim's website). This lack ofor use P2P programs like Kazaa, Morpheus, or
knowledge makes script kiddies very dangerous.II.Limewire. These programs install server software
The Howon your system; essentially back dooring your
Malicious code has been plaguing computersystem. There are also thousands of infected files
systems since before computers became afloating on those networks that will activate when
common household appliance. Viruses and wormsdownloaded.Backups & Disaster Recovery Planning
are examples of malicious code designed toKeep daily backups offsite. These can be in the
spread and cause a system to perform a functionform of tape, CD-R, DVD-R, removable hard
that it was not originally designed to do.Virusesdrives, or even secure file transfers. If data
are programs that need to be activated or runbecomes damaged, you would be able to restore
before they are dangerous or spread. Thefrom the last known good backup. The most
computer system only becomes infected onceimportant step while following a backup procedure
the program is run and the payload has beeis to verify that the backup was a success. Too
deployed. This is why Hackers and Crackers trymany people just assume that the backup is
to crash or restart a computer system onceworking only to find out that the drive or media
they copy a virus onto it.There are four ways awas bad six
virus can spread:months earlier when they were infected by a
1.) Emailvirus or lost a hard drive. If the data that you are
2.) Networktrying to archive is less then five gig, DVD-R
3.) Downloading or installing softwarevdrives are a great solution. Both the drives and
4.) Inserting infected mediaSpreading throughdisks have come down in price and are now a
Emailviable option. This is also one of the fastest
Many emails spread when a user receives anbackup methods to process and verify. For larger
infected email. When the user opens this email orbackups, tape drives and removable hard drives
previews it, the virus is now active and starts toare the best option. If you choose this method,
immediately spread.Spreading through Networkyou will need to rotate the backup with five or
Many viruses are network aware. This meansseven different media (tapes, CD/DVD,
that they look for unsecured systems on theremovable drives) to get the most out of the
network and copy themselves to that system.process. It is also suggested to take a "master"
This behavior destroys network performance andbackup out of the rotation on a scheduled basis
causes viruses to spread across your system likeand archive offsite in a fireproof safe. This
wildfire. Hackers and Crackers also use Internetprotects the data from fire, flood, and theft.In the
and network connections to infect systems. TheyInternet age, understanding that you have to
not only scan for unprotected systems, but theymaintain these processes will help you become
also target systems that have known softwaresuccessful when preventing damage and
vulnerabilities. This is why keeping systems up tominimizes the time, costs, and liabilities involved
date is so important.Spreading through manualduring the disaster recovery phase if you are
installationaffected.ResourcesVirus Resources
Installing software from downloads or disksF-PROT:
increase the risk of infection. Only install trustedMcAfee :
and scanned software that is known to be safe.Symantec Norton:
Stay away from freeware and sharewareTrend Micro:
products. These programs are known to containNIST GOV: software
Spyware, Adware, and viruses. It is also goodAVG Anti-Virus - Free
policy to deny all Internet software that attemptsF-Prot - Free for home usersFree online Virus
to install itself unless explicitly needed.Spreadingscan
through boot sectorsBitDefender -
Some viruses corrupt the boot sector of disks.HouseCall -
This means that if another disks scans theMcAffe -
infected disk, the infection spreads. Boot sectorPanda ActiveScan -
viruses are automatically run immediately afterRAV Antivirus - online Trojan scan
the disk is inserted or hard drive connected.III.TrojanScan - online Security scan
Minimizing the effect of viruses and wormsSymanted Security Check -
We have all heard stories about the virus thatTest my Firewall - Security Resources
destroyed mission critical company data, whichForum of Incident Response and Security
cost companies months to recover and thousandsTeams:
of dollars and man-hours restoring the information.Microsoft:
In the end, there are still many hours, costs, andSANS Institute:
would be profits that remain unaccounted. SomeWebopedia:
companies never recover fully from a devastatingDefinitionsAdware: *A form of spyware that
attack. Taking simple precautions can save yourcollects information about the user in order to
businessAnti-virus Softwaredisplay advertisements in the Web browser based
Another step is to run an antivirus program onon the information it collects from the user's
the local computer. Many antivirus programs offerbrowsing patterns.Software that is given to the
live update software and automatically downloaduser with advertisements already embedded in
the newest virus definitions minutes after theythe applicationMalware: *Short for malicious
are released (Very important that you verifysoftware, software designed specifically to
these updates weekly if not daily). Be careful ofdamage or disrupt a system, such as a virus or a
which antivirus program you chose. Installing a PCTrojan horse.Script Kiddie: *A person, normally
antivirus on a network can be more destructivesomeone who is not technologically sophisticated,
on performance than a virus at work. Nortonwho randomly seeks out a specific weakness
makes an effective corporate edition specificallyover the Internet in order to gain root access to
designed for Windows NT Server and networka system without really understanding what it is s
environments. When using antivirus software on ahe is exploiting because the weakness was
network, configure it to ignore network drivesdiscovered by someone else. A script kiddie is not
and partitions. Only scan the local system and turnlooking to target specific information or a specific
off the auto protection feature. The auto-protectcompany but rather uses knowledge of a
constantly scans your network traffic and causesvulnerability to scan the entire Internet for a
detrimental network issues. Corporate editionsvictim that possesses that vulnerability.Spyware:
usually have this disabled by default. PC editions*Any software that covertly gathers user
do not.Email Clientsinformation through the user's Internet connection
Do not open emails from unknown sources. Ifwithout his or her knowledge, usually for
you have a website for e-commerce transactionsadvertising purposes. Spyware applications are
or to act as a virtual business card, make suretypically bundled as a hidden component of
that the emails come up with a preset subject. Iffreeware or shareware programs that can be
the emails are being sent through server sidedownloaded from the Internet; however, it should
design instead of the users email client, specifybe noted that the majority of shareware and
whom it is coming from so you know whatfreeware applications do not come with spyware.
emails to trust. Use common sense when lookingOnce installed, the spyware monitors user activity
at your email. If you see a strange email with anon the Internet and transmits that information in
attachment, do not open it until you verify whomthe background to someone else. Spyware can
it came from. This is how most MM wormsalso gather information about e-mail addresses
spread.Disable preview panes in email clients. Emailand even passwords and credit card
clients such as Outlook and Outlook Express havenumbers.Spyware is similar to a Trojan horse in
a feature that will allow you to preview thethat users unwittingly install the product when
message when the email is highlighted. This is athey install something else. A common way to
Major security flaw and will instantly unleash abecome a victim of spyware is to download
virus if the email is infected.It is also a good ideacertain peer-to-peer file swapping products that
to turn off the feature that enables the client toare available today.Aside from the questions of
view HTML formatted emails. Most of theseethics and privacy, spyware steals from the user
viruses and worms pass by using the htmlby using the computer's memory resources and
function "< i f r a m e s r c >" and run thealso by eating bandwidth as it sends information
attached file within the email header.We will take aback to the spyware's home base via the user's
quick look at an email with the subject header ofInternet connection. Because spyware is using
"You're now infected" that will open a file calledmemory and system resources, the applications
readme.exe."Subject: You're now infectedrunning in the background can lead to system
MIME-Version: 1.0crashes or general system instability.Because
Content-Type: multipart/related;type="multipartspyware exists as independent executable
_===="programs, they have the ability to monitor
X-Priority: 3keystrokes, scan files on the hard drive, snoop
X-MSMail-Priority: Normalother applications, such as chat programs or word
X-Unsent: 1processors, install other spyware programs, read
To:cookies, change the default home page on the
_====Web browser, consistently relaying this
Content-Type: multipartinformation back to the spyware author who will
====" *** (This calls theeither use it for advertising/marketing purposes
iframe)--====_ABC0987654321DEF_====or sell the information to another party.
Content-Type: text/html;charset="iso-8859-1"Licensing agreements that accompany software
Content-Transfer-Encoding: quoted-printable< H Tdownloads sometimes warn the user that a
M L > < H E A D > < / H E A D > < B O D Y bspyware program will be installed along with the
g C o l o r = 3 D # f f f f f f >requested software, but the licensing agreements
< i f r a m e s r c = 3 D c i d : EA4DMGBP9pmay not always be read completely because the
height=3D0 width=3D0> *** (This callsnotice of a spyware installation is often couched in
readme.exe)obtuse, hard-to-read legal disclaimers.Trojan: *A
< / i f r a m e > < / B O D Y > < / H T M Ldestructive program that masquerades as a
C1234567890DEF_====benign application. Unlike viruses, Trojan horses do
Content-Type: audio/x-wav;name="readme.exe"not replicate themselves but they can be just as
*** (This is the virus/worm)destructive. One of the most insidious types of
Content-Transfer-Encoding: base64Trojan horse is a program that claims to rid your
Content-ID: *** (Notice the < i f r a m e s r c =computer of viruses but instead introduces
?viruses onto your computer.The term comes
MvL0RURCBIVE1MIDQuMCBUcmFuc2l0aW9ufrom a story in Homer's Iliad, in which the Greeks
give a giant wooden horse to their foes, the
lPldobydzIHRoZSBiZXN0LS0tLS0tPyAtTrojans, ostensibly as a peace offering. But after
the Trojans drag the horse inside their city walls,
Y3JpcHQgbGFuZ3VhZ2U9amF2YXNjcmlwGreek soldiers sneak out of the horse's hollow
belly and open the city gates, allowing their
3BjaC5qcz9jdXN0b21lcmlkPTExNDc0compatriots to pour in and capture Troy.Virus: *A
program or piece of code that is loaded onto
hZ2U9ImphdmFzY3JpcHQiPg08IS0tDWZ1your computer without your knowledge and runs
against your wishes. Viruses can also replicate
wsd2luTmFtZSxmZWF0dXJlcykgeyAvL3Yy***themselves. All computer viruses are man made.
Broken to protect the innocent. (Worm isA simple virus that can make a copy of itself
encoded inover and over again is relatively easy to produce.
ZC5jb20vZmNhbGhpc3BvcnRzZnJtMT5Gb290Even such a simple virus is dangerous because it
will quickly use all available memory and bring the
wPiAtIDwvZm9udD4NDTxicj48YnI+PGJysystem to a halt. An even more dangerous type
of virus is one capable of transmitting itself across
3dy5lemJvYXJkLmNvbS8+ZXpib2Fynetworks and bypassing security systems.Since
1987, when a virus infected ARPANET, a large
OTk5LTIwMDEgZXpib2FyZCwgSW5jnetwork used by the Defense Department and
many universities, many antivirus programs have
il Serversbecome available. These programs periodically
The first step to minimizing the effect of virusescheck your computer system for the best-known
is to use an email server that filters incomingtypes of viruses.Some people distinguish between
emails using antivirus software. If the server isgeneral viruses and worms. A worm is a special
kept up to date, it will catch the majority of Masstype of virus that can replicate itself and use
Mailer (MM) worms. Ask your Internet Servicememory, but cannot attach itself to other
Provider (ISP) if they offer antivirus protectionprograms.Worm: *A program or algorithm that
and spam filtering on their email servers. Thisreplicates itself over a computer network and
service is invaluable and should always be includedusually performs malicious actions, such as using
as the first line of defense.Many companies houseup the computer's resources and possibly shutting
an internal email server that downloads all of thethe system down.* Definitions provided by
email from several external email accounts andWebopediaA special thanks goes out to the
then runs an internal virus filter. Combining anCISSP community, various Chief Information
internal email server with the ISP protection is aSecurity Officer (CISO)s, and to those in the Risk
perfect for a company with an IT staff. Thisassessment specialty of Information Systems
option adds an extra layer of control, but alsoSecurity for their help in proof reading and
adds more administration time.suggestions.