All the latest UK technology news, reviews and analysis

Bugwatch: Worm wars

by David Kopp

13 May 2004

Be the first to comment

  • Tweet this
Each week vnunet.com asks a different expert to give their views on recent virus and security issues, with advice, warnings and information on the latest threats.

This week David Kopp, head of TrendLabs Europe, considers recent developments affecting virus proliferation.

If prizes were handed out for upping the ante, then surely the latest breed of malware authors would take this year's top trophy.

They've already amassed an array of alerts from antivirus vendors and seem intent on continuing their conveyor-belt production of new viruses and variants.

In March alone, we issued six new alerts relating to worm-based viruses, showing that worms remain the number one threat to home users and corporate networks.

The majority of these warnings concentrated on two main virus sources: Netsky and Bagle. The profusion of viruses from these two sources is the product of an ongoing worm war that can be traced over a number of months.

For instance, each time a new variant of Netsky is released, a new Bagle derivative also appears. The battle is being pitched on a number of levels, including counter-insurgence operations.

Bagle, for example, is able to disable previous Netsky variants, while Netsky can neutralise previous Bagle viruses and others including MyDoom and Nachi.

It also seems apparent that the virus writers are keen to align themselves strategically.

For example, neither one exploited application vulnerabilities originally. However, as soon as Bagle did, Netsky seemed to follow suit. And the ferocity of the conflict is being amplified by changes in the arena where the cyber-battle is being fought.

One fundamental development is the growing number of users connected to the internet, and, more importantly, the number of home users connected via broadband connections.

Mass-media advertising campaigns have successfully encouraged users to seek out faster, always-on connections that facilitate quick downloads and an improved online experience.

Unfortunately, users are often unaware of the potential threats associated with this kind of connection and can therefore fail to take the appropriate steps to protect themselves.

By plugging straight into the internet without the buffer of an early warning system, home users are increasingly the target for malicious attacks and are emerging as the main vector of virus propagation.

Of course, this isn't the only development affecting virus proliferation. Money also plays its part.

Gone are the days, for example, when virus authors developed malicious code as a means of testing their technical abilities. Now many viruses attempt to steal valuable information.

Most incorporate backdoors, which enable hackers to access computers without the knowledge of the user. While inside, the uninvited guest can spread malicious code, gather email addresses for spam or pilfer credit card numbers.

While it is impossible to predict the future, it seems likely that the growing popularity of broadband connections and the apparent naivety of home users will help the continued proliferation of new viruses and prolong the bitter battle between Bagle and Netsky.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

98%

0%

1%

0%

1%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Danish Speaker Required. Helpdesk. Liverpool. £12-£13 p/h

Danish Speaker Required. Helpdesk. Liverpool. £11-£12...

Solutions Network Engineer

Solution Network Engineer / Network Engineer - Docklands...

Web Developer - Market Leader - Watford - £32,000-£38,000pa

ROLE: Web Developer - Market Leader LOCATION: Watford...

Test Engineer Payments

Test Engineer Payments (UAT) - Leading IT Consultancy...

To send to more than one email address, simply separate each address with a comma.