Make way for the uber worm

Hackers work on worm that could hit 10 million sites in hours

James Middleton

Virus writers could "own the internet in their spare time", according to research from three well respected industry experts.

A highly effective uber worm, capable of hitting up to 10 million internet hosts in a matter of hours, may be just around the corner.

Advertisement

As the SQLsnake worm continues its march - topping the list as the most prolific attacker on the net today with infection attempts hitting the 600,000 mark - experts have warned of the potential for an even greater danger.

A report compiled by Stuart Staniford of security firm Silicon Defense, Vern Paxson of the ICSI centre for internet research and Nicholas Weaver of Berkeley University, claims that: "It is reasonable for an attacker to gain control of a million internet hosts, or perhaps even 10 million.

"Once subverted, these hosts can not only be used to launch massive denial-of-service floods, but also to steal or corrupt great quantities of sensitive information, and confuse and disrupt use of the network in more subtle ways."

The paper, How to 0wn the Internet in Your Spare Time, is a pre-release of a presentation to be given at this year's Usenix Security Forum in August, and reveals that worms such as SQLsnake, Code Red and Nimda have only been precursors for what is to come.

"There are several techniques which, although not yet employed, could further significantly increase the virulence of a worm," warned the researchers.

Additional strategies a worm author could employ include "hit-list scanning", which would give us the Warhol worm - capable of infecting thousands of hosts within 15 minutes.

"Permutation scanning worms", which are self co-ordinated in their attacks, are also a potential threat, as are "internet scale hit-lists", or flash-flood worms.

Improved scanning technology could mean that a worm-infected machine could easily exceed 100 attacks per minute.

Worm writers are also focusing on the more highly homogeneous, highly deployed services to maximise the potential for faster spreading and infection of the greatest number of machines, "considerably faster than any possible human-mediated response".

Such a worm today could arguably subvert upwards of 10 million internet hosts, say the trio. A sobering thought, seeing as one million hosts can cause enormous damage.

"You can launch distributed denial-of-service (Ddos) attacks so immensely diffuse that mitigating them is well beyond the state-of-the-art for Ddos traceback and protection technologies. Such attacks could readily bring down ecommerce sites, news outlets, command and co-ordination infrastructure, specific routers, or the root name servers," the report warned.

"In short, if you could control a million internet hosts, the potential damage is truly immense: on a scale where such an attack could play a significant role in warfare between nations or in the service of terrorism."

By way of defence, Staniford, Paxson and Weaver argue for the pressing need to develop a Centre for Disease Control, an analogue for virus- and worm-based threats to national cybersecurity.

In their paper, available here, they sketch an outline for such a project.

  • Have your say
  • Send to a friend
  • Print
  • Digg
  • Reddit
  • Share

Tags:

Do you agree?

Further reading

Experts explode 'Mac is safer' myth

Any platform with a flaw is a target, says Symantec

Expert warns of Trojan explosion

Researcher bemoans 'blunders waiting to happen'

'Warhol' porn worm warning

'Fifteen minutes of fame' for malicious script

Warhol Worm 'could hit one million PCs'

Code Red threat fades, but worse may follow.

Related whitepapers

Related jobs

Most watched

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Summit: Salesforce.com on SaaS and information overload

How web services contribute to data headaches

Analysis and Reports

Remote access - Three steps to getting connected

3.4 million UK professionals now work from home – is your company equipped?

Cost benefits of a global collaboration network

This white paper is a must read for organisations looking for evidence of the bottom-line benefits of high-definition video and voice communications

Poll

Impact of Information Overload poll

Impact of Information Overload poll

What is the biggest problem your firm faces as a result of the data explosion?

View poll results

Advertisement

White paper library

Keep up to date with the latest products, services and technologies from the world's leading IT companies; IThound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Spotlight

V3.co.uk weekly debrief, 13 Nov 09

This week we discuss the inaugural V3.co.uk Summit

Fingers on keyboard

New Flash vulnerability discovered

Web sites could be vulnerable to Flash attacks

Chris Adams

Summit: Microsoft Office to the rescue

Chris Adams, Office Client product manager for Microsoft UK, explains...

Illegal downloader

Industry and human rights campaigners united in opposition to "three strikes" plan

Critics says government proposals to curb illegal downloading are unworkable...

Primary Navigation