Fear or terror?

Pro

1 April 2005

October was a particularly bad month for terrorism: Car bombs in Bali, hostages in Moscow, snipers in and around Washington and the seemingly endless sequence of suicide bombings in Israel. Oh, and somebody tried to break the Internet!

When you compare the genuine atrocities of the last six weeks with the failed attempt of persons unknown to knock out the root servers that control the Internet’s domain naming system, then calling the latter ‘cyber terrorism’ smacks of hyperbole at best and downright bad taste at worst.

Nevertheless, the fact that a concerted distributed denial of service (DDoS) attack took place on October 22nd and took out some of the key domain name servers for a period of time should remind IT administrators of the need to be prepared and vigilant, and perhaps most fundamentally to be aware of the need to maintain best practice when configuring the services on their servers.

 

advertisement



 

One of the lessons to be drawn from the attacks was that the methods employed were commonplace and relatively easy to counter as the chairman of ICANN’s security committee Stephen Crocker admits, the attacks ‘[did not] teach us anything we didn’t know before’. Rather, it just brought to attention ‘some old lessons that are just evident again.’

At another level, Jan Hruska, founder and chief executive of leading antivirus company Sophos on a visit to Dublin last month, briefed an audience of Irish network managers on the ongoing threat of viruses. Despite the fact that the number of viruses being found is increasing, and that they are being written for new platforms – two Javascript viruses emerged in September this year for example – the main problem is still encouraging people to take the threat seriously in the first place.

‘Too many people are ignoring the advice about safe computing practices,’ said Hruska. This includes such basic common-sense features as being careful with unsolicited attachments, installing and regularly updating antivirus software and keeping an eye on the reputable virus bulletins to learn about the latest threats and/or hoaxes that are at large.

As regards viruses, Hruska reported that of the top ten incidents of viruses causing problems in the last six months, nearly all were Win32-specific programs. This speaks volumes for Microsoft’s dominance of the desktop operating system and productivity applications markets. The Apple Macintosh-using minority can smile smugly although that platform has not escaped entirely the attentions of virus writers. Moreover, macro viruses – which are platform neutral – are still popular with so-called ‘script kiddies’ although there are no new ones in the wild and they are not having the same effect as they once did.

No platform is inherently safe, although Hruska pointed out that handheld platforms are comparatively safe, given that the vector of attack is quite limited. Code and data updates are usually performed via a desktop PC and if that is properly safeguarded, its own antivirus software will detect any problems before they are downloaded to the handheld. Nevertheless there has been a virus written for the Palm PC, although it is more than two years old and is not ‘in the wild.’

For the future, Hruska expects to see more macro and script viruses, more remote-access Trojans which allow unauthorised access to computer networks, more Internet worms of the Code Red variety which attack Web servers and an increasing number of attacks on Unix systems.

‘There is nothing magical about the security of Unix systems,’ he warned. ‘As they grow in popularity, more viruses will be written for them.’ He also expects to see more combined attacks, in which viruses will use multiple vectors of attack.

At the end of the day, like any other form of criminal activity, if somebody bigger and more powerful than you really wants to damage your computer systems, then they probably can do so, but there’s no reason to make it easy for them.

Nor is there any reason to overstate the problem. Computers are intended to streamline business processes and bring efficiencies associated with speed and transparency to organisations. Disrupting them may rightly be termed an act of vandalism or industrial sabotage. But terrorism? I think not.

Read More:


Back to Top ↑