Viruses and Worms, Protection from Disaster

Virus damage estimated at $55 billion in 2003.This option adds an extra layer of control, but also
"SINGAPORE - Trend Micro Inc, the world'sadds more administration time.
third-largest anti-virus software maker, said Friday thatSample specs for an internal email server are:Setup
computer virus attacks cost global businesses an#1
estimated $55 billion in damages in 2003, a sum that* Linux: OS
would rise this year. Companies lost roughly $20 billion* Sendmail: mail server
to $30 billion in 2002 from the virus attacks, up from* Fetchmail: Grabs email from external email
about $13 billion in 2001, according to various industryaddresses
estimates." This was the story across thousands of* F-prot: Antivirus
news agencies desk January 2004. Out of $55 billion,* SpamAssassin: Spam FilterSetup #2
how much did it cost your company? How much did it* Win 2003 Server: OS
cost someone you know?I. The Why* Exchange: Email server
There is an average of 10-20 viruses released every* Symantec antivirus: Antivirus
day. Very few of these viruses actually make ?Wild?* Exchange Intelligent Message Filter: Spam
stage. Viruses are designed to take advantage ofFilterSoftware Updates
security flaws in software or operating systems.Keep you software up to date. Some worms and
These flaws can be as blatant as Microsoft Windowsviruses replicate through vulnerabilities in services and
NetBIOS shares to exploits using buffer overflows.software on the target system. Code red is a classic
Buffer overflows happen when an attacker sendsexample. In august 2001, the worm used a known
responses to a program longer then what is expected.buffer overflow vulnerability in Microsoft's IIS 4.0 and
If the victim software is not designed well, then the5.0 contained in the Idq.dll file. This would allow an
attacker can overwrite the memory allocated to theattacker to run any program they wanted to on the
software and execute malicious code.People makeaffected system. Another famous worm called
viruses for various reasons. These reasons rangeSlammer targeted Microsoft SQL Server 2000 and
from political to financial to notoriety to hacking tools toMicrosoft Desktop Engine (MSDE) 2000.When
plain malicious intent.Political: Mydoom is a goodupdating your software, make sure to disable features
example of a virus that was spread with a politicaland services that are not needed. Some versions of
agenda. The two targets of this virus were MicrosoftWinNT had a web server called IIS installed by default.
and The SCO Group. The SCO Group claims thatIf you do not need the service, make sure it is turned
they own a large portion of the Linux source codeoff (Code red is a perfect example). By only enabling
threatened to sue everyone using Linux operatingservices you need, you decrease the risk of
systems (with "stolen" programming source). The virusattack.Telecommunications Security
was very effective knocking down SCO's website.Install a firewall on the network. A firewall is a device
However, Microsoft had enough time to prepare foror software that blocks unwanted traffic from going to
the second attack and efficiently sidesteppedor from the internal network. This gives you control of
disaster.Financial: Some virus writers are hired by otherthe traffic coming in and going out of your network. At
parties to either leach financial data from a competitorminimum, block ports 135,137,139,445. This stops most
or make the competitor look bad in the public eye.network aware viruses and worms from spreading
Industrial espionage is a high risk/high payout field thatfrom the Internet. However, it is good practice to block
can land a person in prison for life.Notoriety: There areall traffic unless specifically needed.Security Policies
some that write viruses for the sole purpose of gettingImplementing security policies that cover items such
their name out. This is great when the virus writers areas acceptable use, email retention, and remote access
script kiddies because this helps the authorities trackcan go a long way to protecting your information
them down. There are several famous viruses thatinfrastructure. With the addition of annual training,
have the author's email in the source code or openemployees will be informed enough to help keep the
scriptHacking Hackers sometimes write controlleddata reliable instead of hinder it. Every individual that
viruses to assist in the access of a remote computer.has access to your network or data needs to follow
They will add a payload to the virus such as a Trojanthese rules. It only takes one incident to compromise
horse to allow easy access into the victimsthe system. Only install proven and scanned software
system.Malious: These are the people that are theon the system. The most damaging viruses come
most dangerous. These are the blackhat hackers thatfrom installing or even inserting a contaminated disk.
code viruses for the sole intention of destroyingBoot sector viruses can be some of the hardest
networks and systems without prejudice. They getmalware to defeat. Simply inserting a floppy disk with
high on seeing the utter destruction of their creation,a boot sector virus can immediately transfer the virus
and are very rarely script kiddies.Many of the virusesto the hard drive.When surfing the Internet, do not
that are written and released are viruses altered bydownload untrusted files. Many websites will install
script kiddies. These viruses are known as generationsSpyware, Adware, Parasites, or Trojans in the name
of the original virus and are very rarely altered enoughof "Marketing" on unsuspecting victims computers.
to be noticeable from the original. This stems back toMany prey on users that do not read popup windows
the fact that script kiddies do not understand what theor download freeware or shareware software. Some
original code does and only alters what they recognizesites even use code to take advantage of vulnerability
(file extension or victim's website). This lack ofin Internet explorer to automatically download and run
knowledge makes script kiddies very dangerous.II. Theunauthorized software without giving you a choice.Do
Hownot install or use P2P programs like Kazaa, Morpheus,
Malicious code has been plaguing computer systemsor Limewire. These programs install server software
since before computers became a commonon your system; essentially back dooring your system.
household appliance. Viruses and worms areThere are also thousands of infected files floating on
examples of malicious code designed to spread andthose networks that will activate when
cause a system to perform a function that it was notdownloaded.Backups & Disaster Recovery Planning
originally designed to do.Viruses are programs thatKeep daily backups offsite. These can be in the form
need to be activated or run before they areof tape, CD-R, DVD-R, removable hard drives, or even
dangerous or spread. The computer system onlysecure file transfers. If data becomes damaged, you
becomes infected once the program is run and thewould be able to restore from the last known good
payload has bee deployed. This is why Hackers andbackup. The most important step while following a
Crackers try to crash or restart a computer systembackup procedure is to verify that the backup was a
once they copy a virus onto it.There are four ways asuccess. Too many people just assume that the
virus can spread:backup is working only to find out that the drive or
1.) Emailmedia was bad six
2.) Networkmonths earlier when they were infected by a virus or
3.) Downloading or installing softwarevlost a hard drive. If the data that you are trying to
4.) Inserting infected mediaSpreading through Emailarchive is less then five gig, DVD-R drives are a great
Many emails spread when a user receives ansolution. Both the drives and disks have come down in
infected email. When the user opens this email orprice and are now a viable option. This is also one of
previews it, the virus is now active and starts tothe fastest backup methods to process and verify.
immediately spread.Spreading through NetworkFor larger backups, tape drives and removable hard
Many viruses are network aware. This means thatdrives are the best option. If you choose this method,
they look for unsecured systems on the network andyou will need to rotate the backup with five or seven
copy themselves to that system. This behaviordifferent media (tapes, CD/DVD, removable drives) to
destroys network performance and causes viruses toget the most out of the process. It is also suggested to
spread across your system like wildfire. Hackers andtake a "master" backup out of the rotation on a
Crackers also use Internet and network connections toscheduled basis and archive offsite in a fireproof safe.
infect systems. They not only scan for unprotectedThis protects the data from fire, flood, and theft.In the
systems, but they also target systems that haveInternet age, understanding that you have to maintain
known software vulnerabilities. This is why keepingthese processes will help you become successful
systems up to date is so important.Spreading throughwhen preventing damage and minimizes the time,
manual installationcosts, and liabilities involved during the disaster
Installing software from downloads or disks increaserecovery phase if you are affected.ResourcesVirus
the risk of infection. Only install trusted and scannedResources
software that is known to be safe. Stay away fromF-PROT:
freeware and shareware products. These programsMcAfee :
are known to contain Spyware, Adware, and viruses. ItSymantec Norton:
is also good policy to deny all Internet software thatTrend Micro:
attempts to install itself unless explicitlyNIST GOV: software
needed.Spreading through boot sectorsAVG Anti-Virus - Free
Some viruses corrupt the boot sector of disks. ThisF-Prot - Free for home usersFree online Virus scan
means that if another disks scans the infected disk, theBitDefender -
infection spreads. Boot sector viruses areHouseCall -
automatically run immediately after the disk is insertedMcAffe -
or hard drive connected.III. Minimizing the effect ofPanda ActiveScan -
viruses and wormsRAV Antivirus - online Trojan scan
We have all heard stories about the virus thatTrojanScan - online Security scan
destroyed mission critical company data, which costSymanted Security Check -
companies months to recover and thousands ofTest my Firewall - Security Resources
dollars and man-hours restoring the information. In theForum of Incident Response and Security Teams:
end, there are still many hours, costs, and would beMicrosoft:
profits that remain unaccounted. Some companiesSANS Institute:
never recover fully from a devastating attack. TakingWebopedia:
simple precautions can save your businessAnti-virusDefinitionsAdware: *A form of spyware that collects
Softwareinformation about the user in order to display
Another step is to run an antivirus program on theadvertisements in the Web browser based on the
local computer. Many antivirus programs offer liveinformation it collects from the user's browsing
update software and automatically download thepatterns.Software that is given to the user with
newest virus definitions minutes after they areadvertisements already embedded in the
released (Very important that you verify theseapplicationMalware: *Short for malicious software,
updates weekly if not daily). Be careful of whichsoftware designed specifically to damage or disrupt a
antivirus program you chose. Installing a PC antivirus onsystem, such as a virus or a Trojan horse.Script Kiddie:
a network can be more destructive on performance*A person, normally someone who is not
than a virus at work. Norton makes an effectivetechnologically sophisticated, who randomly seeks out
corporate edition specifically designed for Windowsa specific weakness over the Internet in order to gain
NT Server and network environments. When usingroot access to a system without really understanding
antivirus software on a network, configure it to ignorewhat it is s/he is exploiting because the weakness
network drives and partitions. Only scan the localwas discovered by someone else. A script kiddie is
system and turn off the auto protection feature. Thenot looking to target specific information or a specific
auto-protect constantly scans your network traffic andcompany but rather uses knowledge of a vulnerability
causes detrimental network issues. Corporate editionsto scan the entire Internet for a victim that possesses
usually have this disabled by default. PC editions dothat vulnerability.Spyware: *Any software that covertly
not.Email Clientsgathers user information through the user's Internet
Do not open emails from unknown sources. If youconnection without his or her knowledge, usually for
have a website for e-commerce transactions or toadvertising purposes. Spyware applications are
act as a virtual business card, make sure that thetypically bundled as a hidden component of freeware
emails come up with a preset subject. If the emails areor shareware programs that can be downloaded from
being sent through server side design instead of thethe Internet; however, it should be noted that the
users email client, specify whom it is coming from somajority of shareware and freeware applications do
you know what emails to trust. Use common sensenot come with spyware. Once installed, the spyware
when looking at your email. If you see a strange emailmonitors user activity on the Internet and transmits that
with an attachment, do not open it until you verifyinformation in the background to someone else.
whom it came from. This is how most MM wormsSpyware can also gather information about e-mail
spread.Disable preview panes in email clients. Emailaddresses and even passwords and credit card
clients such as Outlook and Outlook Express have anumbers.Spyware is similar to a Trojan horse in that
feature that will allow you to preview the messageusers unwittingly install the product when they install
when the email is highlighted. This is a Major securitysomething else. A common way to become a victim
flaw and will instantly unleash a virus if the email isof spyware is to download certain peer-to-peer file
infected.It is also a good idea to turn off the featureswapping products that are available today.Aside from
that enables the client to view HTML formatted emails.the questions of ethics and privacy, spyware steals
Most of these viruses and worms pass by using thefrom the user by using the computer's memory
html function "< i f r a m e s r c >" and run theresources and also by eating bandwidth as it sends
attached file within the email header.We will take ainformation back to the spyware's home base via the
quick look at an email with the subject header ofuser's Internet connection. Because spyware is using
"You're now infected" that will open a file calledmemory and system resources, the applications
readme.exe."Subject: You're now infectedrunning in the background can lead to system crashes
MIME-Version: 1.0or general system instability.Because spyware exists
Content-Type: multipart/related;type="multipartas independent executable programs, they have the
="ability to monitor keystrokes, scan files on the hard
X-Priority: 3drive, snoop other applications, such as chat programs
X-MSMail-Priority: Normalor word processors, install other spyware programs,
X-Unsent: 1read cookies, change the default home page on the
To:Web browser, consistently relaying this information
==back to the spyware author who will either use it for
Content-Type: multipartadvertising/marketing purposes or sell the information
=" *** (This calls theto another party.
iframe)--====_ABC0987654321DEF_====Licensing agreements that accompany software
Content-Type: text/html;charset="iso-8859-1"downloads sometimes warn the user that a spyware
Content-Transfer-Encoding: quoted-printable< H T M Lprogram will be installed along with the requested
> < H E A D > < / H E A D > < B O D Y b g C o l o rsoftware, but the licensing agreements may not
= 3 D # f f f f f f >always be read completely because the notice of a
< i f r a m e s r c = 3 D c i d : EA4DMGBP9pspyware installation is often couched in obtuse,
height=3D0 width=3D0> *** (This calls readme.exe)hard-to-read legal disclaimers.Trojan: *A destructive
< / i f r a m e > < / B O D Y > < / H T M Lprogram that masquerades as a benign application.
4567890DEF_====Unlike viruses, Trojan horses do not replicate
Content-Type: audio/x-wav;name="readme.exe" ***themselves but they can be just as destructive. One
(This is the virus/worm)of the most insidious types of Trojan horse is a
Content-Transfer-Encoding: base64program that claims to rid your computer of viruses
Content-ID: *** (Notice the < i f r a m e s r c = ?but instead introduces viruses onto your computer.The
vL0RURCBIVE1MIDQuMCBUcmFuc2l0aW9uterm comes from a story in Homer's Iliad, in which the
Greeks give a giant wooden horse to their foes, the
ldobydzIHRoZSBiZXN0LS0tLS0tPyAtTrojans, ostensibly as a peace offering. But after the
Trojans drag the horse inside their city walls, Greek
JpcHQgbGFuZ3VhZ2U9amF2YXNjcmlwsoldiers sneak out of the horse's hollow belly and open
the city gates, allowing their compatriots to pour in and
jaC5qcz9jdXN0b21lcmlkPTExNDc0capture Troy.Virus: *A program or piece of code that
is loaded onto your computer without your knowledge
Z2U9ImphdmFzY3JpcHQiPg08IS0tDWZ1and runs against your wishes. Viruses can also
replicate themselves. All computer viruses are man
d2luTmFtZSxmZWF0dXJlcykgeyAvL3Yy*** Brokenmade. A simple virus that can make a copy of itself
to protect the innocent. (Worm is encoded inover and over again is relatively easy to produce.
C5jb20vZmNhbGhpc3BvcnRzZnJtMT5Gb290Even such a simple virus is dangerous because it will
quickly use all available memory and bring the system
iAtIDwvZm9udD4NDTxicj48YnI+PGJyto a halt. An even more dangerous type of virus is
one capable of transmitting itself across networks and
y5lemJvYXJkLmNvbS8+ZXpib2Fybypassing security systems.Since 1987, when a virus
infected ARPANET, a large network used by the
k5LTIwMDEgZXpib2FyZCwgSW5jDefense Department and many universities, many
antivirus programs have become available. These
NCj==--====_ABC1234567890DEF_====--"Emailprograms periodically check your computer system for
Serversthe best-known types of viruses.Some people
The first step to minimizing the effect of viruses is todistinguish between general viruses and worms. A
use an email server that filters incoming emails usingworm is a special type of virus that can replicate itself
antivirus software. If the server is kept up to date, it willand use memory, but cannot attach itself to other
catch the majority of Mass Mailer (MM) worms. Askprograms.Worm: *A program or algorithm that
your Internet Service Provider (ISP) if they offerreplicates itself over a computer network and usually
antivirus protection and spam filtering on their emailperforms malicious actions, such as using up the
servers. This service is invaluable and should alwayscomputer's resources and possibly shutting the system
be included as the first line of defense.Manydown.* Definitions provided by WebopediaA special
companies house an internal email server thatthanks goes out to the CISSP community, various
downloads all of the email from several external emailChief Information Security Officer (CISO)s, and to
accounts and then runs an internal virus filter.those in the Risk assessment specialty of Information
Combining an internal email server with the ISPSystems Security for their help in proof reading and
protection is a perfect for a company with an IT staff.suggestions.