ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

PC survival time 'down to 20 minutes'

Matt Loney ZDNet.co.uk

Published: 17 Aug 2004 17:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The time that an unpatched PC can survive connected to the Internet has dropped to an average of 20 minutes, down from 40 minutes in 2003.

According to the latest data from the Internet Storm Center at the US-based SANS Institute, which provides research and education on security issues, the historical trend is continuing its downward journey, and has now reached a point at which it does not provide enough time to download the very patches that would protect a system from malware.

SANS calculated the survival time of a PC using the average time between probes of an average target IP address from worms attempting to propagate for an average target IP address.

"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," said the Institute in a statement. However, it said, the result is only an average, and times will vary widely from network to network.

"Some of our submitters subscribe to ISPs which block ports commonly used by worms," said the Institute.

"As a result, these submitters report a much longer 'survival time'. On the other hand, university networks and users of high speed Internet services are frequently targeted with additional scans from malware like bots. If you are connected to such a network, your 'survival time' will be much smaller."

The main issue, said SANS, is that the time to download critical patches now commonly exceeds this survival time. Part of the problem, say security experts, is IT's reliance on patch management..

Speaking at the recent Microsoft TechEd developer conference in Amsterdam, Microsoft Security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.

"Nobody will have time to detect it. Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be all and end all."

Baumhardt drew an analogy with the human body catching the 'flu. "Imagine if your body said 'Hmm, I have the flu, I’ve never had this before, so I‘ll die.' But that doesn't happen: your body raises its temperature and so on, to buy time while other mechanisms kick in."

"If the human body did patch management the way IT does we’d all be dead."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
128 out of 222 people found this useful



Company/Topic Alerts

Create a new alert from the list below:



Related Jobs

.NET Applications Support Specialists Bradford 35,000 Plus package

You will be engaged with incident/ problem, change management, release and patch management, documentation, and training help staff. Key: VB, .NET, ...

Accenture SAP HR Consultant-00041519

Created following Accenture's acquisition of Pecaso in May 2006, it brings together Accenture and Pecaso experts in mySAP ERP HCM technology, ...

SAP HCM Business Development Executive (Europe)

We are looking for experienced consultants with a strong background in HCM transformation who are viewed as subject matter experts in this area, with ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment

Trades Unions against ID Cards

The Trades Union Congress (TUC) has backed up airport workers protesting against ID cards, the Financial Times reports. In a letter to Home Secretary Jacqui Smith, the TUC said it... More

Post a comment