ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

US quarantines visa system after virus attack

Matt Hines CNET News.com

Published: 25 Sep 2003 08:50 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A computer virus has hit the US Department of State, affecting the performance of the government's information technology system that manages visa approvals, according to reports.

The virus shut down the State Department's Consular Lookout and Support System (Class) on Tuesday, according to published reports from Reuters and the Associated Press. A State Department representative CNET News.com reached on Wednesday would not confirm that the system had crashed but indicated that IT personnel were working on a problem.

Late on Wednesday, the State Department provided more details of the incident. According to spokeswoman Joanne Moore, at 4:30 a.m. on Tuesday morning, the department's IT workers discovered the Welchia worm on an "unclassified open network" area of the Class system and began taking measures to contain the attack.

At that time, the State Department sent a message to employees around the world warning them that Class was being temporarily shut down in order to prevent Welchia from spreading. However, Moore indicated that the virus never truly infiltrated Class.

"At no time did the virus infect or corrupt the (Class) system," Moore said. "Due to the fast-spreading virus activity, the department was forced to quarantine all international communications."

Welchia and the related MSBlast virus target openings in Microsoft's Windows operating system and have been linked to a number of government computer failures. A new report from the Computer and Communications Industry Association asserts that reliance on a single technology such as Windows for an overwhelming majority of computer systems threatens the security of the US economy and critical infrastructures.

Class has been identified as one of the tools the US government is leaning on to help stem the flow of terrorists and other criminals entering the United States. According to the State Department, Class has been improved over the past two years and can now access more detailed information banks to scrutinise the eligibility of potential visa applicants.

In a letter sent to Congress earlier this year, President Bush said Class contains about 13 million name records, which increases the State Department's ability to recognise individuals who might be a threat to national safety.

"Class now has over 78,000 records of suspected terrorists, up 40 percent in the past year," Bush wrote in his letter. "This will allow federal, state and local entities to share information nationwide that will ultimately contribute to securing our borders and protecting our nation."

One security expert said a Class shutdown could be a short-term black eye for the State Department, but he pointed out that MSBlast similarly caught many corporations that have huge IT security budgets off-guard. Pete Lindstrom, an analyst with Spire Security, said while it may be disturbing to see that the US visa-approval system is vulnerable, "everyone slips up."

"What this situation highlights is the need for companies and governments to move security from the perimeter level to a layered level, something we've been talking about within the industry for years," Lindstrom said.

He said the current antivirus strategy, typically implemented at the firewall, works acceptably against the known threat of email viruses but can't prevent worms such as MSBlast from spreading. By installing security tools throughout different layers of IT rather than just at a system's perimeters, organisations could increase their protection levels, he said.

In regard to Microsoft and potential weaknesses in Windows, Lindstrom said it's too easy to blame a vendor for security breaches.

"The truth is that there is sufficient technology out there right now to protect organisations from almost any threat out there," he said. "It's mostly in how you use it."

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Kyocera

Did you find this article useful?
61 out of 142 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:



Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Facebook Bans Firefox 3

Ok this is the issue. Because I dared to try and access facebook with firefox 3, and all the cookies disabled, it won't let me back on there with firefox ever again, even though... More

1 comment

GoDaddy suspends travel-getaways.com d...

I'm very pleased to say that GoDaddy has suspended the travel-getaways.com domain. I blogged in June that to my surprise I had found I was the site administrator for travel-getaways.com,... More

1 comment

Hello, I知 a PC. I知 a Handheld.

Hello, I知 a PC. I知 a Handheld. Author: Eric Everson, Founder MyMobiSafe.com I have said it before and I am sure I値l say it again, mobile devices are simply replacing computers.... More

Post a comment