Advertisement
Promo

Security threats Toolkit

PC survival time 'down to 20 minutes'

Matt Loney ZDNet.co.uk

Published: 17 Aug 2004 17:35 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The time that an unpatched PC can survive connected to the Internet has dropped to an average of 20 minutes, down from 40 minutes in 2003.

According to the latest data from the Internet Storm Center at the US-based SANS Institute, which provides research and education on security issues, the historical trend is continuing its downward journey, and has now reached a point at which it does not provide enough time to download the very patches that would protect a system from malware.

SANS calculated the survival time of a PC using the average time between probes of an average target IP address from worms attempting to propagate for an average target IP address.

"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," said the Institute in a statement. However, it said, the result is only an average, and times will vary widely from network to network.

"Some of our submitters subscribe to ISPs which block ports commonly used by worms," said the Institute.

"As a result, these submitters report a much longer 'survival time'. On the other hand, university networks and users of high speed Internet services are frequently targeted with additional scans from malware like bots. If you are connected to such a network, your 'survival time' will be much smaller."

The main issue, said SANS, is that the time to download critical patches now commonly exceeds this survival time. Part of the problem, say security experts, is IT's reliance on patch management..

Speaking at the recent Microsoft TechEd developer conference in Amsterdam, Microsoft Security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.

"Nobody will have time to detect it. Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be all and end all."

Baumhardt drew an analogy with the human body catching the 'flu. "Imagine if your body said 'Hmm, I have the flu, I’ve never had this before, so I‘ll die.' But that doesn't happen: your body raises its temperature and so on, to buy time while other mechanisms kick in."

"If the human body did patch management the way IT does we’d all be dead."

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
129 out of 224 people found this useful


Company/Topic Alerts

Create a new alert from the list below:



Video icon

Video

Sentry Posts Blog

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Symantec website breached

Security company Symantec has said that one of its websites was successfully breached. Romanian security researcher 'Unu' posted details of the breach in a blog post on Monday. Unu... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters