ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Witty 'probably an ISS inside job'

Joris Evers CNET News.com

Published: 26 May 2005 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A year after the Witty worm infected over 12,000 servers worldwide in just 75 minutes, researchers say they have discovered where the worm started and that the attack might have been an inside job.

Witty hit the Internet on March 19, 2004, taking advantage of a flaw in products from Internet Security Systems (ISS), including RealSecure and BlackIce. Its payload was malicious, corrupting the information on a system's hard drive. The worm crashed nearly half the systems it infected.

Now, new information on Witty has been compiled by researchers Vern Paxson and Nicholas Weaver, both of the International Computer Science Institute, and by Abhishek Kumar, a student at the Georgia Institute of Technology.

The researchers re-created how Witty propagated on the Internet, by combining knowledge of the worm's code and the random number generator it used to pick its targets.

They found that the worm was most probably launched from a server at a European ISP and that it was set up to target systems at a US military base.

"To our knowledge, this represents the first time that a Patient Zero has been identified for a major worm outbreak," the researchers wrote in a report published online this week. "Patient Zero" refers to the system used to initiate the spreading of the worm. The IP address of the server has been reported to law enforcement, the report said. (Click here for a PDF of the report.)

The researchers suspect that Witty was created by an ISS insider. The worm's rapid sprawl was helped by a "hit list" of 110 vulnerable systems that were infected within 10 seconds of its onset, according to the report. All of these 110 systems were at a single US military installation, the researchers found.

"We might then speculate that the attacker knew about the ISS installation at the site," the researchers wrote. Additionally, it is likely that the attacker knew about the flaws in the ISS products and was able to construct the worm rapidly, which "suggests that the attacker was an ISS insider", according to the report.

An ISS representative declined to comment.

From their analysis, the researchers also deduced that Witty failed to scan about 10 percent of the Internet's address space, meaning that systems with those addresses would not be attacked.

In the course of their work, the researchers said they found ways to improve future investigations of worms. The researchers relied on data that was captured by computers used to monitor Internet attacks, so-called network telescopes. Distortions were found in the data collected by these systems, the researchers wrote.

"The techniques developed in our study, while specific to the Witty worm... provide a template for future analysis of such similar events," the report said.

The telescopes capture traffic sent to unused portions of the Internet's address space. It is likely that this traffic was part of an attack, as there is no reason for legitimate traffic there. Worms and other malicious programs often randomly generate and connect to IP addresses, including ones not in use.

Network telescopes have been a key to investigating the spread of worms since Code Red started spreading in mid-2001. In the Witty investigation, the researchers used one telescope system at the Cooperative Association for Internet Data Analysis and one at the University of Wisconsin.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with HP

Did you find this article useful?
77 out of 150 people found this useful


Full Talkback thread

1 comment

  1. buy phentermine online . phentermine . Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

Software Engineer

NATS provides air traffic control services to aircraft flying in UK airspace, and over the eastern part of the North Atlantic. Needless to say, this ...

Senior Dialer Analyst - 25,000 - 30,000 Yorkshire

A very large Financial Institute are looking to ring in a Senior Dialer Analyst to help with the day to day running of a Melitta and Avaya Dialer ...

C# Software Engineer 37,000 + 6% Bonus - London

The department you will be working in are the UKs leading company in the traffic signals business. They design, manufacture, install and service a ...

Sentry Posts Blog

Mobile Linux Better For Mobile Busines...

Mobile Linux Better For Mobile Business Apps? Author: Eric Everson, MyMobiSafe.com As mobile Linux is carving it’s footprint on the future of mobile application development, the... More

Post a comment

DWP downplays security breach

The Department for Work and Pensions (DWP) has admitted that some of its staff have been forwarding passwords with password protected material. An email that was leaked on the 'Dizzy... More

Post a comment

How many headshots does one chairperso...

We got a strange request last week from the head of PR from Russian security experts Kaspersky. It seems although the company was very happy with the interview we recently carried with... More

Post a comment

Featured Talkback

On the contrary, if vendors were forced to stand behind their products it should increase innovation. It would force more, and better , testing before hitting the sales floor, resulting in fewer updates and less downtime for the consumer. At present the EULA removes responsibility from the vendor, and moves it to the user, which is a step backward. Make the vendor responsibility for their code.

By: ator1940

Read full story:
RSA: Vendor liability may stifle innovation