Advertisement
Promo

Security threats Toolkit

Witty 'probably an ISS inside job'

Joris Evers CNET News

Published: 26 May 2005 16:15 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A year after the Witty worm infected over 12,000 servers worldwide in just 75 minutes, researchers say they have discovered where the worm started and that the attack might have been an inside job.

Witty hit the Internet on March 19, 2004, taking advantage of a flaw in products from Internet Security Systems (ISS), including RealSecure and BlackIce. Its payload was malicious, corrupting the information on a system's hard drive. The worm crashed nearly half the systems it infected.

Now, new information on Witty has been compiled by researchers Vern Paxson and Nicholas Weaver, both of the International Computer Science Institute, and by Abhishek Kumar, a student at the Georgia Institute of Technology.

The researchers re-created how Witty propagated on the Internet, by combining knowledge of the worm's code and the random number generator it used to pick its targets.

They found that the worm was most probably launched from a server at a European ISP and that it was set up to target systems at a US military base.

"To our knowledge, this represents the first time that a Patient Zero has been identified for a major worm outbreak," the researchers wrote in a report published online this week. "Patient Zero" refers to the system used to initiate the spreading of the worm. The IP address of the server has been reported to law enforcement, the report said. (Click here for a PDF of the report.)

The researchers suspect that Witty was created by an ISS insider. The worm's rapid sprawl was helped by a "hit list" of 110 vulnerable systems that were infected within 10 seconds of its onset, according to the report. All of these 110 systems were at a single US military installation, the researchers found.

"We might then speculate that the attacker knew about the ISS installation at the site," the researchers wrote. Additionally, it is likely that the attacker knew about the flaws in the ISS products and was able to construct the worm rapidly, which "suggests that the attacker was an ISS insider", according to the report.

An ISS representative declined to comment.

From their analysis, the researchers also deduced that Witty failed to scan about 10 percent of the Internet's address space, meaning that systems with those addresses would not be attacked.

In the course of their work, the researchers said they found ways to improve future investigations of worms. The researchers relied on data that was captured by computers used to monitor Internet attacks, so-called network telescopes. Distortions were found in the data collected by these systems, the researchers wrote.

"The techniques developed in our study, while specific to the Witty worm... provide a template for future analysis of such similar events," the report said.

The telescopes capture traffic sent to unused portions of the Internet's address space. It is likely that this traffic was part of an attack, as there is no reason for legitimate traffic there. Worms and other malicious programs often randomly generate and connect to IP addresses, including ones not in use.

Network telescopes have been a key to investigating the spread of worms since Code Red started spreading in mid-2001. In the Witty investigation, the researchers used one telescope system at the Cooperative Association for Internet Data Analysis and one at the University of Wisconsin.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
84 out of 161 people found this useful


Full Talkback thread

1 comment

  1. buy phentermine online . phentermine . Anonymous

Company/Topic Alerts

Create a new alert from the list below:




Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters