ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Spying worms likely to proliferate

Ingrid Marson ZDNet.co.uk

Published: 10 Jun 2005 16:10 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security experts have warned that vulnerability assessment worms, which assess computers for security flaws and relay the information back to the author, are likely to become more of a threat.

James Kay, the chief technology officer of Blackspider, said on Friday that vulnerability assessment worms are quite rare at the moment, but their number will probably increase as virus writers focus their attacks more carefully and try to avoid detection.

"We haven't seen many of them so far, but it's an example of a trend that could accelerate," said Kay. "The idea of reconnaissance fits our view that worms are becoming lower volume and more targeted. In order to produce targeted attacks this information [about the computer's vulnerabilities] would be useful."

The code in vulnerability assessment worms will be different to the code found in vulnerability scanner products, such as the open source vulnerability scanner Nessus. The worms are also likely to change periodically, as the author of the worm remotely changes the code in the worm, according to Kay.

"The code people write for assessing vulnerabilities is normally quite big and quite heavyweight," said Kay. "These worms will be smaller and stealthier. They will only look for a small number of vulnerabilities and will change over time."

Bruce Schneier, the chief technology officer of security firm Counterpane Internet Security, also spoke of the risk of vulnerability assessment worms in a blog earlier this week. He suggested that worms like SpyBot.KEG, which Secunia first reported in February, will become more common in the future.

"In 2005, we expect to see ever more complex worms and viruses in the wild, incorporating complex behaviour: polymorphic worms, metamorphic worms, and worms that make use of entry-point obscuration. For example, SpyBot.KEG is a sophisticated vulnerability assessment worm that reports discovered vulnerabilities back to the author via IRC channels," said Schneier.

But F-Secure was less concerned about the threat of worms that assess vulnerabilities. "We have seen a couple of them, but I wouldn't say it’s a big issue at the moment," said Mikael Albrecht, a product manager at F-Secure.

Security firms have already been talking for a number of months about the change in viruses from sudden impact viruses, such as the Slammer worm, to slow-burning worms where the focus is on avoiding detection.

Viruses are often used to make money nowadays, so avoiding detection is important to virus writers to increase the chance of picking up financial information, according to Kay from Blackspider.

"What virus writers don't want is to alert people to what they're doing. The longer it [the malicious code] is there, the more likely they are to pick up something interesting. If someone patches soon after they're infected, the virus writers are less likely to pick up bank details," said Kay.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
101 out of 212 people found this useful


Full Talkback thread

1 comment

  1. VARIETY AND COMBINATIONS The information technolog... PRAVEEN DALAL

Company/Topic Alerts

Create a new alert from the list below:




Related Jobs

QA Manager, London CRO

For more information, please apply online or contact: Tom Froggatt at Real Pharma on 0207 758 7311 KEYWORDS: Quality Assurance, QA, quality, ...

IT Analysts and Consultants - Workplace Technologies and Collaboration

Key Responsibilities of Analysts and Consultants include: - Working with clients in a dynamic, changing environment - Taking unstructured problems ...

S&P (Security) IT Specialist

Non Technical skills - Security methods and practices - Data encryption technologies and products - Operational security and trust models - Physical ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment