Technology Review - Published By MIT
Advertisement

A Plan to Catch the Conficker Worm

Continued from page 1

By Erica Naone

Monday, March 30, 2009

smaller text tool iconmedium text tool iconlarger text tool icon

Bruce Schneier, chief security technology officer at BT Counterpane, says the new tool's ability to seek out the virus remotely should be useful, since it will let people scan a huge number of machines very quickly. This is important, Schneier says, because the worm is such a nasty pest. "Conficker is an extremely well-written, extremely well-designed, extremely well-executed worm," says Schneier. "It really is an impressive piece of work, and there's someone really smart behind it." But Schneier adds that it's important for computer users and administrators to protect their machines against a variety of malware, not just a single threat.

"If you've been running a good environment, you shouldn't be worried about this," says Rich Mogull, founder of the security-consulting company Securosis, who helped connect the Honeynet researchers and Kaminsky with network-security vendors over the weekend. Mogull notes that Microsoft has already released several patches that block the vulnerability that Conficker uses to infect a machine. However, he says that companies worried about Conficker should start scanning for it right away, after checking to see if their network-security tools have been updated.

Kurt Rohloff, a scientist who studies Internet worms at the research and development company BBN Technologies, says that the tool could prove useful, though he doubts that there's time to find and neutralize every computer infected with the worm. Rohloff says that the new scanner could be used to take preventive action by identifying infected hosts and removing them from the network, though he admits that this approach is "drastic, because you're removing connectivity."

Kaminsky notes that the tool is intended for organizations with large networks. For individuals, he says, the best approach is to make sure that the latest security updates are installed and up-to-date antivirus software is running. Since Conficker blocks a computer from accessing certain security websites, users could test for the worm by trying to visit those sites, Kaminsky says. Werner and Leder plan to release a paper within the next day, describing the technical details of their discovery.

Comments

  • Will a temporary take-down work?
    Identifying infected hosts and removing them from the network is doable, but it's considered too drastic.  How about taking them off the network only for the period when the worm is scheduled to "phone home"?  Much less drastic, and 100% effective if we know the schedule.  (I assume that "home" will be taken out of commission ASAP.)
    Rate this comment: 12345

    jpdemers
    03/31/2009
    Posts:40
    Avg Rating:
    4/5
  • The Conficker Worm
    I think that the only way to catch this worm is to have it yourself!

    That way you can trace where it's contacting - and that might also explain what the virus will actually do!

    I think that the hackers have realised that if they want to hack a big computer, they need all the inocent pc's they can get. I think that today they have been attempting to control all the infected computers to do something - that way it will be way too strong for (whatever they want hacked) firewall.

    So I think that someone should try actually getting the worm to find out what it's contacting. Im sure that the hackers wont make their ip to obvious, so they'll have used a proxy.

    But even that can be traced carefully!
    Rate this comment: 12345

    mitchell.mus...
    04/01/2009
    Posts:5
    Avg Rating:
    4/5
    • Re: The Conficker Worm
      Protection for your computer.
      Search-and-destroy Antispyware is one of the best options available when you are searching for protection for your computer that you can trust. I know because I have tried many different types of scans in the past and the biggest difference I have found between them is the price. I found the antispyware solution from Search-and-destroy to be a great option that is affordable and easy to use. Visit http://www.Search-and-destroy.com to learn more about this scan and what it can do for you. If you are like me, you will be glad that you took the time to check it out.
      Rate this comment: 12345

      Spider Net
      04/15/2009
      Posts:6
      Avg Rating:
      2/5
  • Keep your computer running like new.
    Have you been searching for a great antispyware to keep your computer running like new? If so, you will be happy to know that there are some great options out there. I have tried many different types of antispyware only to find that the majority of them find the exact same types of bugs. The biggest difference that you will find between all the different types of antispyware offered is the price. Search-and-destroy Antispyware is an excellent choice that can be purchased at a lower price than many of the other options available. If you are interested in discovering the benefits offered from antispyware solution from Search-and-destroy visit http://www.Search-and-destroy.com to learn more.
    Rate this comment: 12345

    Spider Net
    04/15/2009
    Posts:6
    Avg Rating:
    2/5
  • Spam
    Those 2 previous message are clearly Spam, can some admin remove them ?
    Rate this comment: 12345

    Sly
    04/15/2009
    Posts:11
    Avg Rating:
    4/5
    • Re: Spam
      I agree. Can they be removed?
      By the way : Great article!
      Rate this comment: 12345

      mitchell.mus...
      04/19/2009
      Posts:5
      Avg Rating:
      4/5

Log In

Forgot your password?     Register »
Advertisement

Videos

Prescription: Networking
Technology Review November/December 2009

Current Issue

Natural Gas Changes the Energy Map
The United States has vast supplies of this cleaner fossil fuel. But how should we use it?
Featured Content
Sponsored by:
White Papers

Twelve ways to reduce costs with SQL Server 2008
Find out how to reduce costs and get more efficient

Download

Total Economic Impact of SQL Server 2008 Upgrade
Forrester reports on increasing productivity and management capabilities

Download 

Achieving Cost and Resource Savings with UC
How Office Communications Server R2 and Exchange Server can make your business smarter and more efficient

Download 
Advertisement
Subscribe to Technology Review's daily e-mail update. Enter your e-mail address

TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology © 2009 Technology Review. All Rights Reserved.