Skip the navigation

Free benchmark could have found Slammer vulnerability

By Dan Verton
January 31, 2003 12:00 PM ET

Computerworld - Not only could companies have easily slammed the door on the Slammer worm if they had installed the patch released by Microsoft Corp. six months ago, but they could also have uncovered the vulnerability exploited by the worm using a free benchmark developed jointly by the government and private sector.
Industry experts and users said the Slammer worm should have been a nonissue for companies because the patches and a free tool capable of detecting the vulnerability exploited by the worm were available six months ago. That's important because it would have given companies advance warning that they were vulnerable and more time to test the patch, said users.
In particular, they point to the issuance in July of the Consensus Minimum Security Benchmarks, also known as the Gold Standard. Developed jointly by five federal agencies, including the National Security Agency (NSA) and the FBI's National Infrastructure Protection Center, as well as the SANS Institute and the Center for Internet Security (CIS), the Gold Standard benchmark can be used to test Windows 2000 Professional systems running as workstations for proper configuration. It is available for download at www.cisecurity.org.
Alan Paller, director of research at SANS, said an NSA study of the benchmark concluded that by running it on a network a company could eliminate more than 90% of known vulnerabilities. And the database-specific vulnerabilities exploited by the Slammer worm would have been among those found, he said.
Pat Hymes, vice president of Corporate Information Security at Wachovia Corp., a CIS member company based in Charlotte, N.C., said properly configured servers are an absolute necessity for security. But maintaining service packs and "hot fixes" can be a challenge for any organization.
"It can take a great deal of time and energy to download, test and implement service packs and hot fixes, especially in large organizations, where they can impact hundreds of applications and thousands of servers," said Hymes. "Software companies, like Microsoft, have to accept more accountability for this situation. The total cost of ownership for servers running some of these distributed OSs, databases and Web software [is] going through the roof due to the manpower being expended to maintain patches and respond to events like the SQL Slammer worm."
Hymes added that the Gold Standard benchmark serves as an "excellent baseline" for security testing. And because it's available for free, "there's no reason not to use it."
The challenge remains awareness, said Clint Kreitner, president of CIS, a Hershey, Pa.-based nonprofit security standards consortium of more than 170 companies. "We continue to fight an uphill battle getting the message out to organizations that competent security configuration and up-to-date patching is one thing that everyone can and should do to make a huge difference in making their systems more secure," Kreitner said.
Maurice Rieffel, an IT security analyst at a major energy company in Louisiana, said, for example, that he was aware of the benchmark but didn't know it tested for the SQL database vulnerability exploited by Slammer.
Claude Bailey, an IT security analyst at one of the nation's largest financial management firms, said that while the Gold Standard is a good starting point, his security administrators say the problem isn't in detecting the vulnerability but in deploying the patches and fixes across an organization of 50,000 employees -- and guaranteeing that the patch won't cause more problems.
"We tested the original patch [for the SQL vulnerability], and it had problems," said Bailey. Now, with the financial firm in the middle of tax season, there's too much to lose to deploy patches that break other parts of the network. As a result, the company has placed a freeze on any such maintenance until tax season is over.
Roger Davis, an IT auditor at a global skin and body care products company in Utah, said a few hours upfront using the Gold Standard would have saved many companies hundreds of man-hours later.
Said Bailey, "If you decide not to patch something, you're dead."




Read more about Malware and Vulnerabilities in Computerworld's Malware and Vulnerabilities Topic Center.



Additional Resources
Forrester Consulting - Optimizing Users and Applications in a Mobile World
WHITE PAPER
Solving application issues over the WAN requires careful consideration. Based on their independent research, Forrester Consulting offers recommendations on how to tackle application performance issues, insufficient bandwidth and the inability to quickly restore users in a disaster.

Read now.

Security KnowledgeVault
WHITE PAPER
Security is not an option. This KnowledgeVault Series offers professional advice how to be proactive in the fight against cybercrimes and multi-layered security threats; how to adopt a holistic approach to protecting and managing data; and how to hire a qualified security assessor. Make security your Number 1 priority.

Read now.

Cut Communications Costs Once and for All
WHITE PAPER
New IP-based communications systems are being deployed by small and midsized businesses at a rapid rate. Learn how these organizations are enabling faster responsiveness, creating better customer experiences, speeding office or mobile interactions, and dramatically reducing existing communications costs.

Read now.

Malware and Vulnerabilities White Papers
Reducing the Cost and Complexity of Web Vulnerability Management
Hackers and cybercriminals are constantly refining their attacks and targets; which means you need agile tools to stay ahead of them.

Download this...
Overcome Top 7 Admin Challenges of Active Directory
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
Insiders Can Ruin Your Company. Take Action.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
Top Solutions and Tools to Prevent Devastating Malware
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
Streamline Compliance and Increase ROI
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will...
All Malware and Vulnerabilities White Papers
Malware and Vulnerabilities Webcasts
Optimizing Networks for the Cloud
Join guest speaker, Rohit Mehra, IDC Director of Enterprise Communications Infrastructure, to explore current trends, discuss best practices for optimizing Data Center and...
Apps QuickStart Series Part 2: Designing and Deploying SQL Server on VMware vSphere
Download this webcast to learn about the design considerations for virtualizing SQL workloads, performance and scalability information and high-availability options, as well as...
Apps QuickStart Series Part 1: Designing and Deploying Exchange 2010 on VMware vSphere
Download this webcast to learn the virtual hardware design considerations for Exchange 2010, deployment using the building block approach, options for high-availability and...
Customer Spotlight: How IPC The Hospitalist Company Implemented Oracle on VMware
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn...
Virtualize Business-Critical Applications with Confidence
Virtualizing business-critical applications has become a key focus for organizations as they move along their virtualization journey. With the launch of VMware vSphere®...
All Malware and Vulnerabilities Webcasts
Newsletter Sign-Up

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all newsletters | Privacy Policy
IT Jobs