Users: We can't take much more worm turmoil
IT managers say they are being worn down by wave of attacks
Computerworld - Users scrambling to fend off a continuing barrage of malicious attacks last week expressed a growing sense of frustration over software vulnerabilities and the constant need to defend against new and increasingly sophisticated threats.
The attacks disrupted IT services at some large companies and prompted the U.S. Department of Homeland Security to issue an advisory relating to one of them.
"We are just very tired of this," said Eric Beasley, a network administrator at Baker Hill Corp., an application service provider in Carmel, Ind. "But it's unfortunately only a harbinger of what's to come."
For the second straight week, security administrators found themselves battling fires on multiple fronts. First, a variant of the recent Blaster worm, variously called Nachi, Welchia or MSBlast.D, surfaced early last week.
Dubbed by some as a "do-gooder" worm, Nachi was ostensibly created to disinfect and patch systems infected by Blaster. But the huge volume of Internet Control Message Protocol (ICMP) traffic that Nachi generated on corporate networks prompted the DHS to issue a warning about denial-of-service attacks caused by the worm.
The other attack came from W32/Sobig.F, a fast-spreading variant of a previous e-mail-borne virus that by midweek had earned the dubious distinction of being the worst ever in terms of the number of systems infected worldwide.
Security experts attributed the worm's seemingly unprecedented speed and reach to its ability to install on each machine it infects a Simple Mail Transfer Protocol server, which it uses to propagate itself via e-mail, and to the fact that it's spread both by e-mail and by network file-sharing.
The attacks disrupted service at some large companies. On Aug. 20, Jacksonville, Fla.-based CSX Corp., which owns the largest rail network in the eastern U.S., had to halt passenger and freight train servicesincluding the morning commuter trains in metropolitan Washingtonas a result of Blaster. The worm caused "significant slowdowns" to major applications, including dispatching and signal systems, according to a note on the CSX Web site.
Air Canada's reservation and airport check-in systems were similarly affected by Blaster, causing the Saint-Laurent, Quebec-based airline to delay and even cancel some flights on Aug 19.
Even companies not directly affected by last week's attacks felt their ripple effects.
External e-mail service at the MD Anderson Cancer Center at the University of Texas at Houston was slowed by Sobig.F "because of the massive number of pings and infected e-mail attempting to penetrate our perimeter defenses," said Lew Wagner, the center's chief information security officer. At its peak, the center's e-mail server was being hit by "tens of thousands" of such e-mails, he said.
And Baker Hill, which uses a third party to screen e-mail, had to deal with a stream of spoofed messages using the e-mail addresses of Baker Hill employees that were being bounced back by other servers.



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts