On The Insider: Britney's Bikini-Clad Top 10
BNET Business Network:
BNET
TechRepublic
ZDNet

July 16th, 2007

Securing the PC

Posted by Paul Murphy @ 12:15 am

Categories: Enterprise Policy, Government

Tags: Security, PC, Bot, Bot Net, Paul Murphy

An interesting report by Robert Lemos on Security Focus last week got me thinking about the money and effort going into what the PC people think of as “security.”

What the report was nominally about was the difficulty PC defenders have in shutting down bot-net attacks where control moves across many hosts. Here are two key bits from the report:

Traditional bot nets have used Internet relay chat (IRC) servers to control each of the compromised PCs, or bots, but the central IRC server is also a weakness, giving defenders a single server to target and take down. An increasingly popular technique, known as fast-flux domain name service (DNS), allows bot nets to use a multitude of servers to hide a key host or to create a highly-available control network. The result: No single point of weakness on which defenders can focus their efforts.

Last month, two significant online threats — the Storm Worm and a recent MySpace Web virus — became the latest malicious programs to incorporate fast-flux hosting into their infrastructure. A recent Storm Worm infection, for example, connected to a bot net that had more than 2,000 redundant hosts spread amongst 384 providers in more than 50 countries, said analyst Baldwin, who is the chief forensics officer for myNetWatchman.com.

“That is what you would have to take down in order to shut down the bot net,” he said. “It’s already ridiculous trying to get an IRC command-and-control server taken down. Now, we are talking about a bot net, that in order to disable it, you have to take down thousands of hosts.”

In late April and early May, networks of zombie PCs were used to attack the Web sites and infrastructure of the government in the Northern European country of Estonia. In June, the FBI announced that the agency had identified more than a million compromised PCs infected by bot software.

Bot-net controllers, also known as bot masters, typically search such systems for financial information and use stealthy keylogging software to record usernames and passwords. The systems are also frequently used to overwhelm corporate networks with garbage data in denial-of-service attacks or send spam advertising penny stocks, fake pharmaceuticals or job scams. At any given time, there are 1.5 million different zombie computers sending spam, according to security firm Secure Computing, which estimates that 50 million computers are currently compromised with bot software.

The real message, however, is one that seems to escape most of the people getting their daily deluge of this kind of information: PC security is a lost cause -and people who tell you otherwise are either lying or dangerously naive.

There are three main reasons:

(1) the PC security universe consists of mutually symbiotic attackers and defenders with both sides dependent on Microsoft and Intel for their cash flows - cash flows now amounting to billions of dollars each year and which both sides can reasonably be expected to lie, fight, and scheme to protect.

(2) the PC community lives in a state of perennial optimism (aka delusion): everyone agrees security is a problem - but it’s always someone else’s problem, never theirs. Personally, I have no idea whether the fifty million number put forth by the oxymoronic “Secure Computing” is realistic, but I guarantee you that essentially all of people responsible for those machines either don’t care, are deeply ignorant, or are lying to themselves about their vulnerabilities.

(3) people selling PC products stress how little knowledge is needed to use them - and then sell the same people security tools that need both expertise and discipline to use. People often lack both - and as a result PCs may start clean but the combination of attacker progress with user mistakes or inertia leaves most machines essentially unprotected after only a few months of use.

The right answers are obvious: in the long run the PC community has to clean up its own mess - change or abandon x86, build a simpler, more reliable, OS, adopt effective self-policing, shift from defence by reaction to defence by prevention, and align its own monetary incentives with protecting, rather than exploiting, the customer.

Sadly I don’t think those miracles will happen any time soon; so, in the meantime, what?

Not caring may be a perfectly reasonable strategy - one way or another that’s what Secure Computing’s fifty million people are doing and they can’t all be wrong - can they? In fact, I’ll bet there’s a market for a hacker supported piece of open source software that simply lets people surrender by offering attackers 24 x 7 access to data and a controlled piece of the computing resource - trading off a hypothetical privacy and some bandwidth for freedom from security hassles and stress.

On the other hand, if you think security does matter to you, you need to start by defining what you actually care about. Remember that all the noise, losses, and excitement selling the multi-billion dollar “PC security” industry is based on the kind of mickey mouse attacks companies like Secure Computing focus on - and have nothing at all to do, except perhaps as camouflage, with longer term strategies aimed at creating and testing exploitable vulnerabilities national governments like that of Communist China can put on. In other words, if your security needs amount to little little more than keeping up, albeit always in arrears, with PC attackers - then all you need to do is help keep the cycle spinning by contributing to industry revenues and hiring.

But what if security really does matter? then you have to abandon the PC: there are no other options. Get away from anything on x86, get away from Windows on anything, physically disconnect secure networks from each other and the internet, use humans to buffer all forms of electronic data transfer in which one side is supposed to remain secure, and start paying close attention to who writes your code - including the stuff you can’t see in the ROMs and EPROMS you depend on

Paul MurphyPaul Murphy (a pseudonym) is an IT consultant specializing in Unix and related technologies. See his full profile and disclosure of his industry affiliations.


Email Paul Murphy

Subscribe to Managing L'unix via Email alerts or RSS.

  • Talkback
  • Most Recent of 43 Talkback(s)
Linux VS Windows, etc
This is the part of Paul's post that I agree with. I don't think the average Joe can secure Windows but I don't think the average Joe can secure Linux either.

There is no drive by malwa... (Read the rest)
Posted by: TripleII Posted on: 07/16/07 You are currently: a Guest | | Terms of Use
Useless  dzabor@... | 07/16/07
Why ? Your post offered something more ?  intrepi@... | 07/16/07
In other words start over...  Erik Engbrecht | 07/16/07
hardware redesign  gdstark13 | 07/16/07
What you describe....  bportlock | 07/16/07
RE: What you describe....  gdstark13 | 07/16/07
I'd still like to see  TripleII | 07/16/07
Camouflage  Anton Philidor | 07/16/07
However...  bportlock | 07/16/07
An unfortunately abusive process  murph_zZDNet Moderator | 07/16/07
Counter-Flood?  Anton Philidor | 07/16/07
I think you missed something  murph_zZDNet Moderator | 07/16/07
Baby Steps  TripleII | 07/16/07
Vulnerability  Anton Philidor | 07/16/07
RE: Vulnerability  gdstark13 | 07/16/07
Fixing the Users  Erik Engbrecht | 07/16/07
Don't let them reproduce??  Anton Philidor | 07/16/07
Tomorrow's blog  murph_zZDNet Moderator | 07/16/07
I wasn't talking about Sun Rays  Erik Engbrecht | 07/16/07
That's not true  rapson | 07/16/07
Sure it is -  murph_zZDNet Moderator | 07/16/07
If you give me a sneak peak...  Erik Engbrecht | 07/16/07
RE: Fixing the Users  gdstark13 | 07/16/07
The customer is NOT always right  mdemuth | 07/16/07
The customer is always right...  Erik Engbrecht | 07/16/07
RE: The customer is NOT always right  gdstark13 | 07/16/07
Excellent Point  Erik Engbrecht | 07/16/07
Still not there.  Anton Philidor | 07/16/07
Wrong Emphasis  Erik Engbrecht | 07/16/07
True, mostly.  Anton Philidor | 07/16/07
Anton, Anton, Anton  Erik Engbrecht | 07/16/07
Diminishing disagreement  Anton Philidor | 07/16/07
LOL - A bit impractical - not to mention unethical and unreasonable  murph_zZDNet Moderator | 07/16/07
I can see why I rarely bother to read your flamebait  Scrat | 07/16/07
I agree with Paul on 1 point  NonZealot | 07/16/07
My hardware of Microsoft's?  Erik Engbrecht | 07/16/07
Those who object buy their own  NonZealot | 07/16/07
If you think Windows on x86 can be secured...  murph_zZDNet Moderator | 07/16/07
Tiny Minority?  TripleII | 07/16/07
Linux VS Windows, etc  TripleII | 07/16/07
Until a new networking protocol is introduced  ctelljohn | 07/16/07
PC security  dick7517 | 07/16/07
RE: PC security  gdstark13 | 07/16/07

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

Archives

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
Click Here