On mySimon: Top MP3 Players and Accessories
BNET Business Network:
BNET
TechRepublic
ZDNet

August 17th, 2005

Are worms actually good for security?

Posted by George Ou @ 9:51 am

Categories: Security

Tags:

You’ve probably heard by now that the Zotob worm is rampaging through business and organizations with computers running the Windows 2000 operating system, but could this actually be good for security?  The way that I see it, any computer worm that doesn’t actually delete or steal any data is the cyber equivalent of biological immunization.

Two years ago, a fast moving worm called Blaster rampaged through the Internet and forced every company in the world to take prompt action to harden their network and thoroughly patch all of their Windows systems.  Since most people simply used Windows Update on all of their client and server systems, it actually had a much broader immunization effect.  This immunization effect isn’t something that’s just theoretical, it actually resulted in a sharp drop in the number of confirmed hacker defacements on Zone-H shown in a report posted here.  This report actually showed Windows servers being hacked significantly less than Linux servers, which seems to validate the theory that worms actually strengthen security like colds strengthen our immune systems.

While the Zotob worm can’t be considered a "vaccine" since it was created with malicious intent to wreak havoc, it is equivalent to getting a nasty case of chickenpox that temporarily knocks you out of commission but you recover from it immunized from all future attacks.  The Zotob worm is effectively forcing IT departments to do a systematic and thorough patch on all vulnerable systems which is exactly how a biological system would react.  Had there been a well-engineered "good" worm that was designed to eliminate side-effects such as rapid reboots and network flooding, this would have been the equivalent of a vaccine.  Such a worm would be able to infect computers, install the patch, instruct the host to infect 10 more computers or wait for a timeout before deleting itself safely without all the nasty side-effects of the bad worm.

Every time I’ve mentioned the possibility of a good worm to my colleagues in the IT world, I usually got very negative feedback.  Their typical reaction would be something like "well I’ll put up some firewall rules to block it from patching my systems because it might break some of my applications".  Ironically, this was exactly the affect I was hoping for.  If the threat of the good worm forced action that would result in the blockage of the good worm or more importantly the bad worm, would that be such a bad thing?  If the good worm did get through because of inaction, the bad worm would have gotten through just as easily only with much more severe side-effects.  Even more of a concern is the fact that hackers use these types of vulnerabilities to commit even worse crimes.  Given the choice between the vaccine or chickenpox, which would you prefer?

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 41 Talkback(s)
Unfortunately, there will always be people
who take advantage of the weak or unprotected and our computer systems are no different. If you don't protect your system with patches and updates, then you deserve what you get. The virus writers wi... (Read the rest)
Posted by: SimonSays Posted on: 08/19/05 You are currently: a Guest | | Terms of Use
Cowpox  Roger Ramjet | 08/17/05
With a probe you wouldn't need a worm...  Anton Philidor | 08/17/05
Petty theft prevents grand theft?  John L. Ries | 08/17/05
Technically  voska | 08/17/05
No disagreement there  george_ou | 08/17/05
By the way.  Anton Philidor | 08/17/05
Same idea, only vendor embedded  george_ou | 08/17/05
Are worms actually good for security?  ron@... | 08/17/05
It's a pragmatic view  george_ou | 08/18/05
Yes worms are good for security.  IT Scion | 08/17/05
Wrong  george_ou | 08/17/05
Okay then  IT Scion | 08/17/05
This one got through on networks that didn't learn  george_ou | 08/17/05
Re: Worms good for Security?  Andromedat6 | 08/17/05
Did you miss something?  george_ou | 08/17/05
No worm is a good worm  xstep | 08/17/05
A worm hunter?  xstep | 08/17/05
Are Apologists Good for Technology?  Harry Bardal | 08/17/05
Open reply to Harry  george_ou | 08/17/05
Individual versus Social Rights  palmwarrior | 08/17/05
Not talking about Vigilantes, but vaccinations  george_ou | 08/17/05
The issue is choice  palmwarrior | 08/18/05
It's not a vaccine then if it's a home-made job  george_ou | 08/18/05
A bigger question:  Altiris_Grunt | 08/18/05
They won't, and that's the problem  george_ou | 08/18/05
Stop grousing and do something positive  palmwarrior | 08/19/05
No, Worms are not good for security  IT-sys | 08/17/05
You don't really understand Zone-H then  george_ou | 08/17/05
your false claims is the issue not Zone-H  IT-sys | 08/18/05
Zone-H is a thermometer  george_ou | 08/18/05
You're preaching against the choir George  toadlife | 08/18/05
I'm just handing him the rope  george_ou | 08/18/05
how about daily news of Windows exploits for a thermometer?  IT-sys | 08/18/05
Depends on the house you live in.  johnadurcan | 08/18/05
OS is UNIMPORTANT  tmurph1810 | 08/18/05
also, remember Cabir?  tmurph1810 | 08/18/05
You are wrong  toadlife | 08/18/05
Worms work! We now have defenses.  Ngallendou | 08/18/05
We would like to hope.  papatator | 08/18/05
hmmmm  GOpcGeeks | 08/18/05
Unfortunately, there will always be people  SimonSays | 08/19/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    advertisement

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More