Feeds

Stormy weather for malware defenses

Virus writers go after anti-virus vulnerabilities

5 things you didn’t know about cloud backup

When the Storm Worm swept through the internet in mid-January, the program's writers took a brute force approach to evading anti-virus defenses: They created a massive number of slightly different copies of the program and released them all at the same time.

On 18 January, the day the misnamed program - a Trojan horse, not a worm - first appeared, more than 350 different variants were released, according to a report penned by security firm CommTouch Software. Four days later, the number of slightly-different versions jumped to more than 7,300. By the end of January, more than 54,000 variants had hit the internet, the report (PDF) stated, each one spammed out by computers previously compromised by the program.

"Virus writers' goals have changed," CommTouch CEO Amir Lev said in an email interview with SecurityFocus. "They are doing 'good' business now. They do not focus on finding vulnerabilities in Microsoft and other products, they look for 'vulnerabilities' (in) the AV (anti-virus) systems."

The technique is effective. While anti-virus program's pattern recognition algorithms, frequently referred to as heuristics, may have stopped a large fraction of the variants, creating signatures to catch all the versions takes time. Response to a new variant - including developing, testing and distributing a signatures - takes hours at a minimum. Responding to thousands can take much longer.

During a January interview, one McAfee researcher underscored the headaches caused by the Storm Worm.

"Every day, it has been a new set of subject lines and new tactics to get people to open these," Allysa Myers, virus research engineer for security software maker McAfee, said in an interview with SecurityFocus. "They have had mass seedings of new variants every day this week."

The program highlights a number of changes in the techniques used by criminal internet groups. The Storm Worm spreads in fairly large, but controlled, bursts of email through previously compromised computers. Each burst typically sends out a custom variant, trying to infect systems before the user updates their anti-virus definitions. The program compromises systems by luring users into opening the attachments of messages with subject lines regarding current news events, including violent storms in Europe - a characteristic that led to the program's naming.

While some other programs have used a similar tactics, the Storm Worm's focus on propagation through sheer permutation carries the trend to a new level. The technique exploits a weakness, not in the software, but in the system. Analysing malicious code requires, for the most part, human researchers, and the coders hope to overwhelm the human component long enough to compromise as many systems as needed.

"Signatures are still needed, but the amount of malware that is being produced and the speed with which it changes means that you need a lot of researchers," said Alex Shipp, a researcher for email security provider MessageLabs.

Other firms have witnessed the trend first hand. In 2006, anti-virus firm Kaspersky Lab added 80,000 virus-pattern records to its product, roughly doubling the number added in 2005, said Eugene Kaspersky, the co-founder and head of research and development for the anti-virus firm.

"This is a competition where the anti-virus companies, I fear, are not in a good position," Kaspersky said.

The Storm Worm is all about creating massive networks of compromised computers that can be controlled by a single group or individual. The networks, known as bot nets, don't need to be large to be useful. A bot net of several thousand computers is more than enough to mount a severe denial-of-service attack or send out a digital deluge of stock spam - common uses for the networks - and, of course, send out more copies of the Trojan horse (this aspect of the Storm Worm is the subject of the first part of this two-part series).

"The guys are very aggressive with the variants, and that has defeated the more simplistic AV engines out there," Arbor Networks senior security researcher Jose Nazario said.

The Storm Worm is likely responsible for creating a bot net that contains more than 20,000 computers and perhaps as many as 100,000, Nazario said. Other evidence appears to indicate that there is more than one Storm Worm-related bot net.

Secure remote control for conventional and virtual desktops

More from The Register

next story
One HUNDRED FAMOUS LADIES exposed NUDE online
Celebrity women victimised as Apple iCloud accounts reportedly popped
Goog says patch⁵⁰ your Chrome
64-bit browser loads cat vids FIFTEEN PERCENT faster!
Rubbish WPS config sees WiFi router keys popped in seconds
Another day, another way in to your home router
NIST to sysadmins: clean up your SSH mess
Too many keys, too badly managed
Scratched PC-dispatch patch patched, hatched in batch rematch
Windows security update fixed after triggering blue screens (and screams) of death
Researchers camouflage haxxor traps with fake application traffic
Honeypots sweetened to resemble actual workloads, complete with 'secure' logins
Attack flogged through shiny-clicky social media buttons
66,000 users popped by malicious Flash fudging add-on
New Snowden leak: How NSA shared 850-billion-plus metadata records
'Federated search' spaffed info all over Five Eyes chums
Three quarters of South Korea popped in online gaming raids
Records used to plunder game items, sold off to low lifes
prev story

Whitepapers

Endpoint data privacy in the cloud is easier than you think
Innovations in encryption and storage resolve issues of data privacy and key requirements for companies to look for in a solution.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Advanced data protection for your virtualized environments
Find a natural fit for optimizing protection for the often resource-constrained data protection process found in virtual environments.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.
Next gen security for virtualised datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.