Perimeter
9/24/2010
05:15 AM
Commentary
Commentary
Commentary
Connect Directly
RSS
E-Mail
50%
50%
Repost This

'Here You Have' A Lesson

It's been interchangeably called spam, or a targeted attack that spun out of control, or a form of cyber-jihad with alleged geopolitical implications. But regardless of what you call it, the "Here You Have" email worm is an excellent example of just how well today's security can work. Here are a few justifications for that optimism.

It's been interchangeably called spam, or a targeted attack that spun out of control, or a form of cyber-jihad with alleged geopolitical implications. But regardless of what you call it, the "Here You Have" email worm is an excellent example of just how well today's security can work. Here are a few justifications for that optimism.1. The security community is nimble. The server hosting the malicious download was shut down within just a few hours of the worm's initial spread. With no ability to infect new victim machines, the email component quickly self-destructed. As a result, 79% of the attempted click-throughs happened within the first three hours of the worm's initial propagation.

2. Proper heuristics do work. Some vendors -- including Cisco -- successfully identified and blocked the worm from the very beginning, no signatures required.

3. The majority of users have learned not to click on unexpected links. In the end, the "Here You Have" email accounted for only 0.3% of Web-delivered malware during a 30-day period. And from a vertical perspective, all industry employees clicked through at the same median rate. Indeed, month over month message-driven social engineering attacks collectively account for only 3% of Web-delivered malware; "Here You Have" didn't nudge this volume.

Despite this, many failed to accurately contextualize the threat posed by the "Here You Have" email and made it seem bigger than it was. As a result, reports of the worm far surpassed the actual spread of the worm itself --- even making national news broadcasts in the U.S.

So why is overstating the risk posed by a particular bit of malware a bad idea? After all, if it promotes security awareness, that's a good thing, right? Maybe not. One problem is that it causes many to equate all malware with something that is highly visible and garners massive amounts of attention. Yet it's the down-and-low, under-the-radar threats that are far more insidious.

Perhaps worse, positioning a threat as more widespread than it really is lends the impression that none of our security controls are working. And that's unfortunate. Because as we can see from the "Here You Have" example, the proper security controls do work -- even for that 99.7% of attacks that don't make the 6 o'clock news.

Mary Landesman is an antivirus professional and senior security researcher for ScanSafe, now part of Cisco. In 2009 she was awarded a Microsoft MVP for her work in consumer security.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-3946
Published: 2014-04-24
Cisco IOS before 15.3(2)S allows remote attackers to bypass interface ACL restrictions in opportunistic circumstances by sending IPv6 packets in an unspecified scenario in which expected packet drops do not occur for "a small percentage" of the packets, aka Bug ID CSCty73682.

CVE-2012-5723
Published: 2014-04-24
Cisco ASR 1000 devices with software before 3.8S, when BDI routing is enabled, allow remote attackers to cause a denial of service (device reload) via crafted (1) broadcast or (2) multicast ICMP packets with fragmentation, aka Bug ID CSCub55948.

CVE-2013-6738
Published: 2014-04-24
Cross-site scripting (XSS) vulnerability in IBM SmartCloud Analytics Log Analysis 1.1 and 1.2 before 1.2.0.0-CSI-SCALA-IF0003 allows remote attackers to inject arbitrary web script or HTML via an invalid query parameter in a response from an OAuth authorization endpoint.

CVE-2014-0188
Published: 2014-04-24
The openshift-origin-broker in Red Hat OpenShift Enterprise 2.0.5, 1.2.7, and earlier does not properly handle authentication requests from the remote-user auth plugin, which allows remote attackers to bypass authentication and impersonate arbitrary users via the X-Remote-User header in a request to...

CVE-2014-2391
Published: 2014-04-24
The password recovery service in Open-Xchange AppSuite before 7.2.2-rev20, 7.4.1 before 7.4.1-rev11, and 7.4.2 before 7.4.2-rev13 makes an improper decision about the sensitivity of a string representing a previously used but currently invalid password, which allows remote attackers to obtain potent...

Best of the Web