On TechRepublic: IT pros refuse to let go of Windows XP
BNET Business Network:
BNET
TechRepublic
ZDNet

By Robert Lemos
Posted on ZDNet News: Aug 17, 2004 7:22:00 PM

Don't connect that new PC to the Internet before taking security precautions, researchers at the Internet Storm Center warned Tuesday.

According to the researchers, an unpatched Windows PC connected to the Internet will last for only about 20 minutes before it's compromised by malware, on average. That figure is down from around 40 minutes, the group's estimate in 2003.

The Internet Storm Center, which is part of the SANS Institute, calculated the 20-minute "survival time" by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.

"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," the center, which provides research and education on security issues, said in a statement.

The drop from 40 minutes to 20 minutes is worrisome because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from Internet threats.

Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the center's data believeable.

"It's a tough problem, and it's getting tougher," Conti said.

One of Conti's administrators tested the center's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.

The school is now checking the status of computers before letting them connect to the Internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.

"We are giving the people the ability to remediate before connecting to the network," Conti said.

The center also said in its analysis that the time it takes for a computer to be compromised will vary widely from network to network.

If the Internet service provider blocks the data channels commonly used by worms to spread, then a PC user will have more time to patch.

"On the other hand, university networks and users of high-speed Internet services are frequently targeted with additional scans from malware like bots," the group stated. "If you are connected to such a network, your 'survival time' will be much smaller."

In a guide to patching a new Windows system, the Internet Storm Center recommends that users turn off Windows file sharing and enable the Internet Connection Firewall. Microsoft's latest security update, Windows XP Service Pack 2, will set such a configuration, but users will have to go online to get the update, opening themselves up to attack.

One problem, experts say, is network administrators' reliance on patching and their assumption that users will quickly patch systems.

Speaking recently at the Microsoft TechEd developer conference in Amsterdam, Microsoft security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.

"Nobody will have time to detect it," he said. "Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be-all and end-all."

Baumhardt stressed the importance of adaptability, using the human immune system as an example: "Imagine if your body said, 'Hmm, I have the flu. I've never had this before, so I'll die.' But that doesn't happen: Your body raises its temperature and so on, to buy time while other mechanisms kick in."

"If the human body did patch management the way (companies do), we'd all be dead."

Matt Loney of ZDNet UK reported from London.

Don't connect that new PC to the Internet before taking security precautions, researchers at the Internet Storm Center warned Tuesday.

According to the researchers, an unpatched Windows PC connected to the Internet will last for only about 20 minutes before it's compromised by malware, on average. That figure is down from around 40 minutes, the group's estimate in 2003.

The Internet Storm Center, which is part of the SANS Institute, calculated the 20-minute "survival time" by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.

"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," the center, which provides research and education on security issues, said in a statement.

The drop from 40 minutes to 20 minutes is worrisome because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from Internet threats.

Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the center's data believeable.

"It's a tough problem, and it's getting tougher," Conti said.

One of Conti's administrators tested the center's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.

The school is now checking the status of computers before letting them connect to the Internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.

"We are giving the people the ability to remediate before connecting to the network," Conti said.

The center also said in its analysis that the time it takes for a computer to be compromised will vary widely from network to network.

If the Internet service provider blocks the data channels commonly used by worms to spread, then a PC user will have more time to patch.

"On the other hand, university networks and users of high-speed Internet services are frequently targeted with additional scans from malware like bots," the group stated. "If you are connected to such a network, your 'survival time' will be much smaller."

In a guide to patching a new Windows system, the Internet Storm Center recommends that users turn off Windows file sharing and enable the Internet Connection Firewall. Microsoft's latest security update, Windows XP Service Pack 2, will set such a configuration, but users will have to go online to get the update, opening themselves up to attack.

One problem, experts say, is network administrators' reliance on patching and their assumption that users will quickly patch systems.

Speaking recently at the Microsoft TechEd developer conference in Amsterdam, Microsoft security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.

"Nobody will have time to detect it," he said. "Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be-all and end-all."

Baumhardt stressed the importance of adaptability, using the human immune system as an example: "Imagine if your body said, 'Hmm, I have the flu. I've never had this before, so I'll die.' But that doesn't happen: Your body raises its temperature and so on, to buy time while other mechanisms kick in."

"If the human body did patch management the way (companies do), we'd all be dead."

Matt Loney of ZDNet UK reported from London.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 149 Talkback(s)
How did you test to find Compromise
How did you test to find Compromise?
Did you use software?
Jon (Read the rest)
Posted by: johnydii@... Posted on: 08/19/04 You are currently: a Guest | | Terms of Use
It's called the "Microsoft Challenge"...  Xunil_Sierutuf | 08/17/04
As opposed to 'User Base' challenged what?  seosamh_z | 08/17/04
That's a LIE  itanalyst | 08/17/04
Exactly  Jeff Spicoli | 08/17/04
You average user you NT  seosamh_z | 08/17/04
I wonder how long will the unpatched Mac  Laff | 08/18/04
A long time. Nobody's interested  seosamh_z | 08/18/04
the "average user"  ryusen | 08/18/04
right  Jeff Spicoli | 08/17/04
re: right  cbradshaw@... | 08/19/04
Easy...  ScottT | 08/17/04
XP SP2 Patched PCs Crash in 5 Minutes  itanalyst | 08/17/04
Mac  nomorems | 08/17/04
Unfortunately....  Flablooie | 08/18/04
How about 5 seconds?  keltek | 08/17/04
you are correct...  Monkey_MCSE | 08/17/04
Very true  toadlife | 08/17/04
No Maccy?  Jeff Spicoli | 08/17/04
My experience with Macs is...  toadlife | 08/17/04
Forgot Mac  nomorems | 08/17/04
yep  toadlife | 08/17/04
COMPREHENSIVE GUIDE TO SECURING A NEW WINDOWS SYSTEM  itanalyst | 08/17/04
Re: COMPREHENSIVE GUIDE TO SECURING A NEW WINDOWS SYSTEM  DragonBRockin | 08/17/04
Re: Comprehensive Guide To Securing A New Windows System  in-DUH-vidual | 08/17/04
RE: Comprehensive Guide...  alajon | 08/19/04
Yet another ZDNet article lacking in details...  Michael Kelly | 08/17/04
Oh and one other thing...  Michael Kelly | 08/17/04
You bet  nomorems | 08/17/04
So the article's up to scratch then  seosamh_z | 08/17/04
Yes, it does happen  Fred Fredrickson | 08/17/04
The details....  Jomo_z | 08/17/04
Lacking in Details  CodeBubba | 08/19/04
Re: Yet another ZD Net. . .  seatech1 | 08/19/04
Simple Solution!!!  Heatlesssun | 08/17/04
Never work.  seosamh_z | 08/17/04
Yet another ZDNyet article with a deceptive title  Seething Ganglia | 08/17/04
Did you not understand the article? NT  seosamh_z | 08/17/04
WHAT THE TITLE OF THE ARTICLE SHOULD BE  itanalyst | 08/17/04
Like SQL Server Worm  brenthawkinsmd | 08/17/04
Nice try  seosamh_z | 08/17/04
So Strange That Anyone Would Defend Microsoft...  brenthawkinsmd | 08/17/04
It's not strange at all  seosamh_z | 08/17/04
I bet you're proud...  brenthawkinsmd | 08/17/04
Morals  seosamh_z | 08/17/04
Are you trully willing to do "What ever it takes"  Laff | 08/18/04
To Laff: Whatever it takes  seosamh_z | 08/18/04
Morals  CodeBubba | 08/19/04
well about moving jobs to India..  computer_man | 08/17/04
So strange anyone wouldn't...  No_Ax_to_Grind | 08/18/04
even more strange that...  ryusen | 08/18/04
Not quite true.  Joel R | 08/18/04
Blasphemy!  toadlife | 08/17/04
Like I Said...  brenthawkinsmd | 08/17/04
Doctor. doctor, it hurts when I do this  seosamh_z | 08/17/04
Uh huh. Go on with your elitism  toadlife | 08/17/04
No Firewall?  ScottT | 08/17/04
Like I Said...  CodeBubba | 08/19/04
Where's our buddy No_Ax running to MicroSloth's Defense?  itanalyst | 08/17/04
Your thick, sloping cranium tells me you're a Linux user.  chrislovesdana | 08/17/04
My thick sloping cranium tells you I should have read your post first.  chrislovesdana | 08/17/04
I heard about a guy in Des Moines  itanalyst | 08/17/04
I heard...  Martin Marvinski | 08/17/04
I heard at the factory, when they test the ethernet port..  Xunil_Sierutuf | 08/17/04
PC infected cause the owner had flu ...  Ardian Daka | 08/18/04
It's worse than you think.  Joel R | 08/18/04
If you're dumb enough to give an unpatched system a public ip address.....  chrislovesdana | 08/17/04
I would fix my own brakes  Martin Marvinski | 08/17/04
EXACTLY!!!!  itanalyst | 08/17/04
Yes but  seosamh_z | 08/17/04
You're missing the point  chrislovesdana | 08/17/04
That's not going to happen  seosamh_z | 08/17/04
right - cause ms makes it so simple  V Sanders | 08/17/04
The biggest security vulnerability on your computer is the power button.  chrislovesdana | 08/17/04
What rubbish!  No_Ax_to_Grind | 08/17/04
"Interation?"  Judas I. | 08/17/04
No user interaction?  Fred Fredrickson | 08/17/04
I have to disagree with you.  computer_man | 08/17/04
AHAHAHA, wrong  Valis Keogh | 08/17/04
Ran a test over night. Nothing.  No_Ax_to_Grind | 08/18/04
Um..  Patrick Jones | 08/18/04
Good oh then ... RTFA  Fred Fredrickson | 08/18/04
Can you define "unpatched"?  No_Ax_to_Grind | 08/18/04
Can you read?  sa_z | 08/18/04
DMZ port?  sa_z | 08/18/04
No, my router allows one port to be a DMZ.  No_Ax_to_Grind | 08/18/04
No and neither does yours.  sa_z | 08/18/04
Oh, I am so NOT impressed.  No_Ax_to_Grind | 08/18/04
1.5  sa_z | 08/18/04
Depends which port you are talking about  voska | 08/18/04
They do ..... LoL  computer_man | 08/18/04
This lines shows the problem  voska | 08/18/04
Well i think that's what their problem is.  computer_man | 08/18/04
To SA and Ax before you start bashing yourself with keyboards  computer_man | 08/18/04
It's really simple  agottschald | 08/19/04
The idea is to turn off the firewall  Taz_z | 08/18/04
Chanllenge?  sa_z | 08/18/04
Default configuration is not "properly configured"  CobraA1 | 08/18/04
Spam: TalkBack Ignore List  marksashton | 08/17/04
?  Linux User 147560 | 08/17/04
You did not...  computer_man | 08/17/04
Well that explains it!  Linux User 147560 | 08/17/04
Sorry, won't work...  Plain Logic | 08/17/04
You're so sweet NT  seosamh_z | 08/17/04
It make take time but it will work.  computer_man | 08/17/04
maybe it would if....  V Sanders | 08/17/04
20 minutes? HAH!!!  Dave P. | 08/17/04
The challenge ahead ...  George Mitchell | 08/17/04
Preaching to the choir... tell that to the evil empire  Xunil_Sierutuf | 08/17/04
So what about...  rapson | 08/18/04
Excellent point Carl, but don't get me started on this one!  George Mitchell | 08/18/04
Sneakernet  sa_z | 08/18/04
If sharing your system with hackers is a step forward ...  George Mitchell | 08/18/04
No just use firewall  sa_z | 08/18/04
Another solution for safe LAN file sharing:  Joel R | 08/18/04
Your Point is Well Takin  wiskyjon | 08/18/04
Simple solution = DITCH WINDOWS  ITGuy04 | 08/17/04
Have no fear, the industry is listening...  Xunil_Sierutuf | 08/17/04
Linux and Mac users  Immanuel Tranz-Mischen | 08/17/04
Aren't accronyms done like this  voska | 08/18/04
No..  Patrick Jones | 08/18/04
They do  seosamh_z | 08/18/04
What is a pep(s)? Yes a pro can get into your  Laff | 08/18/04
Peps = people  seosamh_z | 08/18/04
Is the difference betwen your PC and Mac as  Laff | 08/18/04
Where are you going today?  seosamh_z | 08/18/04
Load system disconnected from net  FilledOut | 08/18/04
New process for patching?  sa_z | 08/18/04
Or use Knoppix  bit_rot | 08/18/04
Some of the techs at work proposed such  FilledOut | 08/18/04
Easily resolved; simply build systems off-line.  JonathonDoe | 08/18/04
Home users?  sa_z | 08/18/04
Jonathon has a point ...  George Mitchell | 08/18/04
One step further  sa_z | 08/18/04
Pure Garbage, hype the fear, ZDNET should be ashamed  Protector | 08/18/04
Which world do you come from?  George Mitchell | 08/18/04
He just doesn't turn them on - ultimate safety  j.m.galvin | 08/18/04
What about MSBlaster and the like?  voska | 08/18/04
I disagree - it's not fair to blame the users  sfphil | 08/18/04
German security firm warning of security flaws in SP2  whisperycat | 08/18/04
Yeah read that too  voska | 08/18/04
M$ is SOOOO weak  NonZealot | 08/18/04
Install behind a firewall  Dawnsman | 08/18/04
It's Time to Protect Your Product Manufacturers  wiskyjon | 08/18/04
Using rcn.com WinXP+SP1 is destroyed in under one minute  sfphil | 08/18/04
Unpatched PCs won't last 20 minutes  pbiss | 08/18/04
Patches vs Firewalls  Sabro | 08/19/04
only 20 min  maartin@... | 08/19/04
20 minutes?  Suprchief | 08/19/04
How did you test to find Compromise  johnydii@... | 08/19/04

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

CIO Sessions

advertisement
Click Here