On CNET: Check out the 2010 Toyota Prius
BNET Business Network:
BNET
TechRepublic
ZDNet

By Munir Kotadia
Posted on ZDNet News: Jan 27, 2005 7:37:00 PM

MyDoom first appeared on January 26 and according to antivirus firm F-Secure, during its first day the worm generated more than 100 million e-mails, "a major part of all e-mail traffic globally." During its first two weeks MyDoom hit SCO's Web site with one of the largest DDoS attacks ever recorded and kept the site offline for more than a month.

MyDoom, which was quickly followed by the various Bagle and Netsky variants, indicated that virus writing had been adopted by underground organizations that are motivated by money rather than fame, according to Scott Chasin, chief technology officer at e-mail security specialists MX Logic.

"MyDoom signaled the end of the juvenile worm author and was the bridge to the commercialization of virus and worm writing. There has been a global shift away from the egocentric teenage hacker to the economic-orientated threat. It has also taught us that there is an underground open-source community that actively trades in virus-writing techniques," said Chasin.

Adam Biviano, senior systems engineer at antivirus firm Trend Micro, said that MyDoom didn’t do anything that antivirus firms had not seen before, but it was far more efficient than previous worms.

"Mass-mailing viruses are nothing new--we saw the first one with Melissa in the late '90s--but MyDoom was written in a more sophisticated language so it was able to both fool content filtering systems into allowing its e-mails through and trick users into executing it’s payload,” said Biviano.

Over the past year, Biviano said that worms have generated a large number of variants--more then 30 for MyDoom alone--each of which improve on the previous design in order to stay one step ahead of the IT security community.

"If a vendor comes out with a new product to stop security vulnerabilities being taken advantage of--like on Microsoft’s Windows XP SP2--then the new variants simply take that into account by changing the list of controls and processes that need to be terminated,” said Biviano.

Biviano said he expects variants of MyDoom and other big worms to continue being created and released into the wild.

"I have seen nothing that gives any indication that this will stop any time soon. If you build a smarter mousetrap the mouse gets cleverer,” said Biviano. MX Logic’s Chasin agrees that more variants are on the way but he said one of the biggest challenges will be to try and overcome the social engineering aspect.

"The source code, which anyone can access if they do a smart Google search, is the foundation of future threats. The big problem is the social engineering effect--there is a lot we can do from a technology perspective to minimize the risks but there is always a weak link in the chain and that is usually the human operator," said Chasin.

SponsoredWhite Papers, Webcasts, and Downloads

  • Talkback
  • Most Recent of 1 Talkback(s)
MyDoom--one year and counting  Loverock Davidson | 01/27/05

What do you think?

advertisement
advertisement

White Papers, Webcasts, and Downloads

SmartPlanet

  • Thought-provoking progressive ideas on diverse topics that intersect with technology, business, and life, and matter to the world at large. Visit SmartPlanet
  • More from IBM
  • Innovate your business' process model, play against the market, compete against others on our scoreboards and WIN! Try INNOV8 2.0: A BPM Simulator
  • Enabling Real-World Business Transformation through IBM Service Management Read the EMA Analyst Report
advertisement
Click Here