Commentary

Michael Hickins
 

Are We Getting Con-Ficked?

Conficker, the super virus that was going to bring down the Interweb, seems to have flopped -- unless, in true horror film tradition, it isn't really dead.

Conficker, the super virus that was going to bring down the Interweb, seems to have flopped -- unless, in true horror film tradition, it isn't really dead.Conficker was supposed to cause 50,000 PCs around the world to rise up against their human masters on April 1, and since that failed to happen, has been called a hoax and "much ado about nothing."

But neither could be further from the truth. The likes of Ron Rivest and SRI International, which specializes in cybersecurity research, don't work feverishly through the night to find a fix for a figment of someone's imagination.


More Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

But Conficker also begs the question of whether an entire anti-virus industry isn't profiting from periodic scares of this kind. It sure isn't making money by actually solving the problem, and it's not for lack of resources or brains. Conficker is a clever bug for sure, but it wasn't created by evil super-geniuses from another planet.

In fact, while the bug has some innovative features, it relies on a well-known vulnerability, the buffer overflow, to infect computers.

I spoke to one security vendor, Comodo, whose CEO claims that none of his customers have been infected. Melih Abdulhayoglu claims anti-virus makers can't say the same because their protections allow all programs to execute their code by default; they're only stopped if they're on a blacklist.

Comodo blocks all programs by default, and forces users to allow them to execute. Comodo also uses heuristics -- essentially, behavioral analysis -- to detect when a program is behaving abnormally, and blocks it on the spot. Buffer overload would fall into that category.

The reason anti-virus vendors like McAfee, Symantec and Trend Micro can't stop it is because they rely on reactive techniques: they identify a bug, create a signature, and then send the signature to their customers so they can prevent the bug from coming in.

It's a bit like faxing over a picture of Keyser Soze to the police station once he's left the building, or a photograph to border security after the terrorist has already gone through customs. It's too late.

Why don't anti-virus vendors adopt the same default-deny technique as Comodo? Abdulhayoglu refused to speculate about his competitors, but I will.

One thing I think is that vendors know that users simply won't tolerate any kind of friction. If I have to wait fifteen seconds for a program to load because of a security check then, doggone it, I'm going to turn it off.

The other reason? As I said earlier, having some super bug out there doesn't hurt sales. That might sound a little like blaming the pharmaceutical industry for an outbreak of Ebola, but at least the health care system does manage to show progress from time to time.

Which brings me to another thing: whoever named it Conficker is a marketing genius. I haven't heard a name that menacing since Lex Luthor.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links