Security - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Cisco Small Business Advantage
  • Register for WES 2010 by February 19 and save $400.
  • up.time Easily Monitors Virtual/Physical/Cloud. Free Trial.
  • Seagate® Barracuda® drives fit every desktop need.
  • MSP Partners helps solution providers stay competitive.
  • Learn more about EnterpriseDB @ the Postgres Center
  • Earn 40-50% margins. Zenith open houses show how.
  • CDW Healthcare offers the IT solutions you need.
  • One number. One voicemail. Sprint Mobile Integration.
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily.
  • Give your customers more with LSI 6Gb/s solutions.






  • Channel Insider conferred 75 awards to vendor, distribution, solution provider and industry groups for performance excellence. Check out all the winners in the 28 Bull’s Eye Award categories.
    >> Bull’s Eye Central


     

    Conficker: Don`t Be Made a Fool April 1

    in Security


    Article Rating:starstarstarstarstar / 4
    Article Views: 6867

    Rate This Article:
    Add This Article To:
    Conficker.C’s reported update on April 1—April Fool’s Day—has put the hype machine in overdrive with dire warnings of massive distributed denial of service attacks. The threat is still relatively unknown, but the reality is malware writers have no motivation for causing massive outages. Here’s why.

    In just three short days the world will learn how dangerous the latest variant of the Conficker worm is. Some reports say that more than 10 million PCs are already infected and the activation of the worm will cause massive distributed denial of service (DDoS) attacks.

    The concern is so great that the alarms have been sounding for more than a week and the battlements manned in anticipation of an overwhelming assault by this digital menace.

    Conficker concerns have created a wave of hype so great that the FUD threatens to overwhelm networks and administrators more so than the actual worm. Over the weekend, Symantec even warned that searching for information about Conficker could open users to compromise by the malware.

    The truth about malware is much more sublime and boring than the hype of pending disaster and unthinkable destruction.

    Resource Library:

    Here are a few truths to consider:

    1) Destruction Isn’t the Aim
    Let’s face reality here: taking down the Internet or disabling networks serves no hacker’s ultimate purpose. What malware writers really want is to infiltrate networks and gain access to data and computing resources. The days of hacker meritocracy earned through digitally destructive acts, such as those caused by the LoveLetter virus, have given way to profit schemes in which malware and hacking skills are used to snoop on networks.

    2) Botnets are Business
    Conficker.C, the variant that’s supposed to go live on April 1, is likely designed to create a botnet, which draws power from individual PCs and corporate networks for distributed computing. Experts say we’ll have to wait until Conficker phones home to get new instructions to discover what its real intent is. Even if it’s just there to create a botnet, a botnet in and of itself is a valuable tool that organized hackers are renting out to others for big bucks.

    3) Anti-virus Works
    The standard advice in advance of a massive malware outbreak is to ensure AV signatures are up to date and real-time scans are enabled. The first round of Conficker was contained in many Western countries by standard AV applications. But anti-virus and anti-spyware applications are like squelching devices, they capture what you expect them to capture – largely the nosiest pieces of malicious code. More advance piece of malware require close inspection and, oftentimes, human remediation.

    4) Conficker: The Wrong Call to Arms
    Symantec, Kaspersky Lab and Sophos each reports that 2008 was the worst year for malware in the wild. Over the last decade, the volume of malware has steadily increased. In the last 12 months, the number of malware samples in circulation skyrocketed from tens of thousands to more than 600,000 new original and variant codes. While Conficker.C is a significant, predictable event, the malware trend requires constant vigilance among IT and security managers, IT solution providers and services companies, and individual end users.

    FUD (fear, uncertainty and doubt) isn’t an entirely useless tool, since such massive publicity and misinformation about a single event can open many opportunities for IT solution providers to engage with their customers about the security of their networks and systems.

    Containing Conficker and other such malware requires a combination of policy, product and practices.

    Solution providers should talk with their clients about ensuring users are not downloading unknown files, clicking on suspicious links that take them to malicious or compromised Websites, or disabling their security agencies on their clients.

    Synergistic security technologies are still the best defense against compromises. A combination of endpoint security controls, tight configuration management and policy enforcement, Web filtering and reputational analysis of Websites, and standard malware detection and removal technology goes a long way toward preventing infection. Additionally, network monitoring technology, intrusion prevention systems, and data loss prevention technologies help mitigate the chances of a worm using a network for malicious purposes or stealing data.





    Discuss Conficker: Don`t Be Made a Fool April 1
     
    I have windows Vista but I don't worry about these viruses or spywares. I have tech...
    >>> Post your comment now!
     

     
     
    >>> More Security Articles          >>> More By Lawrence Walsh
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How much time do you spend hunting for enterprise IT content?
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com
     
    Should You Be Using “up.time”?
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and along with best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Free Trial Download Here (Virtual Appliance available)
    Managed service providers are using regulatory compliance and industry standards to win business and give customers peace of mind. Join host Larry Walsh of Ziff Davis Enterprise and his guests on Friday, February 19, 2010, at 1:00 pm ET for a discussion of “Compliance as a Service.”
    Register Today