ad info

 
CNN.com  technology > computing
    Editions | myCNN | Video | Audio | Headline News Brief | Feedback  

 

  Search
 
 

 
TECHNOLOGY
TOP STORIES

Consumer group: Online privacy protections fall short

Guide to a wired Super Bowl

Debate opens on making e-commerce law consistent

(MORE)

TOP STORIES

More than 11,000 killed in India quake

Mideast negotiators want to continue talks after Israeli elections

(MORE)

MARKETS
4:30pm ET, 4/16
144.70
8257.60
3.71
1394.72
10.90
879.91
 


WORLD

U.S.

POLITICS

LAW

ENTERTAINMENT

HEALTH

TRAVEL

FOOD

ARTS & STYLE



(MORE HEADLINES)
*
 
CNN Websites
Networks image


When it comes to security, there's no such thing as crying wolf

Computerworld

June 21, 2000
Web posted at: 10:54 a.m. EDT (1454 GMT)

(IDG) -- Despite the occasional false alarm, it's still better to be safe than sorry when it comes to responding to virus threats.

That's the advice users and analysts have in the wake of reports last week that the so-called Serbian Badman virus wasn't nearly as deadly as had first been feared.

The Serbian Badman scare was triggered June 8 by Network Securities Inc. (Netsec), a relatively little-known Herndon, Va.-based security firm. The company claimed that the Trojan horse, disguised as a video clip, could be used by crackers to launch distributed denial-of-service attacks similar to the ones that crippled several major Web sites earlier this year. (See story.)

  MESSAGE BOARD
 
  ALSO
 

Trojan programs basically allow crackers to remotely control infected systems.

Netsec, which rushed to the FBI with news of its discovery, claimed that it had unearthed at least 2,000 servers worldwide that had already been infected by the Serbian Badman.

The scare ended almost as quickly as it began, though, with security experts quickly dismissing the virus as a mostly harmless version of a much older and well known Trojan horse. Popular security sites such as the FBI's National Infrastructure Protection Center (NIPC) and Carnegie Mellon University's Computer Emergency Response Team (CERT) didn't even issue their usual alerts relating to new virus information.

The incident illustrates how the publicity surrounding recent virus attacks sometimes causes a false alarm. But administrators still need to treat reports of every threat seriously, users and analysts said.

MORE COMPUTING INTELLIGENCE
IDG.net   IDG.net home page
  Virus: A love story
  Practice safe computing
  Let your ISP scan for viruses
  Virus links e-mail to porn sites
  Reviews & in-depth info at IDG.net
  E-BusinessWorld
  TechInformer
  Questions about computers? Let IDG.net's editors help you
  Subscribe to IDG.net's free daily newsletter for IT leaders
  Search IDG.net in 12 languages
  News Radio
  * Fusion audio primers
  * Computerworld Minute

"There is no silver bullet associated with this," said Harry DeMaio, president of Deloitte & Touche Security Services LLC in Deerfield, Ill.

"Firewalls, protective structures and intrusion-detection technologies all help but don't absolutely guarantee that a specific attack will not take place," DeMaio said.

So the only option for users is to make sure they aren't compromised each time a new virus warning comes out, he said.

Despite such incidents, users need to take every threat seriously, said Josh Turiel, a network services manager at Holyoke Mutual Insurance Co. in Salem, Mass.

"There are some real honest-to-goodness threats out there," Turiel said. "So if anything, all this hype (surrounding recent virus attacks) is at least making us feel a little more paranoid about our security."

Such incidents also highlight the need for companies to always have quick access to reliable security information, said Ron Freedman, a vice president of information assurance at USinternetworking, Inc,. an outsourcer of business applications in Annapolis, Md.

Until recently, the company had two full-time staffers to monitor security bulletins and keep track of breaking virus news. Three months ago, the company decided to outsource the task to a newly formed unit of Ernst & Young called eSecurityOnline.com (see story.)

"The number of vulnerabilities that were being identified each day was getting to be overwhelming," Freedman said. "We were spending a lot of time trying to sort out which of those pertained to our environment, what its likely impact was, what the recommended fix was and where we had to go to get it."




RELATED STORIES:
Should you encode your e-mail?
June 16, 2000
Linux security classes now available
June 12, 2000
IT pros debate security of Linux and Unix
June 8, 2000
Second line of defense: Distributed firewalls
June 6, 2000
Senate eyes Guard for info security
June 1, 2000

RELATED IDG.net STORIES:
7 virus killers compared
(PC World)
Virus: A love story
(Sunworld)
Wireless security concerns
(Infoworld)
Spreading viruses is a crime in Pennsylvania
(Civic.com)
Linux's immunity to the Love Bug
(Linuxworld)
Frisking computers at the door
(Network World Fusion)
Virus links e-mail to porn sites
(Computerworld)
Security Watchpage
(Computerworld)

RELATED SITES:
National Infrastructure Protection Center
Electronic Privacy Information Center
Hackers Home Page

Note: Pages will open in a new browser window
External sites are not endorsed by CNN Interactive.

 Search   

Back to the top   © 2001 Cable News Network. All Rights Reserved.
Terms under which this service is provided to you.
Read our privacy guidelines.