Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
/

Denial of service and the worm

Today's breaking news
Send to a friendFeedback

Advertisement:


When Worm.ExploreZip hit corporate networks a couple weeks ago, I was sitting in the lobby of a large corporation waiting to interview the security director of the firm's electronic commerce subsidiary. When he finally arrived, he told me that the corporate bigwigs had shut down all Internet mail access and, as a result, the e-commerce subsidiary would lose "hundreds of thousands or millions of dollars."

The firm's corporate IS group and other units were vulnerable to the worm, so upper management cut off all incoming e-mail at the firewall to buy time for inoculating various Microsoft Exchange servers and gateways. But because e-mail is the e-commerce subsidiary's lifeblood, its security group had already deployed measures to deal with the worm. Hence the security director's frustration with the decision to shut down e-mail corporatewide.

This episode illustrates that worms and viruses are not only disruptive and destructive, they're also denial-of-service attacks. Like a bomb scare, a virus threat can cause disruption and economic damage even if no physical damage occurs. But while a physical bomb affects only one location, viruses are everywhere.

We've also seen that corporate capabilities to combat viruses are a mixed bag. This kind of problem will get worse if random acts of vandalism, such as the Worm.ExploreZip and Melissa viruses evolve into more sophisticated information warfare, including information terrorism between competing nations, corporations and other groups. Worm.Explore-Zip, which targets Microsoft, already looks like information warfare.

The attacks seem to be occurring more frequently, and the denial-of-service implications are increasingly obvious. The days when enterprises could just shut down Internet mail are coming to an end. E-mail is too mission-critical to be cut off everywhere.

Containing viruses requires a layered defense. Install countermeasures in firewalls, gateways, servers and desktops. Deploy intrusion-detection technology that brings your network to a heightened state of alert and increases scanning at the first sign of trouble. Also, increase end-user education efforts and lean on the ISPs - they should bear some responsibility for letting viruses propagate through their networks to yours.

Dealing with the denial of service requires clearly communicated policies. Where business units sharing a messaging network have different defensive capabilities or risk tolerances, and where the criticality of e-mail varies across units, IS departments must find ways to selectively quarantine incoming mail or other forms of connectivity. At a minimum, get the business units to agree to general contingency protocols in advance, or allocate funding to build the flexibility they say they must have. Don't let denial of service threaten the basic consensus on which your shared messaging network depends.

RELATED LINKS

Blum is a senior vice president and principal consultant with The Burton Group, an IT advisory service providing in-depth analysis for network planners. He can be reached at dblum@tbg.com.

What do you think? Jump into nwfusion.talk and start a thread.

More Intranet Advisorr columns


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.