Stories
Slash Boxes
Comments

SoylentNews is people

posted by cmn32480 on Monday August 10 2015, @05:45AM   Printer-friendly
from the how-is-this-still-a-thing dept.

From Computerworld:

In late 2008, a worm called Conficker began infecting millions of computers, startling the computer security community into action.

Conficker's quick spread was so alarming that an organization was formed called the Conficker Working Group that was tasked with stopping the botnet and finding its creators.

Many countries also formed their own groups that worked with Internet service providers to remove infections from users' computers. But seven years later, there are still about 1 million computers around the world infected with the malware despite the years-long cleanup effort.

Researchers in the Netherlands have analyzed those efforts and tried to figure out what went right and wrong in order to guide future botnet-fighting efforts. Their research paper will be presented next week at the 24th USENIX Security Symposium in Washington, D.C.

"These people that [have computers which] remain infected -- they might remain infected forever," said Hadi Asghari, assistant professor at Delft University of Technology in the Netherlands.

Hadi Asghari, assistant professor at Delft University of Technology.

In December 2008, Microsoft patched the vulnerability in Windows XP used by Conficker that allowed remote files to be executed if file-sharing was enabled. But Conficker's worm capabilities made it surprisingly resilient, and it continued to infect computers even when researchers took over the botnet's command-and-control system.

Special efforts by individual countries to control Conficker's spread, such as in Finland, helped keep a check on it, Asghari said. Some other advanced countries, including Norway and Sweden, did not have Conficker remediation programs but still managed to keep it under control, he said.

Researchers are still monitoring Conficker-infected computers since they took over control of the botnet years ago. Asghari said his team saw more than 1 million IP addresses of infected machines calling home to a sinkhole for instructions, but it's difficult to figure out what type of machines those are and why they may still be infected.

Asghari said it's likely many computers are probably running Windows XP without automatic updates installed. It's also possible that some of them may be rarely updated or abandoned embedded systems.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by TheRaven on Monday August 10 2015, @08:35AM

    by TheRaven (270) on Monday August 10 2015, @08:35AM (#220587) Journal

    However far-fetched the name "virus" might have been in the beginning, it has become totally appropriate.

    No it hasn't. Computer viruses are still almost completely unlike biological viruses in every way.

    --
    sudo mod me up
    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 0) by Anonymous Coward on Monday August 10 2015, @09:51AM

    by Anonymous Coward on Monday August 10 2015, @09:51AM (#220607)

    Not to mention that (as the summary correctly states) Conficker is a worm, not a virus. While there's a trend to use "virus" for about any type of malware, I think it is still worthwhile to make some differences. A worm can infect an uninfected vulnerable system even if it is left alone doing nothing but its normal operation. A virus, on the other hand, always needs some user interaction, be it starting an infected executable, opening an infected attachment, surfing an infected web site, inserting an infected data storage medium, …

    • (Score: 2) by TheRaven on Monday August 10 2015, @12:16PM

      by TheRaven (270) on Monday August 10 2015, @12:16PM (#220642) Journal
      That's not quite true. A worm is self replicating malware, a virus is malware that embeds itself in another piece of code. Malware can be both a virus and a worm, and a lot of the high-profile viruses have also been worms, which is probably where the confusion comes from.
      --
      sudo mod me up