The Coming Age of Defensive WormsDavid Meltzerdjm@.ppt
《The Coming Age of Defensive WormsDavid Meltzerdjm@.ppt》由会员分享,可在线阅读,更多相关《The Coming Age of Defensive WormsDavid Meltzerdjm@.ppt(40页珍藏版)》请在麦多课文档分享上搜索。
1、The Coming Age of Defensive Worms David Meltzer CTO, Intrusec,Why?,“I dont know whether a good worm can be safe and effective, but this merits serious technical study.”- Martha Stansell-Gamm (May 26, 2003)1 Chief, Computer Crime and Intellectual Property Section, U.S. Department of Justice,What Wil
2、l You Learn?,The history of good wormsThe problems with defensive wormsHow defensive worm problems are solvedPossible evolutionary steps,The Question,Will anyone in charge of a large network ever willingly launch a worm on their own network to protect it?,Worm Reality,A new exploit just came out.You
3、 have 5,000 vulnerable systems.The worm is coming.What do you do?,The Worm Antidote,It fixes all the systems on your network.It does it faster than the worm can spread.It only infects your own systems.Do you run it?,Which Worm Do You Want?,What Will You Learn?,The history of good wormsThe problems w
4、ith defensive wormsHow defensive worm problems are solvedPossible evolutionary steps,“Good Worms”,A Worm, BUT A “beneficial” payload BUT Still Disruptive to networks Runs without permission Requires clean-up ILLEGAL,What Do “Good Worms” Do?,ScanListenExploitPatchDisinfect,Timeline of “Good Worms”,19
5、99,2000,2001,2002,2003,Case Study: Millenium2,3,Discovered 8/15/99 Written by Mixter4 Multiple Linux Vulns: Scans, Patches, BackdoorsScans for systems vulnerable to 5 remote linux holes Exploits remote system Patches 5 linux vulns Installs a backdoor Sends notification to hotmail address of infectio
6、n Installs itself on system,Case Study: Cheese5,Discovered 5/01 Unknown Author Lion Worm Response: Scans, DisinfectsScans for systems infected by Lion Installs itself using backdoor left by Lion Removes Lion backdoor from system,Case Study: Code Green6,Code Released 9/1/2001 Written by Der HexXer Co
7、de Red Response: Scans, Disinfects, Patches Scans for systems infected with CodeRed Exploits ISAPI vuln on infected systems Removes CodeRed from system Installs Q300972 Hotfix on system Installs itself on system,Case Study: CRClean7,Code Released 9/1/2001 Written by Markus Kem Code Red Response: Lis
8、tens, Disinfects, Patches Listens for CodeRed to attack it Exploits ISAPI vuln on CodeRed attackers Removes CodeRed from system Patches ISAPI vuln on system Installs itself on system,Industry Thinking on “Good Worms”,“Generally Not Well Regarded” eEye8,Industry Thinking on “Good Worms” - Continued,“
9、The idea of a patch worm is a nice thought, but it is not a solution” - CERT9,Industry Thinking on “Good Worms” - Continued,“You cannot predict whats going to happen. You dont know what the impact is going to be if its altered. Its never an alternative.” Trend Micro10,Industry Thinking on “Good Worm
10、s” - Continued,“You cannot predict whats going to happen. You dont know what the impact is going to be if its altered. Its never an alternative.” Trend Micro10,Industry Thinking on “Good Worms” - Continued,“-What about the traffic it takes up? -What about the boxes that dont patch properly, dont mak
11、e it back after reboot, or took down etrade in the middle of a trading day? -How does your worm know when its done?-Maybe I dont want my box patched, the patch broke my app -How do I tell your good worm apart from the original bad worm, or the other worm which looks like the good worm, but is really
12、 a bad worm?-How about people like us who track attack data, and you just skewed the heck out of it? When does www1.whitehouse.gov get to come back? If theres still *A* worm around on the 1st, which one is it?-Do we really want an Internet-sized game of corewars?”,Industry Thinking on “Good Worms” -
13、 Continued,“Visions of bots floating around in the ether waging mighty, but invisible, battles belong in books such as Neal Stephensons “The Diamond Age,“ not on production Internet servers.” Timothy Dyck11,Industry Thinking on “Good Worms” - Continued,“ Worms are inherently uncontrollable, meaning
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- THECOMINGAGEOFDEFENSIVEWORMSDAVIDMELTZERDJMPPT

链接地址:http://www.mydoc123.com/p-373241.html