ARN

Storm worm can befuddle NAC

Interop attendees hear of new threats, countermeasures … and retaliation

A newly discovered capability of the Storm worm could invalidate results churned out by NAC products, attendees at Interop New York learned last week.

This new trick is Storm's ability to interrupt applications as they boot up and either shut them down or allow them to appear to boot, but disable them, says Josh Corman, host protection architect for IBM/ISS.

Users will see that, for example, antivirus is turned on, but actually it isn't scanning for viruses, or as Corman puts it, it is brain dead. "It's running but it's not doing anything. You can brain-dead anything," he says.

NAC vendors acknowledged at the show that this capability could thwart the endpoint checking that their products perform. NAC scans devices before they gain admission to networks looking for the likes of properly patched operating systems and personal firewalls and antivirus software that is updated and turned on.

If the software seems turned on but is doing nothing that would invalidate the scan, say representatives of NAC vendors ConSentry, Juniper and McAfee. "This is an example of why pre-admission NAC is not enough," says Michelle McLean, director of marketing for Consentry.

Analyzing what devices attempt to do once they are on the network - post-admission NAC - is necessary as a backstop to pre-admission tests, says Vimal Solonki, senior director of product marketing for McAfee.

Storm also exemplifies the sophistication of new malware that retaliates against researchers studying it with the goal of stamping it out, Corman revealed at the show.

The worm can figure out which users are trying to probe its command-and-control servers, and it retaliates by launching distributed DoS attacks against them, shutting down their Internet access for days, he says.

"As you try to investigate [Storm], it knows, and it punishes," he says. "It fights back."

Come socialise with us! Facebook | LinkedIn

More about: Adaptive Edge, Avaya, Cisco, ConSentry, Forrester Research, Hewlett-Packard, HIS Limited, HP, HP ProCurve, IBM, IEEE, Interop, ISS, Juniper, McAfee, Panda, Panda Software, Trapeze Networks

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the ARN comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Whitepapers
Latest Stories
Community Comments
ARN Directory | Distributors relevant to this article
24/7 Distribution , ACA Pacific , Alloys , Annuity Systems , ASI Solutions , Australasian PC Distributors (APCD) , Australian IT Spares , Avnet Technology Solutions , Banksia Software , Dicker Data , Distribution Central , Express Data , Express Online , Impact Systems Technology , Ingram Micro Australia , Leader Computers , Leading Pacific Australia , Lynx Technologies , MPA Systems , Multimedia Technology , Nexsan , POS POS , Simms International (For Simms International please see Express Online) , Synnex Australia , Topstar Computer International , Unity Systems , VExpress Distribution , Wavelink , Westcon Group , XiT Distribution , Xpress I.T. , Dynamic Supplies , EMPR Australia , Fusion Power Systems , Sektor
ARN Directory | Vendors relevant to this article
HP
rhs_login_lockGet exclusive access to ARN's news, research and invitation only events.
ARN Distributor Directory
ARN Vendor Directory

iAsset is a channel management ecosystem that automates all major aspects of the entire sales,marketing and service process, including data tracking, integrated learning, knowledge management and product lifecycle management.