Presentation is loading. Please wait.

Presentation is loading. Please wait.

By Michael Carlisle CpSc 420 December 6, 2007. Worms – A Definition!  Worm – a program that copies itself from one computer to another.

Similar presentations


Presentation on theme: "By Michael Carlisle CpSc 420 December 6, 2007. Worms – A Definition!  Worm – a program that copies itself from one computer to another."— Presentation transcript:

1 By Michael Carlisle CpSc 420 December 6, 2007

2 Worms – A Definition!  Worm – a program that copies itself from one computer to another.

3 Common Terms  Payload – the code’s harmful results. Example – Nyxem worm – targets files with commonly used extensions ○ ZIP, DOC, PDF, PPT, XLS … ○ Replaces data in those files with the text “DATA Error [47 0F 94 93 F4 F5]” Example – Melissa.U – deletes critical files on Windows computers. ○ Command.com, IO.sys, Ntdetect.com, Suhdlog.dat

4 Common Terms (cont.)  Mitigation – make something less severe, or to eliminate possiblity of adverse action Many types ○ Patches ○ Updates  Propagation – spreading or self- replication of a worm.

5 Good Worms?!?  Xerox PARC – created in the late 1970’s Designed to find idle processors on a network Once found, helped to share processing and improve CPU cycle use efficiency  Welchia (Nachia) Downloaded patches and updates from Microsoft Found the vulnerability it used and patched it Many considered this a malicious worm ○ Created a lot of traffic ○ Rebooted computers

6 Malicious Intent  Melissa – macro virus Attacked Outlook and Word Distributed by an infected attachment Sends infected file to first fifty e-mail addresses encountered modified Word documents by adding a quote from “The Simpsons” Damage – 300 – 600 million dollars!

7 Malicious Intent  ILOVEYOU VBscript appeared as e-mail attachment (LOVE-LETTER-FOR-YOU.TXT.vbs) Overwrote music and image files with copy of itself Damage – 10 to 15 billion dollars! http://www.dia.unisa.it/~ads/corso-security/www/CORSO-0102/macrovirus/ilovey3.jpg

8 Malicious Intent  Mydoom – one of the fastest spreading worms ever Transmitted by e-mail Finds local files – address book Finds folders entitled “shared folder” to spread via file sharing networks Supposedly responsible for… ○ Decrease 10% in global Internet performance ○ 50% decrease Web load times

9 ILOVEYOU Worm  Searches Microsoft Outlook address book and retrieves all addresses  No limit in number of recipients  Social engineering – e-mails addressed with subject “ILOVEYOU”  Works only with systems that have WSH (windows scripting host) installed  Copies itself to 2 directories Main windows directory ○ File named Win32DLL.vbs System directory ○ File named MSKernel32.vbs  Modifies Windows Registry to make sure it runs during every boot  Overwrites music and image files and copies itself… adds.vbs extension  Searches for mIRC Tries to send html file across IRC channels File has prompt to download an ActiveX control

10 ILOVEYOU Worm (cont.) HTML file sent through IRC

11 Preventative Measures  Education, Education, Education! User’s need to be aware of common worm tactics (social engineering)  Updates Make sure software is updated regularly IMPORTANT – OS updates regularly!  Patches

12 Any Questions?

13 References  Bezroukov, Dr. Nikolai. “Melissa Worm/Virus – a Worm Parasiting on Ms Office 97 Architectural Problems and Ms Word Users’ ignorance.” 6 March 2007. 1 December 2007.  “Computer Worm”. Wikipedia, The Free Encyclopedia. 7 November 2007. 1 December 2007.  “ILOVEYOU”. Wikipedia, The Free Encyclopedia. 30 November 2007. 1 December 2007.  Kehoe, Brendan. “Zen and the Art of the Internet.” 1992. 27 November 2007.  Landesman, Mary. “Nyxem aka Blackmal Worm.” 29 November 2007.  “Melissa Worm.” Wikipedia, The Free Encyclopedia. 7 November 2007. 1 December 2007.  “Mitigation.” The Free Dictionary. Farlex. 30 November 2007.  “Morris Worm.” Wikipedia, The Free Encyclopedia. 28 November 2007. Wikimedia Foundation. 1 December 2007.  Seeley, Donn. “The Internet Worm of 1988.” 27 November 2007.  “VBS.ILoveYou.A”. CA. 11 October, 2005.  “Welchia”. Wikipedia, The Free Encyclopedia. 7 November 2007. 1 December 2007.


Download ppt "By Michael Carlisle CpSc 420 December 6, 2007. Worms – A Definition!  Worm – a program that copies itself from one computer to another."

Similar presentations


Ads by Google