- Microsoft will float cloud OS this month
- Top 16 Chinese iPhoneys
- Pimp your ride: Cool car technology
- Laptop stolen from McCain campaign
- Cisco, Microsoft roll out server, networking appliance
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Value of WDS
While organizations around the world this week scrambled to disinfect and patch systems that had been hit by the dangerous new W32.Blaster Internet worm, John Halamka could sit back and relax.
"I'm proud to say we don't have a single copy (of Blaster) in the hospital," said Halamka, CIO of Beth Israel Deaconess Medical Center (BIDMC) in Boston, a Harvard University research institution.
BIDMC's good news on Blaster came amid reports of the new worm's continued spread on Wednesday and the appearance of new worm variants on the Internet.
It was also a marked contrast to the scene at BIDMC in January after the SQL Slammer worm crippled the hospital's computer systems for about six hours, forcing medical staff to resort to paper-based records to track patients.
With Slammer, Halamka's staff patched their Microsoft SQL Server software prior to the worm's release. However, like many Microsoft customers, BIDMC was blindsided by an overlooked component on Windows XP desktop machines called the Microsoft Data Engine 2000 (MSDE). MSDE was also vulnerable to SQL Slammer and the worm was able to infect computers in the hospital's research labs and private offices. It then flooded the rest of the network with traffic, according to Halamka.
So when Microsoft warned customers in July of the RPC (Remote Procedure Call) vulnerability - the one later exploited by W32.Blaster - Halamka and his staff weren't taking any chances.
BIDMC staff updated their network firewall configurations to block the ports, such as 135 and 4444, which were identified by Microsoft as avenues that could be used to exploit the new vulnerability, according to Halamka.
The hospital also promptly updated its intrusion detection systems with the appropriate signatures to detect and warn about traffic associated with scans for vulnerable systems, according to Kristofer Karas, senior security engineer at BIDMC.
Then came the patching.
Not wanting to fall into the same trap as with the Slammer worm, Halamka developed an aggressive schedule for patching servers and desktop machines at BIDMC.
On the server side, the IT staff held what Halamka called an "all nightmare-athon" patching session in late July, applying the relevant Microsoft patches to the hospital's 130 Windows servers.

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Vulnerability Management For DummiesDownload this concise book "Vulnerability Management for Dummies," to learn about the simple steps...
Security Considerations When Deploying Remote Access SolutionsEffective network security is most successful when you use a layered approach, with multiple...

The Vista era of Windows is here. Yet most organizations will retain Windows XP alongside new Vista...
Turning information into a Competitive AdvantageCompanies today are realizing that competitive advantage is harder to sustain when based solely on...
PoE Plus: Impact on the PoE MarketThe standard for Power over Ethernet (PoE), IEEE Std. 802.3af(tm)-2003, advanced networking,...

Discover why Unified Threat Management Firewalls are ready for the enterprise today. High...
The Evolution of Network SecurityWe have so many holes punched in our firewalls today that many industry insiders question the value...
The self-managed networkWe aren't there yet, but advances in network and systems management tools are making it possible to...
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment