Storm worm can befuddle NAC

News
Oct 25, 20077 mins

Interop attendees hear of new threats, countermeasures … and retaliation

NEW YORK – A newly discovered capability of the Storm worm could invalidate results churned out by NAC products, attendees at Interop New York learned last week.

This new trick is Storm’s ability to interrupt applications as they boot up and either shut them down or allow them to appear to boot, but disable them, says Josh Corman, host protection architect for IBM/ISS.

Users will see that, for example, antivirus is turned on, but actually it isn’t scanning for viruses, or as Corman puts it, it is brain dead. “It’s running but it’s not doing anything. You can brain-dead anything,” he says.

NAC vendors acknowledged at the show that this capability could thwart the endpoint checking that their products perform. NAC scans devices before they gain admission to networks looking for the likes of properly patched operating systems and personal firewalls and antivirus software that is updated and turned on.

If the software seems turned on but is doing nothing that would invalidate the scan, say representatives of NAC vendors ConSentry, Juniper and McAfee. “This is an example of why pre-admission NAC is not enough,” says Michelle McLean, director of marketing for Consentry.

Analyzing what devices attempt to do once they are on the network – post-admission NAC – is necessary as a backstop to pre-admission tests, says Vimal Solonki, senior director of product marketing for McAfee.

Storm also exemplifies the sophistication of new malware that retaliates against researchers studying it with the goal of stamping it out, Corman revealed at the show.

The worm can figure out which users are trying to probe its command-and-control servers, and it retaliates by launching distributed DoS attacks against them, shutting down their Internet access for days, he says.

“As you try to investigate [Storm], it knows, and it punishes,” he says. “It fights back.”

As a result, researchers who have managed to glean facts about the worm are reluctant to publish their findings. “They’re afraid. I’ve never seen this before,” says Corman. “They find these things but never say anything about them.”

And not without good reason, he says. Some who have managed to reverse engineer Storm in an effort to figure out how to thwart it have suffered distributed DoS attacks that have knocked them off the Internet for days, he says.

As researchers test their versions of Storm by connecting to Storm command-and-control servers, the servers seem to recognize these attempts as threatening. Then either the worm itself or the people behind it seem to knock them off the Internet by flooding them with traffic from Storm’s botnet, Corman says.

The sheer variety of attacks against corporate networks is also soaring, according to a study released at the show. The number of new pieces of malware has spiked dramatically starting in February, marking a new phase in attack production, security experts say.

“That’s the change in motivation,” says Ryan Sherstobitoff, product technology officer for security vendor Panda Software, which presented the results of its security survey at the show. “That’s where the business model kicks in.”

“The motivation has shifted from prestige to profit to political,” says Corman. That means that rather than writing code for massive disabling of systems and reveling in twisted glory, the writers of malicious code are writing for profit or to commit cyberterrorism.

Just as motivation is shifting, the quality of the attacks is improving, he says. They are targeted at individual companies or persons with the goal of stealing intellectual property or valuable personal data.

One security executive at the show who could not speak for attribution because his company does not allow it, said he has encountered attacks tailored for individual executives within his corporation.

According to Sherstobitoff, makers of malware no longer write it and toss it directly into the wild, but test it to find out whether it is effective against likely corporate defenses. These criminals perform quality assurance and even offer the equivalent of service-level agreements on how effective their wares will be, he says.

Meanwhile, show-goers were told they need new architectures to protect corporate networks against changing threats while also opening those nets to access anytime, anywhere, and from any place.

Architectures optimized for distributed applications in 2005 evolved into those focused on security and IT consolidation in 2006, says Chris Silva, an analyst at Forrester Research. This year’s wave will be LAN infrastructures designed to accommodate disaster recovery and further consolidation.

Enterprises want their networks to function as a utility, and wireless coverage will drive infrastructure deployments, Silva says. With that, he believes IEEE 802.11n wireless LANs and WiMAX will become pervasive in the 2011-13 time frame.

HP ProCurve believes the next-generation LAN architecture will be a 50:50 mix of wired and wireless infrastructures, and consistent with the Adaptive Edge vision the company put forth in 2003. That plan involves putting more network intelligence, such as 802.1X authentication as well as Layer 2 and Layer 3 QoS and NAC security services, in enterprise wiring closets. All processing is distributed and all intelligent devices are able to execute services and initiate resource access control.

“Those are the foundational elements of how these issues would be addressed,” said John McHugh, vice president and general manager of HP ProCurve.

McHugh said the next-generation LAN should not be based on a constraining proprietary architecture with features that are “bolted on” instead of integrated into the fabric.

“This is very difficult with an overlay structure,” he said. “And it should be done in a way that is open – a hosting environment for best of breed” products.

Along with ubiquity, users will demand security and integration with wired and voice infrastructures. That’s fine with wireless companies like Trapeze Networks and secure switching vendors like ConSentry.

Components of the “new” LAN include mobility, security and identity-based networking – the ability to configure users’ access and services as opposed to what switch and router ports they can use, says David Cohen, Trapeze director of marketing.

The LAN architecture will encompass a hybrid of distributed forwarding and centralized forwarding based on the application: distributed for latency-sensitive traffic like voice over WLAN and “.11n ready” applications; and centralized for security-sensitive traffic like guest access, Cohen says.

Switches will support “virtual stacking,” Cohen says, in which capacity is pooled and automatically assigned, remapped and balanced across access points when they are added to or subtracted from the network.

This is not unlike the challenges facing enterprises in branch-office networking. More than 90% of employees work in a branch or remote office. Yet the branch is made up of a disparate set of technologies, capabilities and functionalities that increase the cost of doing business and the inconsistency of the customer experience, says Steve Hardy, Avaya director of converged communications product marketing.

“The branch is a much more strategic part of the business plan, Hardy says, adding that it’s morphed from a cost center to a profit center. “The branch is the place where business interacts with its customers. The customer experience will be the key driver of the technology refresh.”

Some of the considerations enterprises must deal with are whether business applications need to be centralized or distributed to branch locations, he says. Integrated security is “critical,” he claims, as is an “open, standard converged infrastructure” to maximize total cost of ownership.

But therein lie some opposing goals, Hardy says: maximizing application reach while minimizing TCO. That’s why enterprises will increasingly adopt hybrid models where some applications are hosted at the headquarters site, others in the branch and others with the company’s telecom carriers.

Cisco concurs with the hybrid model of application hosting in the next-generation branch office. Cisco says the numbers of branches are growing 10% per year, consuming 70% of a company’s IT resources.

Branch employees are also computing different than they did three to five years ago, says Michael Wood, director of product management in Cisco’s Access Routing technology group. They are mobile, executing Web 2.0 applications and performing mashups, he says.

“Their expectations and experiences are much different,” he says. “They’re more interactive.”