tgreene
Executive Editor

NAC is on Storm’s path

Opinion
Oct 30, 20072 mins

* Suggestions for preventing Storm worm from affecting NAC

A newly discovered feature of the versatile malware lets it interrupt applications as they boot up and either shut them down or allow them to appear to boot, but actually disable them.

The Storm worm could cause trouble for NAC.

A newly discovered feature of the versatile malware lets it interrupt applications as they boot up and either shuts them down or allows them to appear to boot, but actually disables them.

The implication is that if used against antivirus software, the software would appear to be running and scanning for viruses when really it is doing nothing. NAC scanning agents would think the software is running and report that back to the NAC server. The infected machine would pass that part of the health check.

Several NAC vendors acknowledged that this could render the NAC health report inaccurate, and had several suggestions about what to do.

First, get a NAC product that includes post-admission NAC. Even if a machine is infected, this phase of NAC could track its behavior on the network and quarantine it or disconnect it altogether if it engages in anomalous behavior.

Second, supplement NAC with other security products such as anti-rootkit software.

And third, use NAC preadmission products when they are available that tap into security chips placed in the computers that would detect that something is amiss.

As a matter of course, businesses should design the admission policies to constrain users as much as possible while letting them do their jobs. That way whatever damage an infected machine might do is limited.

A security expert who talked about this application-numbing feature of the Storm worm at Interop last week says it seems to keep adapting and developing new characteristics. Stay tuned.

Editor’s note: Starting Tuesday, Nov, 13, this newsletter will be renamed “Security: Network Access Control Alert.” Subscribers to the HTML version of this newsletter will notice some enhancements that will provide you with access to more resources relevant to IT security. You will still receive Tim Greene’s analysis of this market, which you will be able to read in its entirety online at NetworkWorld.com, along with links to relevant news headlines of the day. We hope you enjoy the enhancements and we thank you for reading Network World newsletters.