The IT Big One: Just a matter of time

Opinion
Jan 24, 20054 mins

What if an uncrackable virus targets spyware as a delivery and transmission vector? Or what about a zero-day exploit built into a virus or worm that infects, say, Windows operating systems? It would be great to believe that such a combination couldn’t exist, but that wouldn’t be a smart bet given the history of the security problems of commercial products and their increasing complexity.

There are bad times just around the corner,There are dark clouds hurtling through the sky.And it’s no use whining about a silver lining,For we KNOW from experience that they won’t roll by.– From “There are bad times just around the corner” by Noel Coward.

The recent tsunami tragedy should make us all realize that no matter how unlikely a catastrophe might seem, the potential exists.

Ask any large company about its disaster-readiness and recovery plans and you’ll hear about multiple data centers, standby generators, and on and on. But are they really prepared for the Big One?

In the face of a real, mega-scale, global online disaster could they keep working? Could any of us? Could we really do much at all if the Big One hits? I suspect we’re all fooling ourselves about what we really could do.

The problem is the large-scale network disasters we’ve seen so far have been limited in scope and fixed in a few days. Most of our big catastrophes, which have been caused by worms and viruses, have in reality caused less financial and operational problems than spam and spyware.

The Big One, the mother of all cyberdisasters, will affect more machines in more organizations in more countries than any disaster we’ve seen. Its effects will be lasting, and its economic impact dreadful.

You might disagree about calling today’s spam and spyware problems catastrophes. What makes people think of them as mere problems is they crept up on us slowly. But when you consider the billions of dollars in lost productivity, corrupted data and support costs, it’s hard to not call these disasters.

This could be the pattern of some future disasters: a slow buildup that culminates in a really expensive, permanent degradation of how our systems work. We are much like the proverbial frog in a pot that sits still and gets boiled to death because the water is heated gradually.

Alternatively, the Big One could hit us really quickly. I recently read in Network World that Mikko Hyppönen, director of anti-virus research at F-Secure, suggests that “Uncrackable viruses . . . could be on the horizon. Authorities put up their best numbers yet in 2004 with respect to arresting virus writers, but unfortunately the people they’re catching are hobbyists and teenagers . . . the biggest threats come from professionals who are beefing up their arsenals” (see the whole article).

And that’s the least of it. What if an uncrackable virus targets spyware as a delivery and transmission vector?

Or what about a zero-day exploit built into a virus or worm that infects, say, Windows operating systems? It would be great to believe that such a combination couldn’t exist, but that wouldn’t be a smart bet given the history of the security problems of commercial products and their increasing complexity.

In such a scenario, we could find that within a few hours most consumer PCs would be disabled and most of our outward-facing servers would collapse. Next the problem would spread to our internal servers and desktops and laptops.

Thud. E-commerce is history, the online economy is gasping for air, and corporate IT groups worldwide have retired to the nearest bar to get wasted.

A dull, sullen silence would settle over the Internet disturbed only by the scratchings of technology columnists as they labor into the night on smug op-ed pieces claiming “we told you so.”

It won’t surprise you that I don’t have any answers and I have yet to talk to anyone who has, other than those who say such a scenario is highly unlikely. Which is exactly my point: It might be unlikely but it is not impossible. What can we do?

Are bad times around the corner? Your chorus to backspin@gibbs.com.