Wenn diese Seite nicht korrekt angezeigt wird
gehen Sie bitte zur Originalseite



Latest Malware Is a Call to Action - Computerworld
Skip the navigation

Security Manager's Journal: Latest malware is a call to action

Practice tempers panic. But the Google 'Operation Aurora' malware required a few extra precautions.

By Mathias Thurman
February 8, 2010 06:00 AM ET

Computerworld - I got a call from an information security colleague who had forensic evidence from a command-and-control server identified as part of the so-called Operation Aurora incident that included a hack of Google in China. The evidence showed connections from my company's DNS servers to questionable domains. As you can imagine, I was alarmed.

Alarmed, but not panicked. At the end of the day, this was just another piece of malware, and we have the experience to deal with that. And I hadn't seen any unusual activity flagged by our antivirus software and intrusion-detection system, or any other indicators that we might be infected with a zero-day exploit -- no network bandwidth anomalies, no sudden increases in help desk calls related to system weirdness and no mentions on the various threat blogs that ours was a victimized domain.

Still, this piece of malware was reported to be more sophisticated than most in the way it operates and communicates.

With any malware, I want to determine whether my company was infected, whether the infection compromised intellectual property or other sensitive information, and whether our products' integrity was affected. Of course, I also want to remove the infestation and get back to a steady state without any business disruption.

First, I checked our DNS servers. I have high confidence in their integrity, because they are hardened and because we use Tripwire to detect changes. After a thorough review conducted using various tools and Unix compromise checklists that can be found on the Internet, we determined that the DNS servers seemed unhacked.

The next task was to find the systems that were querying the suspicious site, perform the forensic analysis and start cleaning up the mess.

After we enabled logging on our DNS servers, we could see the suspect queries. But they all originated from our Active Directory servers. That's because all of our Windows servers point to AD for name resolution first, and then the request is passed to the Unix DNS infrastructure. That meant we needed to log DNS queries at our AD server. It was a challenge, due to the sheer amount of log data, but we were able to identify some beaconing hosts.

Digging Deeper

At the same time, we contacted Juniper, our IDS vendor, and it provided a signature file for our IDS sensors. It detected attempts to exploit the Internet Explorer vulnerability that had enabled this whole mess. Almost immediately, we began to see alerts from every sensor, in the U.S., Germany, Taiwan, Hong Kong and Singapore -- connections from PCs and servers, mainly to development SAP systems. Only a few were outbound connections on Port 80, which thankfully were blocked by our content-filtering engines.

Join In

To join in the discussions about security, go to computerworld.com/blogs/security

We then contacted our antivirus vendor, Trend Micro, which released pattern files for our OfficeScan servers that we are now pushing to the more than 8,000 Windows resources on our network. But I still wasn't satisfied, since none of this told me the impact on our intellectual property. We took an EnCase image of a couple of affected machines prior to the installation of any patches or antivirus updates, which let us use the freely available Wireshark packet sniffer to analyze the network traffic generated by the malware. I also wanted to see if the malware installed keystroke monitoring software or other data-collection programs.

The forensic analysis continues, and we plan on pushing a new Microsoft patch within the next couple of days to prevent future incarnations of this malware from impacting our environment.

This week's journal is written by a real security manager, "Mathias Thurman," whose name and employer have been disguised for obvious reasons. Contact him at mathias_thurman@yahoo.com.

Read more about Security in Computerworld's Security Topic Center.



Operation Aurora

Additional Resources
ESG - What's Needed for Cloud Computing
WHITE PAPER
Just what is cloud computing anyway? Skeptics might say it is nothing but industry hyperbole, visionaries might say it is the future of IT. In reality, both statements are true - cloud computing has been embellished by the tech industry but it does hold real potential for new types of on-demand dynamic IT services. This paper seeks to clarify the definition of cloud computing, identify how far along users are in terms of cloud deployment, and examine the role of the network in the cloud computing model.
Driving Storage Efficiency in SAN Environments
WHITE PAPER
This ESG paper outlines the considerations for architecting an efficient SAN data storage infrastructure with a focus on the NetApp solutions for increased utilization, improved performance and streamlined protection to reduce operational costs.
Get a Quick ROI from Being Green
WEBCAST
The menu of green initiatives is long, but how do you get an early win with a solid ROI? Enterprise Print Services address sustainability issues well beyond paper usage. Learn how you can get an assessment of enterprise printing to identify underutilized devices, reduce energy consumption, cut waste, and free-up valuable space.
What People Are Saying
Security White Papers
Backup and Disaster Recovery eGuide
As the digital universe grows beyond imagination, enterprise IT executives face the daunting task of keeping their little pieces of it backed up...
Forrester Research: Know your Facts: Understanding The Realities Of Desktop And Application virtualization
Read Now.
Windows 7 Migration Made Easier with Desktop Virtualization
Read Now.
Virtualization 2.0: The Desktop Revolution
Read Now.
Securing Data in the Cloud
This document is intended to give a broad overview of our security policies, processes and practices.
All Security White Papers
Security Webcasts
Desktop virtualization keys innovation drive
View now.
Survival Guide: Overcoming the Obstacles to Effective Risk Management
This virtual meeting for IT managers and CIOs is based on a new IBM study. Senior Vice Presidents and a Chief Technology Officer...
The Evolution of Managed File Transfer
Managed file transfer has evolved greatly from its earliest meaning of scheduled FTP to today's meaning of complete file governance, including visibility, enforcement,...
How to cut software management costs and avoid over-spending in the future
View now!
Get a $20 Amazon Gift Card - Just watch a Demo
View now!
All Security Webcasts
IT Jobs