Microsoft slammed for 'stupid' friendly-worm idea

Reminiscent of the "good" Nachi worm unleashed in 2003, Microsoft researchers have touted the idea of "friendly worms" to issue software patches, which has been labelled "stupid" by security experts.

In a research paper entitled Microsoft's Sampling Strategies for Epidemic-Style Information Dissemination, the software giant looks at optimising the dissemination of data over a large-scale network by sampling computers in a subnet or IP address block -- a similar technique to that used by worms -- to identify computers that contain a known vulnerability.

"My focus is fundamental research on improving the efficiency of data distribution of all types across networks, and isn't limited to certain scenarios or types of data but investigating underlying networking techniques," Milan Vojnovic, researcher at Microsoft UK, told ZDNet.com.au sister site ZDNet.co.uk.

"Using understanding from the field of epidemiology is one of the methods that we're investigating in this area, and we hope that our research will help inform future computer science research and networking technology," he said.

However security expert Bruce Schneier said the concept of using worm-like techniques to distribute software patches is "stupid".

"Patching other people's machines without annoying them is good; patching other people's machines without their consent is not," wrote Schneier in a blog post.

"A worm is not 'bad' or 'good' depending on its payload. Viral propagation mechanisms are inherently bad and giving them beneficial payloads doesn't make things better. A worm is no tool for any rational network administrator, regardless of intent," added Schneier.

If Microsoft were to venture down this path of so-called "good worms", it would be revisiting old territory covered in 2003.

The 2003 worm dubbed W32.Welchia, W32/Nachi and Worm_MSBlast.D, was one such example of a "good worm" turned bad. Nachi downloaded a patch for Windows from Microsoft's Web site.

The "good worm" became a pest and claimed the UK police computer systems along with over 500,000 victims.

Back then, Oliver Friedrichs, who was the senior manager for Symantec's security response centre, was one of numerous experts that said worms were not a good way to distribute patches.

"I don't necessarily think whenever you infect someone's systems, install software and reboot the computer that that is a good thing ... It still tries to propagate; it is still attacking people over the Internet," he said at the time.

Even today, the field of "computer epidemiology" sparks excitement and caution in the security industry.

"I believe this is an exciting and important area of research. The more complex and interconnected our information systems become, greater understanding of how code spreads in this ecosystem will undoubtedly be invaluable in better protecting our information ecosystem against malicious intent (worms included)," said Nishad Herath, security researcher at McAfee's AvertLabs.

However Herath also said the method is "extremely risky" because of the impact on user expectations of how to manage software updates.

"Forcing software updates (via good worms), without adequate user consent or proper user education as to why these updates are necessary, will only open the door to a culture where users will become accustomed to such unverifiable "automatic updates", making it easier in the end to spread malware masquerading as 'good worms'," said Herath.

"As always, the devil may well be in the details of the implementation, but still, [it's] very risky all the same," he added.

However, echoing Schneier's blog comments, IBRS security analyst, James Turner, said the technique may have a place for consumers, who are bad at maintaining their software.

"This is potentially fantastic for home users, who are notoriously bad at maintaining their security," said Turner.

Turner agreed that this method of distribution would present major problems when ensuring patches come from a trusted source. But this may also present an opportunity for Microsoft to change the permission model it uses for consumers.

"Potentially Microsoft could make this a setting when you set up your account by asking the question, 'Do you want Microsoft to patch your machine on the fly'," said Turner.

However, Turner believes the ramifications for corporate users could be dire.

"In terms of corporations, this would be a nightmare, not least because of the change control issues. Microsoft is so keen to get people running on the latest version but it hasn't always done a quality control assessment against the customised apps that organisations are running," said Turner.

"Those customised apps could have been taking advantage of aspects of the software that gets changed by one of these worms," he added.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/vA11Otks

SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the Square Kilometre Array (... http://t.co/FqSe1Uju

SKA bid ends in three-way tie AU/NZ/ZA http://t.co/aGw6dndH < interesting outcome

RT @MADinMelbourne: roxon "will enable more families to access credit" @MLolderandwiser: Privacy Act amendments http://t.co/Mv4c7PC2 via @zdnetaustralia

Is #PR dying at the hands of #SocialMedia? Check out how #UnitedAirlines suffered a Social PR hiccup in 2008 http://t.co/OVpYX8Uv

The interface is nowhere near as clean and user friendly as the Rdio streaming service apps. It doesn't compete with Rdio which has very ...

1 hour ago by Jeff12345 on Spotify finally goes live in Australia

RT @ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/0rCoszCl #infosec #hack #cybersecurity

by http://t.co/vmlLt4bh: SKA bid ends in three-way tie: The bid to host the world's largest radio telescope, the ... http://t.co/ySDRbo3l

It's official. The SKA bid has ended in a three-way tie between Australia, South Africa and New Zealand: http://t.co/Wn1niauX ^LH

Biometric bugs too dangerous for public?
http://t.co/48XQpWiY

Aussies getting ripped off by retail: Choice http://t.co/6ZQ0wuCJ via @zdnetaustralia

Thats really interesting to find this post especially in this period of my life I'm Italian, I'm owner of a website that ships worldwide...

1 hour ago by salbini on Aussies getting ripped off by retail: Choice

Android's biggest security flaws - ZDNET - ZDNet Australia http://t.co/4j4R1x6Q

RT @Techmeme: RIP webOS: Again and for good this time (@jkendrick / ZDNet) http://t.co/RhADp6WL http://t.co/fFYGIy5R

Cybercrime golden age over in two years? http://t.co/LyqqjWYU #Cybercrime #Gescrise #Riskmanagement (via @ECCOUNCIL)

RT: ECCOUNCIL: Cybercrime golden age over in two years? http://t.co/X0In9ijs #infosec #hack #cybersecurity

Cybercrime golden age over in two years? http://t.co/VJnt6nEo #infosec #hack #cybersecurity

NBN users opt for 100Mbps - http://t.co/C2Vs7d3t

Yes, if only he had access to FTTP instead of wishing for wireless or space optics, perhaps the comedy site would still be up and running...

2 hours ago by Beta on NBN users opt for 100Mbps

I could not resist :-)

I remember that website well, you must too, it was full of so many comedy pieces.

2 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

Bazaarvoice acquires rival PowerReviews; adds SMBs to CRM portfolio: By Andrew Nusca | May 25, 2012, 4:42am PDT ... http://t.co/WngvcsxL

MikeSkoey, what a naive collection of words. How do you know what context Paul has been working in. How do you know he implemented whats ...

3 hours ago by AnonymousCIO on 30 servers to 7: BUPA redoes virtualisation

Post 'social' improved speed to information and context http://t.co/7u9odG7N

HC, don't be so mean to Todd...

He is actually one who may not be just politically opposed ;-)

3 hours ago by Beta on NBN users opt for 100Mbps

No, Quigley is, as CEO's of all companies are, quite simply motivated for his company to be a professional and successful company, as it ...

3 hours ago by Beta on NBN users opt for 100Mbps

Forced lol. btw I tried to load your website www.nonbn.org but all I got was a "website unavailable" I really wanted to donate some mone...

3 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

http://t.co/aDIOqQ4c http://t.co/NeUOcLt5

What has the debt level got to do with what plan people chose? I'd point out that the debt wont be $50 billion but i'd be wasting my bre...

4 hours ago by mstat_z on NBN users opt for 100Mbps

Quigley is entirely politically motivated, this is headline grabbing and nothing more. The statistic should read - "of those who took up ...

4 hours ago by merarischroeder on NBN users opt for 100Mbps

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

"the artificial speed tiers will mean that on average speeds the country will be left well behind others and social inequality will incre...

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

The most insulting aspect of the ads is CommBank's expectation that we would accept a bank account with fees unless you deposit $2000/mth...

4 hours ago by gikku on Triple J's Spotify conundrum

NBN users opt for 100Mbps - Communications - News http://t.co/3A84AASP

That's right. Quigley DOES know best. So when Quigley presents a plan to the shareholders (us) and says "this is our worst case scenario...

4 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

"NBNCo predict 13% of premises passed by fibre will opt for wireless because it is cheaper." Which leaves 87% well above the 70% estimate...

5 hours ago by Beta on NBN users opt for 100Mbps

HC the critics said the NBN wouldn't make a cent (yes, yes here comes the, it's still in debt arguments - we know what you meant and so d...

5 hours ago by Beta on NBN users opt for 100Mbps

Look what you did Gwyn...LOL. Yes, but as you have been told umpteen times Mathew (whenever you sprout the same old repetitive lines abo...

5 hours ago by Beta on NBN users opt for 100Mbps

It's great that in one area NBNCo are beating the prediction on speed tiers in the Corporate Plan (page 118). Unfortunately it is the onl...

5 hours ago by mathew42 on NBN users opt for 100Mbps

10 cool iPad apps you'll wish you found sooner | 2 of 10 http://t.co/M9SXbnJS via @zite

Do you have a reference for the 40% in Willunga? The only public figures I've seen are 29% for Willunga and 26% for Kiama. It would cert...

5 hours ago by mathew42 on NBN users opt for 100Mbps

Considering that Quigley wrote the corporate plan based on a number of studies one would expect him and the plan to know best.

5 hours ago by mathew42 on NBN users opt for 100Mbps

yep don't worry, I'm sure the anti-NBN zealots will find some other ridiculous line to fill the void. I imagine it'll be "oh but these ar...

5 hours ago by Hubert Cumberdale on NBN users opt for 100Mbps

SA Health's journey to ehealth Business News ZDNet Australia: Implementing e-health services for an entire state... http://t.co/QuiOy7OQ

London to become Intel's city-living R&D testbed - ZDNet UK (blog): IT PROLondon to become Intel's city-living R... http://t.co/5qdivDa1

#Google #Australia Much ado about Google's tax http://t.co/DCMsJGyN

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

by http://t.co/vmlLt4bh: Build your own smartphone stand: Looking for a smartphone stand, but not interested in d... http://t.co/DptVvkoB

Build your own smartphone stand: Looking for a smartphone stand, but not interested in dishing out the dough? We... http://t.co/TgSeZIdM

last couple of hours to submit your application for #crmidol. Step up and take your chance! http://t.co/7vQxdbY3 #scrm #crm #value

The rural Silicon Valley http://t.co/vqV6bl5i

RT @JamesVickery: NBN users opt for 100Mbps http://t.co/atP8fi1L

Build your own smartphone stand http://t.co/IY6VxA7n

RT @zdnetaustralia: NSW outs datacentre deal details: http://t.co/A1Cj4Eot ^LH

The rural Silicon Valley http://t.co/jhEFQwSX

The rural Silicon Valley: What happened in Senate Estimates this week? What's the issue with tech company taxes?... http://t.co/Umoa7CHX

This story has been voted 12000 times in the last 24 hours!

1 day ago, Is Bill Gates a great leader?

This story has been voted 10 times in the last 24 hours!

3 days ago, CeBIT 2012 opens: photos

This story has been voted 15 times in the last 24 hours!

3 days ago, Lenovo ThinkPad 3G tablet (32GB)

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar