Don't fear the Sober, just prepare for it

By Tom Espiner, ZDNet UK
13 December 2005 08:14 AM
Tags: january 5, worm, virus, attack, prepare, sober, malware, machine
Security administrators need not worry about the effects of the predicted Sober attack on 5 January, as long as they take precautions and strip infections from their systems, security experts said last week.

The impact of the upcoming attack can be mitigated by rooting out the problem at source, according to McAfee.

Because a machine needs to be already infected with a variant of the virus for the update to take effect, machines can be prevented from downloading the updated virus by having the current version removed before 5 January.

"For an attack to proceed, a machine needs to be infected with existing variants. Administrators can scan and clean machines and remove Sober before 5 January. The effects can be mitigated by updating antivirus software, and scanning for normal versions of the variant," said Greg Day, security analyst at McAfee. "Best case scenario, the impact will be small," he said.

McAfee said that administrators had a relatively large time frame in which to scan machines. "We have quite a large time frame to deal with the existing part of the problem -- administrators have nearly a month to update their systems."

However, McAfee warned that systems professionals should not underestimate the scale of the problem, and should be aware of the potential strain on their mail servers when the virus update is released.

"The worst case scenario is that machines aren't checked, and they pull down code that is executed on the machines. If machines are infected on your network they're going to be pulling the attack from the outside in," said Day. "Organisations may suffer some instances from outside the business."

Finnish antivirus company F-Secure also underlined the scale of the problem.

"Sober.Y was the biggest e-mail outbreak of the year. It is still responsible for around 40 percent of all the infections we see," said the company in a blog posting.

Security research company iDefense warned of increased strain on mail servers as traffic increases due to compromised machines trying to mail out the virus update.

"Even the latest set of attacks had a reported effect on e-mail servers. As widespread as this worm has become, the outbreak could have an even greater impact on network traffic around the globe," said Jason Greenwood, senior product marketing manager, iDefense.

Once the network has been scanned and cleaned if necessary, iDefense recommended filtering mail to lessen the impact of predicted attack.

"Filtering e-mail at the border gateway, especially if several antivirus engines can be used concurrently is a great way to minimise the number of samples that can enter the enterprise. This method has been extremely effective until now. Also stripping most known malicious attachments from e-mails will ensure that no sample can make it beyond the network perimeter."

McAfee said security vendors and professionals should be able to take the upcoming attack in their stride.

"We've seen so many Sober variants, it's like any other day. This has a broader visibility date, but it's not a new scary problem. We're very effective at dealing with it," said Day.

ZDNet UK's Tom Espiner reported from London. For more coverage from ZDNet UK, click here.

Advertisement

Talkback 0 comments

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal IT: Govt's cost-cutting bitch
    The government needs to stop looking at IT as a necessary evil or the place to remove costs when the Treasurer comes calling.
  • Array Can complaints on mobile content be cut?
    On 1 July this year the new Mobile Premium Services Code was introduced. It sounds like it's had a good impact, but is it enough?
  • Array NZ farmers: Bleating about broadband
    As we know, farmers are such bleaters. They bleat as much as the four-legged woolly things in their paddocks. If it's not the weather, it's the strength of the dollar! Nothing is ever right. Likewise with rural broadband.
  • More blogs »

Tags

Back to top

Featured