Low-threat worm caused 'most significant breach' of U.S. military net

By , Network World |  Security, US Military, USB drive

The most http://www.networkworld.com/news/2010/082510-pentagon-net-hack.html?hpg1=bn ">significant breach of U.S. military computers ever was carried out in 2008 by W32.SillyFDC, a low-level-threat worm that got into the network via a thumb drive plugged into a military laptop.

http://www.networkworld.com/news/2010/040610-cyberattacks-clarke.html?nw... ">Is the U.S. the nation most vulnerable to cyberattack?

At the time, a variant of the worm found its way into classified and unclassified military networks and took months to eradicate.

This despite the fact that generic W32.SillyFDC worms had been discovered the year before, and security companies had long since figured out how to deal with them. Removal was ranked "easy".

The incident made public this week by a high-ranking Department of Defense official alarmed the Pentagon. "This previously classified incident was the most significant breach of U.S. military computers ever, and it served as an important wake-up call," says William J. Lynn III, an udersecretary of defense, in an essay published in Foreign Affairs.

The hack, which was publicized at the time, led to a ban on use of thumb drives that the military has just started to lift in the past 10 months, says John Pironti, a security consultant with IP Architects.

Despite being a variant of a well-known and low-risk worm, the malware could have been more dangerous than it might seem at first glance, he says.In discussions with military clients since the incident, he gleaned that the variant -- known as W32.agent.btz -- lodged itself within the network where it was smart enough to wend its way into a classified network. This requires a level of knowledge about sensors and defenses within military networks.

"It propagated well before it was detected," Pironti says. "This was not something off-the-shelf. It was something fresh and very interesting."

Still, corporate IT security professionals had a leg up on the worm if they had commercial antivirus software. For example, Symantec posted an advisory on the worm Feb. 27, 2007, in which it says that its then-current antivirus software would identify and remove it.

W32.SillyFDC removal was ranked easy by Symantec, its damage level potential was ranked medium and its overall threat rating was very low.


Originally published on Network World |  Click here to read the original story.
Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

SecurityWhite Papers & Webcasts

See more White Papers | Webcasts

Answers - Powered by ITworld

ITworld Answers helps you solve problems and share expertise. Ask a question or take a crack at answering the new questions below.

Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Ask a Question