Q&A
Johannes Ullrich, SANS ISC: Taking the Internet by Storm
The sudden emergence in January of the Slammer worm called attention to the vital role played by Internet monitoring services such as the Internet Storm Center (ISC) at The SANS Institute.
In the meantime, I discussed with my colleagues what we should tell users. We sent out an e-mail that reiterated the need to block that port. Then we also did some research to pinpoint all the infected hosts on the network.
What was interesting or unusual about Slammer from your perspective?
That the bandwidth went up within the first 30 seconds, but that ultimately Slammer choked itself.
What is your nightmare outbreak?
It's definitely a worm attacking a commonly used service [for example, a domain name system or Web HTTP]. In general, I'm not afraid of a flash worm. I'm more afraid of slowly spreading worms with more destructive payloads. These payloads are lines of malicious code that can erase hard drives, steal credit card programs and so on. They can live under the radar for a long time, and it can be hard to raise people's awareness levels.
SANS ISC
Security Directions: A Virtual Conference
Available On Demand Sept. 30 - Dec. 30
Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.
Protecting PII: How to Work with IT to Manage Risk
Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.



