Q&A

Johannes Ullrich, SANS ISC: Taking the Internet by Storm

The sudden emergence in January of the Slammer worm called attention to the vital role played by Internet monitoring services such as the Internet Storm Center (ISC) at The SANS Institute.

Page 2

In the meantime, I discussed with my colleagues what we should tell users. We sent out an e-mail that reiterated the need to block that port. Then we also did some research to pinpoint all the infected hosts on the network.

What was interesting or unusual about Slammer from your perspective?

That the bandwidth went up within the first 30 seconds, but that ultimately Slammer choked itself.

What is your nightmare outbreak?

It's definitely a worm attacking a commonly used service [for example, a domain name system or Web HTTP]. In general, I'm not afraid of a flash worm. I'm more afraid of slowly spreading worms with more destructive payloads. These payloads are lines of malicious code that can erase hard drives, steal credit card programs and so on. They can live under the radar for a long time, and it can be hard to raise people's awareness levels.

SANS ISC

RESOURCE CENTER
Loading...
VIRTUAL CONFERENCE
Security Directions: A Virtual Conference

Security Directions Available On Demand Sept. 30 - Dec. 30

Join us for a virtual event with candid, expert information on top security challenges and issues - all from the comfort of your desktop.

» Register Now

WEBCAST
Protecting PII: How to Work with IT to Manage Risk

Compuware Understand the critical nature of the test data privacy problem and get tips on how to work with IT to implement a test data privacy program.

» View this Webcast

Featured Sponsors