Deworming the Internet

Douglas Barnes · SSRN Electronic Journal · 2004

I. Introduction In 1988, graduate student Robert T. Morris released the first worm1 to have a major impact on the internet.2 The self-replicating program directly and indirectly disabled thousands of time-shared, multi-user computers3 by exploiting a range of security vulnerabilities, including poor system configuration, easily guessed passwords, and software defects.4 Fifteen years later, the underlying software and hardware have changed several times over, but the same problems provide opportunities for worms to wreak havoc,5 and wave after wave of worms continue to sweep through the internet.6 One thing is different: The stability of the internet has become increasingly important as a matter of collective economic security. While predictions of an electronic Pearl Harbor are likely overblown,7 internet worm attacks carry substantial economic costs.8 Unless something changes, these attacks are likely to continue. Much as Larry Lessig has famously asked what things regulate Cyberspace,9 in this Note I ask a more narrow question: What things can regulate, or should regulate, worms in Cyberspace? Worms are written by people and are transmitted over the internet, where they take advantage of latent defects in software installed on other internet-connected computers.10 Once infected, these computers are used as jumping-off points for the worms to infect other computers.11 My focus in this paper is on worm authors,12 vulnerable software, and the people who buy this software. Part II of this Note evaluates two approaches to regulating worm authors. These authors have long been the most popular focus for U.S. regulatory attention,13 and this attention has generally proceeded according to a broad principle of deterrence that is achieved by punishment and by setting the moral high ground.14 Because this strategy has accomplished little or nothing, Cyberspace pundits, including Lessig, are now calling for bounties and changes to internet architecture that would make it easier to catch worm authors, punish them, and deter future authors. Part II argues that these approaches are both unlikely to work and potentially destructive to the internet. Part III discusses the role of the market in regulating the worm problem. In technical circles, the role of vulnerable software in creating worm crises is well understood. However, to the extent that this concern appears on the agenda of policymakers, they apparently assume that markets will eventually provide the right incentive for software publishers to produce better software. This has not happened. Part III develops a theory to explain both why the market has not yet produced substantially more secure software in its current configuration and why it is not likely to do so in the future absent changes in incentives or market structure. Part IV addresses the issue of government intervention in the worm crisis. Market failure alone does not justify government intervention; it must be possible for intervention to make the situation better. Part IV first argues that software publishers have long had the ability to prevent the types of worms that are currently afflicting the internet and that the damages suffered from worms are large, if hard to pin down with any precision. Part IV goes on to argue that these preventable damages make a prima facie case for government intervention, despite the belief in some circles that the internet should be protected from regulation. Part V looks at regulation of the worm problem through litigation. Virtually no lawsuits have been filed for worm-related damage. Current law does not provide a useful vehicle for those damaged by worms, whether they are the software purchasers themselves, or non-purchasers who are nevertheless affected when the internet either slows down or grinds to a complete halt. Part V examines why current law fails in this regard and argues that even if tort causes of action could be extended to cover worm-related damage, this would not necessarily be a good thing. …

Read the paper · More papers on PaperTik