Conficker

Jonathon Keats · Oxford University Press eBooks · 2010

Some called it Downadup. Others preferred Kido. As soon as the Conficker worm started spreading over the internet on November 20, 2008, security firms agreed that they faced a pandemic and immediately began to cooperate on containing it, but they couldn’t reach a consensus about what to name it. The worm continued to propagate unabated, infecting an estimated 15 million computers, including systems in the German military and British Parliament. By the following April the media had reported on the worm so extensively that PC World compared its notoriety to the celebrity of Paris Hilton, dubbing Conficker “the world’s most famous piece of malware.” Nevertheless several security companies still insisted on calling it Downadup. And though nobody was any closer to eliminating it, the worm had acquired several more identifiers, official codes such as TA08–297A, VU827267, and CVE-2008–4250, seldom referenced by anyone. Conficker will always have conflicting monikers. Most malware does. Despite periodic attempts to standardize the naming process, no system has ever become ubiquitous. Even the first, codified in 1991 when a mere thousand viruses were in circulation, was ignored as often as it was followed by the half-dozen computer firms then in the nascent security business. And no wonder. Mandating the form Family_Name.Group_Name.Major_Variant.Minor_Variant[:Modifier] , it made Linnaean binomials seem, comparatively, to roll off the tongue. A 1999 revision only bloated the nomenclature, requiring that virus platform and malware type also be specified, while ignoring a much deeper problem: even researchers who followed the formula seldom agreed on what to call the groups and families. Each new worm or virus averaged four totally incompatible appellations—generally unpronounceable strings of letters—and every month the number of worms and viruses in the wild increased by thousands. Hackers spread much of the malware by email. You’d get a virus embedded in the attachment to a message ostensibly coming from a personal contact. If you opened the attachment the virus would take over your computer’s email software, automatically forwarding itself, now in your name, to every address on your own contact list, renewing the whole infection process.

Read the paper · More papers on PaperTik