You are here: silicon.com > Software > Security Strategy

Security Strategy

MSBlast worm outbreak 'infected 8 million PCs'

Microsoft claims epidemic far larger than previous estimates…

By Robert Lemos

Published: 5 April 2004 09:15 GMT

New data from Microsoft suggests that at least eight million Windows computers have been infected by the MSBlast, or Blaster, worm since last August - many times more than previously thought.

The latest data comes from the software giant's ability to track the usage of an online tool that its engineers created to clean systems infected with the worm.

Since the January release of the tool, more than 16 million of the systems that connected to Microsoft's Windows Update service were found to be infected with MSBlast and were offered a patch and the use of the disinfecting tool, the software giant told silicon.com's sister site CNET News.com. During the same period, about eight million systems actually called on Update to patch them and prevent reinfection and used the special tool to remove the worm.

Though Microsoft believes the total number of users infected by the worm is likely closer to the higher, 16 million tally, the eight million figure may provide a more solid indication of the minimum number of systems hit. The larger number may include systems counted more than once, as busy computers users declined to deal with the worm immediately, or cancelled the process once it had begun, only to return to Windows Update later. Once those systems were disinfected and patched, however, they would not be re-counted. Microsoft did not track what systems, specifically, used the tool, just that it was used.

Late last year, "we knew we were getting reports from customers saying that they were still seeing symptoms of Blaster," said Stephen Toulouse, security program manager for Microsoft's security response centre. "Our internet service provider partners were seeing a lot of Blaster traffic on their networks as well."

In fact, the worm hit so hard that the company quickly asked some development teams to stop work on the software giant's next version of Windows and create an interim update, known as Service Pack 2, to enhance the security of Windows XP. Moreover, several months of complaints led Microsoft to augment Windows Update with the online tool to detect and clean the MSBlast worm.

The tool has also given Microsoft an invaluable data point to quantify the threat of such internet worms.

Already, the size of the digital epidemic far exceeds the estimates of researchers who have tracked the worm since it first started spreading, on 11 August. Typically, researchers try to estimate the size of a worm epidemic by collecting data from the records of network devices, such as firewalls and intrusion detection systems. By aggregating the information from the devices, researchers can count the number of internet addresses from which a worm, such as MSBlast, is trying to spread.

Most internet security organisations had believed that at most 500,000 systems had been compromised by the self-propagating program.

"I don't doubt [the new] number," said Johannes Ullrich, CTO for the Internet Storm Center, which collects firewall logs from thousands of volunteers in order to gauge which digital threats are spreading on the internet. Using the voluntarily submitted records, the Internet Storm Center had tallied enough Internet addresses to estimate that between 200,000 and 500,000 computers had been infected by the worm.

Another threat tracker, security company Symantec, has agreements with the owners of some 20,000 network devices to use their records for analysis. The company crunches the numbers to keep track of threats on the internet, and though it stopped counting once the MSBlast worm spread to more than 40,000 computers, Symantec estimated that "a couple hundred thousand" systems may have been compromised, said Alfred Huger, senior director of engineering for the company.

"I am surprised by [Microsoft's] number," he said. "However, I can't contest it; they have the best insight. We certainly see Blaster out there in spades."

Robert Lemos writes for CNET News.com

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
Transition/Change Management Manager - GLOBAL

The Transition Project Manager will also assist in developing the cost estimate/budget for the project, providing support and due diligence tasks and ...

Project Operations Manager

Ensuring that time recording is carried out correctly and accurately and that activity codes are appropriate to project and administrative ...

Technical Consultant

The sites are based n Hook , Hampshire- Commission AX4 SAN Environments as per design document,- Provision new Guest machines as per design ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: