
Not even enough time to download patches, says study…
By Matt Loney and Robert Lemos
Published: 18 August 2004 09:10 BST
An unpatched Windows PC connected to the internet will last for only about 20 minutes before it's compromised by malware, according to security experts – down from 40 minutes in 2003.
The Internet Storm Centre, which is part of the SANS Institute, calculated the 20-minute "survival time" by listening on vacant Internet Protocol addresses and timing the frequency of reports received there.
"If you are assuming that most of these reports are generated by worms that attempt to propagate, an unpatched system would be infected by such a probe," the centre, which provides research and education on security issues, said in a statement.
The drop from 40 minutes to 20 minutes is worrying because it means the average "survival time" is not long enough for a user to download the very patches that would protect a PC from internet threats.
Scott Conti, network operations manager for the University of Massachusetts at Amherst, said he finds the centre's data believeable.
"It's a tough problem, and it's getting tougher," Conti said.
One of Conti's administrators tested the centre's data recently by placing two unpatched computers on the network. Both were compromised within 20 minutes, he said.
The school is now checking the status of computers before letting them connect to the internet. If a machine doesn't have the latest patches, it gets quarantined with limited network access until the PC is back up to date.
"We are giving the people the ability to remediate before connecting to the network," Conti said. The centre also said in its analysis that the time it takes for a computer to be compromised will vary widely from network to network.
If the internet service provider blocks the data channels commonly used by worms to spread, then a PC user will have more time to patch.
"On the other hand, university networks and users of high-speed internet services are frequently targeted with additional scans from malware like bots," the group stated. "If you are connected to such a network, your 'survival time' will be much smaller."
In a guide to patching a new Windows system, the Internet Storm Centre recommends that users turn off Windows file sharing and enable the Internet Connection Firewall. Microsoft's latest security update, Windows XP Service Pack 2, will set such a configuration, but users will have to go online to get the update, opening themselves up to attack.
One problem, experts say, is network administrators' reliance on patching and their assumption that users will quickly patch systems.
Speaking recently at the Microsoft TechEd developer conference in Amsterdam, Microsoft security consultant Fred Baumhardt said the day is likely to come when a virus or worm brings down everything.
"Nobody will have time to detect it," he said. "Nobody will have time to issue patches or virus definitions and get them out there. This shows that patch management is not the be-all and end-all."
Baumhardt stressed the importance of adaptability, using the human immune system as an example: "Imagine if your body said, 'Hmm, I have the flu. I've never had this before, so I'll die.' But that doesn't happen: Your body raises its temperature and so on, to buy time while other mechanisms kick in."
"If the human body did patch management the way [companies do], we'd all be dead."
Matt Loney writes for ZDNet UK, Robert Lemos writes for CNET News.com
Even with 40 mins, SP2 is 80MB! This would take at...
Anonymous
This is very true, but it is worse than that. I a...
Juan Bencosme
Get a Mac...
no adware.. few virus's
makes ...
Adam Filipowicz
Conti's network must be wide open if 2 PCs were in...
Bod
Some of that is absolute rubbish. Yes it is possi...
Adrian Lee
Global Technolgy Giant- System Administrators- Linux-Unix- TCP/IP- Scripting-Databases-London- 40k My client is a global leading award winning ...
Other main functions of the role are troubleshooting & resolving cross platform message flow related issues, problem resolution & estate & patch ...
Systems Administrators/ Unix, Linux, TCP/IP- 40k Systems Administrators needed for market leading Blue Chip organisation. Blue Chip Market Leaders ...
CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.
Stories from the web...
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page
Peter Cochrane Peter Cochrane's Blog: Is convergence a fiction? Or could it finally be happening…
Clive Longbottom Quocirca's Straight Talking: A game of two halves Microsoft Virtualisation scores while its SOA bores...