, 2003-01-13
Why I should have the right to kill a malicious process on your machine.
Expand all |
Post comment
Strikeback, Part Deux
2003-01-13
Chris Caydes (2 replies)
Chris Caydes (2 replies)
Strikeback, Part Deux
2003-01-13
Stealthbadger (2 replies)
Stealthbadger (2 replies)
The Self-Defense Argument is flawed... Strikeback, Part Deux
2003-01-14
Shawn Duffy (5 replies)
Shawn Duffy (5 replies)
Give me a break... Strikeback, Part Deux
2003-01-13
Shawn Duffy (7 replies)
Shawn Duffy (7 replies)
Give me a break... Strikeback, Part Deux
2003-01-14
Anonymous (5 replies)
Anonymous (5 replies)
Give me a break... Strikeback, Part Deux
2003-01-14
Shawn Duffy (3 replies)
Shawn Duffy (3 replies)
Isn't this like smacking the neighbor's kid for mouthing off?
2003-01-14
Anonymous (7 replies)
Anonymous (7 replies)
No, it's like shooting your neighbor's dog who ruthlessly attacking someone.
2003-01-15
P. Hofmeister (1 replies)
P. Hofmeister (1 replies)
Strikeback, Part Deux
2003-01-20
Anonymous (1 replies)
Anonymous (1 replies)
Strikeback, Part Deux
2003-01-20
Anonymous (1 replies)
Anonymous (1 replies)
Strikeback, Part Deux
2003-01-21
Anonymous (2 replies)
Anonymous (2 replies)

David Moore, Colleen Shannon, Geoffrey Voelker and Stefan Savage, have an excellent analysis of how to respond/contain self propigating code on the Internet.
http://charlotte.ucsd.edu/users/savage/papers/Infocom03.pdf
It turns out that identifying/removing infected machines is not an effective response strategy unless you are really hyper-sensitive. What is needed is identifying the infection and blocking the INFECTION from spreading to new machines.
Additionally, counterattack to stop unknown threats (which nimda in the first few hours was) requires automatic systems to identify and respond, which may be suseptible to spoofing. Someone I don't like? I fake a scan from his machine to your counterattacking network range.
[ reply ]
Link to this comment: http://www.securityfocus.com/comments/columns/134/17606#17606