Skip to main content

The strange decline of computer worms

posted onMarch 19, 2005
by hitbsecnews

Computer worms are becoming less commonplace as virus writers diversify their malware spreading tactics to create the maximum effect for the least possible effort. Email-borne worms, such as NetSky, Bagle and Sober, remain perennial favourites with malware authors but Slammer-style worms are becoming rarer, according to anti-virus firm F-Secure.

Mikko Hypponen, director of anti-virus research at F-Secure, said that with the single exception of the Santy worm (which targeted vulnerable PHP installations) little new has been seen of computer worms since the May 2004 outbreak of Sasser. The hiatus follows a string of high-profile worm outbreaks including Blaster, Nimda, Slammer, Welchi and Code Red over recent years. The decrease in computer worms noted by F-Secure ironically comes at the same time many vendors, such as HP, Cisco, Check Point and others, are aggressively marketing worm-throttling technology.

One explanation for the dip in computer worms is that the widespread use of XP SP2 and greater use of personal firewall had rendered worms far less potent in the same way that boot sector viruses died out with Windows 95 and the introduction of Office 2000 made macro viruses far less common. Thwarted worm attacks could be explained by security improvements but Hypponen notes that virus writers have not even attempted to spread computer worms over recent months. Computer worms exploit software vulnerabilities to spread automatically and are technically more difficult to write than other types of malware. Hypponen reckons this factor might have a lot to do with explaining their relative decline.

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th