SANS – Internet Storm Center – Preparing for Battle
Lost of great info here
Preparing for Battle (NEW)Published: 2006-01-04,
Last Updated: 2006-01-04 20:40:11 UTC by Kyle Haugsness (Version: 1) Are you ready to battle a large virus/worm outbreak? Please don’t view
this is a prediction that there will be a large event, but let me just say that conditions are right for a big storm (WMF issue and the return of the Sober worm).Regarding the WMF issue, you have probably decided to either wait for the official Microsoft patch, or you are rolling out Ilfak’s patch. But there is still about 6-10 days of risk here for a major worldwide event. So here are some recommendations for preparing for the battle. (This is primarily written for system and network admins…)Prepare a short briefing for management on the situation: 1) There is a serious vulnerability in Microsoft operating systems. 2) An official patch will not be available from Microsoft until Jan. 10. 3) There are multiple propogation vectors: e-mail, instant messaging, web surfing, etc. 4) Several different versions of the exploit are in the wild and are being actively used by criminal groups. All propogation methods are being used. As of Wednesday, Jan 4 20:15:00 UTC, our current poll indicates that 22% of respondents (340) have seen exploit attempts through one of the exploitation vectors. 5) Tools to generate random files to exploit the vulnerability are publicly available. These tools may be used to evade anti-virus and IDS/IPS signatures. 6) Anti-virus signatures and intrusion detection/prevention system signatures may only be able to catch the first generation of exploits. 7) If an outbreak does occur, how are you going to sanitize laptops that were infected outside of your network before allowing them to connect to your internal network?As you provide this information, you should also provide an action plan for mitigating damage in the worst case scenario. You should consider the following action items in your plan. Also consider that your organization may have no internal infections, but that the rest of the Internet is having problems. Solicit input from your management on the circumstances that would dictate each of the actions below. 1) Disconnect from the Internet. You should take this time to validate that you have good backups of your In a virus outbreak/worm event, communication between the operational You can find much more information about incident response plans at the http://www.intrusions.org/ |
No comments yet.
Leave a Reply
-
Recent
- SANS Internet Storm Center – "Malicious" Websites
- SANS – Internet Storm Center – CME-24 (Blackworm) Analysis: The destruction does not appear to spread across Windows network shares
- F-Secure : News from the Lab – Nyxem on a world map
- SANS – Internet Storm Center – Prepraring for Feb 3rd(CME-24\Blackworm)
- Microsoft Security Advisory Notification – Update for Security Advisory (904420) – Win32/Mywife.E@mm
- F-Secure : News from the Lab – First reports of Nyxem damage
- Microsoft Security Advisory (904420): Win32/Mywife.E@mm (aka Blackworm)
- SANS – Internet Storm Center – BlackWorm Summary – Updated Info
- SANS – Internet Storm Center – BlackWorm Summary – Updated Info
- SANS – Internet Storm Center – More on Nyxem
- SANS – Internet Storm Center – What’s the threat? And who is noticing it? Nyxem_e versus CME 508
- SANS – Internet Storm Center – New mass mailer spreading (Blackmal/Grew/Nyxem) – With updated info
-
Links
- WordPress.com
- WordPress.org
- Symantec Security Response
- Secunia – Virus Information
- McAfee – Newly Discovered Threats
- SANS Internet Storm Center
- Trend Micro-Virus Information
- F-Secure: News from the Lab
- F-Secure: 50 latest virus descriptions
- VirusTotal.com
- Common Malware Enumeration (CME)
- worm blog
- Computer Associates Virus Information Center
- Kaspersky Analyst’s Diary
- Kaspersky’s Viruslist.com
- Panda Software Latest Threats
- Norman: Virus and Security
- Sophos Virus Info
- F-Prot Virus Information
- Sybari Threat Info Center
- Anti-Malware Engineering Team
-
Archives
- November 2007 (1)
- February 2006 (8)
- January 2006 (33)
- December 2005 (30)
- November 2005 (5)
-
Categories
-
RSS
Entries RSS
Comments RSS