Looking beyond the Melissa virus.The computer virus that struck in late March exposed serious weaknesses in the security of many computer systems. Nicknamed Melissa, this rogue program acted like an automated chain letter, overwhelming electronic-mail service in more than 300 organizations, including government agencies, military bases, and large businesses. What made this particular virus stand out was the extraordinary speed with which it spread throughout the world. "The Melissa virus A Word macro virus that was unleashed in the spring of 1999. It sent an e-mail message with a list of pornographic Web sites to the first 50 names in the user's Microsoft Outlook address book. represents a new level of sophistication so·phis·ti·cate v. so·phis·ti·cat·ed, so·phis·ti·cat·ing, so·phis·ti·cates v.tr. 1. To cause to become less natural, especially to make less naive and more worldly. 2. in the progression of computer viruses," says Richard Pethia of Carnegie Mellon University's Software Engineering Institute in Pittsburgh. Pethia was one of several computer security experts who testified at a congressional hearing Congressional hearings are the principal formal method by which committees collect and analyze information in the early stages of legislative policymaking. Whether confirmation hearings — a procedure unique to the Senate — legislative, oversight, investigative, or a last month on ways to protect information technology from emerging threats. The Melissa virus exploited a well-known vulnerability of small computer programs called macros. Word processing word processing, use of a computer program or a dedicated hardware and software package to write, edit, format, and print a document. Text is most commonly entered using a keyboard similar to a typewriter's, although handwritten input (see pen-based computer) and software often attaches macros to documents in a way invisible to the typical user. The Melissa virus, posing as a macro, was hidden in a Microsoft Word A full-featured word processing program for Windows and the Macintosh from Microsoft. Included in the Microsoft application suite, it is a sophisticated program with rudimentary desktop publishing capabilities that has become the most widely used word processing application on the market. document, which was distributed by E-mail. Opening the document activated the virus, which would then look for an organizer program called Microsoft Outlook For the e-mail and news client bundled with certain versions of Microsoft Windows, see . Microsoft Outlook or Outlook (full name Microsoft Office Outlook . The virus would mail itself to the first 50 addresses listed in the organizer's E-mail directory. Because Word and Outlook are widely used, often without sufficient security precautions, the virus spread rapidly. It merely perpetuated itself and forced the suspension of E-mail service See Internet e-mail service. at sites that it inundated in·un·date tr.v. in·un·dat·ed, in·un·dat·ing, in·un·dates 1. To cover with water, especially floodwaters. 2. . A virus designed to destroy data, however, could use the same security loophole to wreak much more havoc. One encouraging aspect of the Melissa episode was the quick response by several virus-monitoring organizations, which collected information and provided timely, well-publicized warnings. Within a few days, new infections slowed to a trickle. Response times measured in hours and days, however, may not be fast enough in the future. "Future mutations ... could easily be much harder to detect, spread even more quickly, and cause significantly more damage," Pethia contends. Experts estimate that about 30,000 viruses are now in circulation, with 300 new ones created each month. "Users should be sure that their computers are running the most up-to-date virus protection software," warns Michael A. Vatis, director of the Federal Bureau of Investigation's National Infrastructure Protection Center in Washington, D.C. "The long-term solutions to the problems represented by Melissa will require fundamental changes to the way technology is developed, packaged, and used," Pethia concludes. "It is critical that [computer] system operators and product developers recognize that their systems and products are now operating in hostile environments." |
|
||||||||||||||||||||

Printer friendly
Cite/link
Email
Feedback
Reader Opinion