Showing posts with label downadup conficker worm virus computer security ethics. Show all posts
Showing posts with label downadup conficker worm virus computer security ethics. Show all posts

Monday, March 23, 2009

Conficker Stumps the Experts, So Far

Back in January, I blogged on the Conficker or Downadup worm that had spread to millions of computers worldwide. Conficker is a worm that is intended to form "botnets" of computers owned by unsuspecting users who have no idea that their machine has been taken over for (usually) nefarious purposes. Since then, Conficker has continued to spread and its developer (or developers) have managed to stay a few steps ahead of the growing team of computer-security experts who are trying to foil it.

A recent New York Times article describes how the "Conficker Cabal," a team of leading security specialists from a variety of private and governmental organizations, have tried to frustrate the worm's attempts to control its botnets from a list of Internet domain names that was originally only 250 or so. The Conficker authors foxed the experts by modifying the program so it can now use about 50,000 addresses from which to send its nefarious instructions, making the problem of combating it much harder. Even the U. S. military doesn't seem to know what to do. The situation grows more urgent as April 1 approaches, which is evidently the date at which the bots in the botnet will report for Conficker duty. But what that duty might be is a matter of speculation, ranging from a harmless April Fool prank to a severe attack on Internet sites of major importance, or even the entire Internet.

I'm trying to think of another case in which a high-tech system of international scope has been turned from good to evil purposes. It's not that hard. The Sept. 11, 2001 attacks on the World Trade Center used atoms, not bits, but the idea was similar: take a complex technology that involves large amounts of power and divert it to harmful purposes. Conficker lacks the element of surprise that 9/11 carried, but the level of planning and expertise required is comparable. Nuclear energy is another ongoing example. The beneficial use of nuclear energy for peaceful power reactors carries with it the constant hazard of diversion of nuclear fuel and knowhow to rogue regimes who want nuclear weapons.

A question we could ask that ties all these cases together is this: to what extent should engineers who develop a new technology, take into account the evil purposes to which it could be applied? I'm not talking about accidental hazards, but intentional misuse. I can't help but think that the original developers of the Internet were not thinking too heavily along these lines when they came up with the protocols that they did. Obviously, the Internet is generally one of the greatest success stories of the twenty-first century, and such problems that we have run into on it so far have not led to fatalities on a wide scale. But as we depend on it more and more and as attacks grow more sophisticated, that may change.

I have mentioned previously the need for engineers to use moral imagination, but mostly in the context of imagining how a given technology employed for its intended purpose can affect various groups of people. This is not always an easy thing to do, and it takes determined effort and a kind of thinking outside the usual engineering box to do it. But it often pays off in terms of new insights about potential problems that can be avoided, sometimes with simple low-cost fixes such as notifications or minor changes.

What I haven't considered in such musings is the need for a kind of twisted or evil imagination. It looks like not only should you think of how a technology will affect people if it is used as intended, but also if some evil person comes along and tries to do really nasty things with it. For some reason, this line of thinking has gone farther in computer technology than in most other forms of technology, partly because attempts to defeat security measures have been a part of computer programming almost since the beginning. There are several reasons for this.

Much more than other kinds of technology, computer technology is homogeneous: there's the human programmer or user, and the machine with its software. And the prize is simple: control. While control is only one aspect of the problem with hijacking other kinds of technology, control is the major part of the battle with computer hacking. Once you have control, computers will do your bidding with entire indifference to your moral values. And computer technology is the supreme example of fungibility: a general-purpose computer can literally do almost anything, limited only by resources. So once you have control, there's no particular problem in making the botnet or whatever do your evil will.

All the same, when programmers and computer scientists create new technologies, they build into them realms of possible and impossible actions. Because of the way the system is structured, there are certain things that it is physically impossible to do with the Internet. It's too late now, but wouldn't it be nice if one of those impossible things was to create a botnet and do evil things with it? Hindsight is generally sharper than foresight, but there are always new technologies coming along, and so there is still a chance to get it right, or more nearly right, in the future.

Of course, if you're clever and wicked enough, you can take almost any technology and do something bad with it. This doesn't mean that designers should simply drop any project that could conceivably be used for malicious acts. Engineering is all about compromises and tradeoffs. All I'm suggesting is that when you can think of an obvious nefarious use for a new technology, it would be a good idea to take some small steps toward building in preventive measures that would make it harder to use in a bad way.

In the meantime, let's hope that nothing worse happens on April 1 than a few bad practical jokes here and there.

Sources: I last blogged about the Conficker worm on Jan, 16, 2009. The New York Times article "Computer Experts Unite to Hunt Worm" can be found at http://www.nytimes.com/2009/03/19/technology/19worm.html.

A Note About Broken Links: Whenever I give a source URL link, I make sure that it is working at the time I write the blog. Over time, some of these links have become broken because the source website has taken down the article or for other reasons. I do not have the resources to go back and repair old links, so if you are interested in a source URL, my suggestion is to click on it as soon as you see it show up. If you are interested in a link but find it is broken and can't locate the material any other way, you can email me at kdstephan@txstate.edu. I sometimes keep local file copies of the source material referred to, and if I have done so I will be happy to provide you with a copy if the original URL is broken.

Monday, January 26, 2009

Downadup: A Cure Worse Than the Disease?

Anyone with a PC (and that means most people reading this blog) should know that there is a new worm out there which by some estimates has infected as many as one out of every three PCs worldwide. Known as Downadup or Conficker, it has spread rapidly in the last few weeks despite attempts by Microsoft to issue updated security patches to its Windows operating system. One reason these attempts haven't been particularly successful is that the worm reportedly disables the computer's automatic security update function by blocking access to security websites. Experts are concerned that the worm will be used by its originators to mount malicious botnet activity or other harmful and/or illegal actions in the near future.

That's all bad enough, but this attack has brought up an interesting ethical question. Suppose that security experts find that the worm is poised to do some really nasty things, as many already suspect it is. Suppose also that they (the "good guys," that is) figure out how to use the worm to gain access to infected computers, more or less the way its original developers intended. But instead of turning the worm (so to speak) to evil purposes, the security people use it simply to warn users that their computer is infected, and that they ought to do something about it. Would that be an ethical thing to do?

Opinions in the security community are reportedly divided on this issue. One security analyst was quoted by the New York Times as saying "It's a really bad idea . . . . The ethics of this haven't changed in 20 years, because the reality is that you can cause just as many problems as you solve." Arguing in favor of the idea, another expert was quoted as saying, "Yes, it's illegal, but so was Rosa Parks sitting in front of the bus."

I can think of at least two objections to the notion of using the worm itself to warn people about it. One is legal, and the other is more pragmatic and sociological.

The legal objection has to do with using malicious means to achieve a good end. If you as a security person exploit a worm that was developed by someone intending to harm others, you are intruding on the privacy and integrity of every computer that is infected. The very act of using such a means is illegal, even if you intend to use it for a good purpose. That is acknowledged by the expert who cited Rosa Parks as an example of someone who obeyed a higher law than what was on the law books at the time. But the immoral status of the law in this case is far from being as clear-cut to us now, as the Jim Crow discriminatory laws against blacks were when Rosa Parks disobeyed them half a century ago.

The pragmatic and sociological objection has to do with the reactions of the people who would get the alleged warning message. What is the first thing that comes to your mind when you get an email, say, telling you that your computer is infected and to go to such-and-such website to fix it? I don't know about you, but my first reaction is suspicion, and my next reaction is to flush the email, because I am pretty sure it is a "phishing" email designed to get me to compromise my computer somehow. The cyberworld has been so plagued by phishing dodges like this, that the chances of a legitimate message from a bona-fide security organization being believed are certainly less than 100%, and maybe much lower. So not only is it illegal, it probably wouldn't work very well.

There might be some invisible software way for the security folks to disable the worm remotely without the knowledge of those whose computers are infected, but who knows what other ramifications that might involve? Every computer is slightly different, and the risks involved in such tinkering probably outweigh the benefits that might result. Besides, it's no different in principle than walking into a stranger's office and messing with their computer, even if you mean to help out. Most people wouldn't appreciate this if they saw you doing it in person, and doing it remotely and invisibly doesn't change that aspect of the situation.

Maybe the person who brought up Rosa Parks is right, and the severity of the new worms like Downadup warrants a re-thinking of traditional ethics on this issue. An analogous historical situation that comes to mind was the controversy that arose when fluoridation of public water supplies was first proposed on a large scale in the 1950s to prevent tooth decay. This was another case in which an individual right (not to drink fluoridated water) was posed against a public good (the benefits of lower rates of tooth decay). In the Downadup issue, you have the individual right of not having some security expert mess with the inner workings of your PC, opposed against the common good that would result if said experts had the freedom to try counteracting worms by using the same methods the worms use. Although fluoridation is widespread, it is by no means universal and can still inflame controversies in regions where it is not yet practiced. Of course, public water supplies are delineated by geographic boundaries, while computer networks are essentially borderless, so the cases are different in that respect.

Perhaps we'll just have to wait and see what Downadup's evil creators (I have no hesitation in using that word for them) plan to do next. If its attacks are bad enough, maybe there will be a wider debate on the issue of how to forestall or prevent worms, including a reconsideration of the ethics of using worms to fight other worms. But until then, I'm not believing any emails telling me my computer's infected, unless they come from someone I trust in cyberspace. And these days, that's not a very long list.

Sources: The New York Times article "Worm Infects Millions of Computers Worldwide" appeared in the Jan. 22 online edition at http://www.nytimes.com/2009/01/23/technology/internet/23worm.html. I also used material from the About.com sites http://pcworld.about.com/od/virusesphishingspam/Downadup-Worm-Eats-into-1-of-E.htm and http://antivirus.about.com/od/virusdescriptions/tp/downadup.htm. (Full disclosure: My wife edits a blog for About.com, which is a subsidiary of the New York Times Company.)