David Perry: Clearly, the rise of network viruses, starting with SLAMMER and climaxing with MS-Blast. The slammer worm was propagated on Super Bowl Weekend, which caught many American computer users unawares. It leveraged network protocols to spread from sql server to sql server. It was, however, limited to only infecting servers of that type. Slammer was so successful that it managed to obscure an entire country (South Korea) from the Internet--an unprecedented event in the history of malicious code. Blaster, on the other hand infected all copies of Microsoft NT, XP and 2000. This raised the potential victim count from several hundred thousand to hundreds of millions, worldwide. Also known as Nachia, this network virus went through a variety of versions and has had the lasting effect of disabling use of MS-Exchange from most ISP's (exchange connect from client to server on port 135--which was one of the primary ports used by the worm. I use the terms virus and worm interchangeably because worms are a special subset of viruses, hence all worms are viruses.
All network worms share the ability to infect a machine with no interaction from the user. This makes them both more prolific and more secretive. A user has no visual clue whatsoever that he or she is infected with a network worm. This is the most pernicious of their various traits. On an entirely different front--there has been a great deal of speculation about the connection between spam and viruses. A particular email worm (SOBIG) dropped a component that could conceivably be used by spammers to spread their annoying email messages anonymously.
Fernando de la Cuadra: The year began with SQLSlammer, a really fast infector. It only collapses MS SQL Server, but the speed when infecting servers was really incredible. It was a very important milestone for AV manufacturers because most of them cannot detect the code with their obsolete technologies. The Blaster virus attacked in August, once again using system vulnerability, and having fast propagation. Both viruses are, from my point of view, the biggest infectors appeared in 2003, but there is a really important infector in 2003, that appeared a long time ago: Klez.I virus. Since its discovery, it is always on the top virus lists.
Denis Zenkin: Undoubtedly the major deplorable surprise on the virus scene this year was high proliferation of the "flash"-type network worms: Slammer and Lovesan. This implies the real start of a new era of malware creation and protection: traditional anti-virus tools are no longer enough to protect a workplace against worms, but they should be definitely strengthened with firewalls to ensure maximum security. Another disturbing trend is of course the situation with security patches. The speed they are released and the way they are distributed is not sufficient.
Mikko H. Hypponen:From my perspective, these were the top five issues:
- Slammer: single largest attack against the internet ever
- Sobig.F: single largest email worm ever
- Microsoft buying RAV and entering the AV business
- New York blackout
- Spammers starting to use viruses
Reading our newsletter every Monday will keep you up-to-date with security news.
Receive a daily digest of the latest security news.