

                                      April, 1994









                CORPORATE ANTIVIRUS DISCIPLINES


















                                    Alan Fedeli, Manager
                                    AntiVirus and Phone Fraud
                                    Integrated Systems Solutions Corp.
                                    A Subsidiary of IBM
                                    P.O. Box 700
                                    Long Meadow Road
                                    Sterling Forest, NY 10979



       Internet..................   FEDELI@VNET.IBM.COM
       MailExchange..............   USIBMT8Y on IBMMAIL
       IBM VNET..................   FEDELI @ RHQVM14
       FAX.......................   914-759-4690 (8/248)
       Telephone.................   914-759-2901 (8/248)







                      CONTENTS


        Corporate Experience with Computer Viruses..........

        No Simple Solution; No Panacea......................

        Organizing for Corporate Incident Management........

        Corporate AntiVirus Disciplines

            Incident Reporting..............................

            Incident Response...............................

            New Virus Analysis..............................

            Incident Closure................................

            Incident Trend Analysis.........................

            AntiVirus Tools Deployment......................

            AntiVirus Education.............................

            Recall Capability...............................

            Evaluating Process Effectiveness................

        Conclusions ........................................

        Acknowledgements....................................


CORPORATE EXPERIENCE WITH COMPUTER VIRUSES

Computer viruses, and their close relatives, worms and Trojan horses,
have gotten significant media attention in the past several years.  The
media coverage has increased public awareness during certain episodes,
but the media effect has often been confusion rather than enlightenment.
There have been a few fast-spreading network incidents.  The media
reacted to the November, 1988 Internet Worm, which infected thousands
of Unix based machines on the Internet within hours.  There was less
coverage for the CHRISTMA EXEC, a REXX program for IBM's VM operating
system, which spread through European university networks and then into
IBM, flooding IBM's internal network with copies of itself.  In both
episodes the harmful code spread rapidly around the world, but the spread
was stopped relatively quickly as network audit trails led to the source
of infection.  In each cases, it appeared to be an experiment gone awry.

Microcomputer viruses behave differently than network infections. Viruses
on microcomputers start more slowly, spread as software moves from one
PC to another, and build up over time.  The author is rarely caught;
there is no audit trail as with network spread.  And the infection isn't
easily arrested and snuffed out.  Every popular microcomputer operating
system has an ongoing virus problem.  These include PC-DOS, Macintosh,
Amiga, Atari, and AppleDOS.  Critical operations have been down for days
at a time because computers were rendered inoperable by viruses.  This
has been especially true if Local Area Network (LAN) servers are infected
and they spread the infection to a wide population of PCs connected to
the server.  Estimates of more than a million dollars in loss from such
incidents are commonplace, but rarely admitted in the press for fear of
damage to corporate reputation.

A  computer virus is a program or program segment which, when run, copies
itself, or a variation, into another program.  The copy is also capable
of copying itself again when the infected program is run.  Thus there is
continual spread.  In addition to making copies of itself, a virus may
contain additional code to do something else.  These actions can include
anything that can be done by a program.  Many viruses do nothing but
spread; others display a message to the user.  Still others change or
erase all the data on a disk.

Studies of stable populations over the past three years indicate steady
linear growth of reported incidents.  Media events such as the March,
1992 Michelangelo attention tend to affect that growth pattern.  We saw
a sharp rise in reported incidents in February and March of 1992, and
then a dramatic decrease for several months afterwards.  It is possible
that attention to Michelangelo caused enough scanning to reduce the
prevalence of viruses worldwide.

For the most part, older viruses are no longer increasing in prevalence;
they appear to have reached an equilibrium, or begin to go extinct.  The
one exception is the FORM virus, which has now far outdistanced all other
viruses in prevalence.  However, most of the current increase in reported
virus incidents is due to new viruses appearing in the wild.

NO SIMPLE SOLUTION; NO PANACEA

It isn't possible to completely solve the virus problem for most computer
systems.  Viruses can be written on any system on which users can create
programs.  They can spread on any system on which a program can create or
modify another program.  They can spread between users any time a program
that one user runs can create or modify a program that another user can
run.  This includes almost every general-purpose computing system.

Access control can be used to limit the authority users have to modify
programs on a system.  If access control is broadly used and carefully
practiced, the opportunity for viruses to spread will be narrowed to
periods of authorization.  Mandating access control solely to stop
viruses becomes an expensive partial solution.

Programs can be written to examine other programs to determine if they
contain a virus.  However, it can be mathematically proven that it is not
possible to do this without mistakes.  The "halting problem," a famous
problem in computer science, demonstrated this proof.

Unlike other computer crime problems, the spread of viruses is generally
innocent, after the initial writing and implantation.  People going
about their business, doing their job, get accidentally infected by
running one program, and then pass the infection along unwittingly.
For this reason, we can't legislate the problem away.  Viruses
exist and will continue to spread unintentionally.

For the most part, PC user reaction to the existence of viruses
is inconsistent and generally reactive.  Some use antivirus tools
religiously, some don't.  Some people react to media hype, and scan
only then.  Most corporations encourage the use of antivirus tools,
but few practice consistent, corporate wide disciplines for incident
management and control.

ORGANIZING FOR CORPORATE INCIDENT MANAGEMENT

It is not intuitive that a corporation would want to orchestrate its
computer virus incident management globally.  In fact, the tendency is
to decentralize the activity, and let each site or division deal with
the problem locally.  There are reasons why viruses, more than most other
corporate phenomena, should be managed with a corporate-wide purview:
  a) A corporation needs to know quickly whether it is dealing with
     an isolated viruses, or whether they are experiencing an epidemic.
  b) A corporation needs to know the extent of the computer virus problem
     to keep the cure in line with the cost of the problem.
  c) A corporation can't afford to replicate virus expertise in all sites
     and divisions at a level needed for more serious virus situations.

Given the decision to coordinate computer virus disciplines at a central
level within the corporation, there is an organizational approach which
has been successful.  This is the Computer Emergency Response Team (CERT)
approach, with central coordination and local control.

The CERT approach has two centrally located components.  One is very
technical, the other is technical and administrative.  The more technical
component is the virus center of competency or "research" arm of the CERT
structure.  This team operates a virus lab, deals with virus signatures,
responds to nastier virus problems, and is the ultimate consultant on
technical matters.  (This is a good candidate for outsourcing through
an antivirus service offering.)  The other CERT component is the more
administrative team that coordinates incident reports and responses,
deploys antivirus tools, coordinates antivirus education, and provides
general technical support.  This is the central CERT.

The remote infrastructure must also be properly identified.  The object
is to have local site focal points who feel responsible to support
antivirus activities.  They help educate their constituency, ensure that
tools are properly deployed and used, and assist when viruses are found.
These are the local CERTs.

The currently active CERT skill these days is PC expertise, as PC virus
incidents are the most common form of virus incident.  The team should
include mini, mainframe, and network skills as well.  CERTs should
be well connected to site security.

While the central CERT deploys effective tools, the local CERT tailors
the distribution of tools, aids, and information in a manner suitable
for his population.  For instance, technical groups can be expected to
download tools from central repositories, LAN users might receive their
tools and updates automatically from servers, and some non-technical
users will be more cooperative if they or their secretaries are given
antivirus tool diskettes on a regular basis.

INCIDENT REPORTING

The incident reporting procedure attempts to ensure that all virus
incidents are reported to central.  This procedure should be triggered
by the antivirus program detecting the virus.  That program should
either directly report, or cause the user to report the presence
of a virus to a central help desk, and simultaneously to a locally
designated antivirus SWAT team.  An E-Mail message is preferable to
a phone call, for the sake of discipline.   But if phone calls are
permitted, the recipient of the call should capture the information
electronically for action and logging.  Users should feel comfortable
about reporting viruses, i.e., no recriminations.  And they should expect
assistance when they report a virus.  However, the full assistance will
not likely come from the central location.  Users at different skill
levels need differing levels of assistance with some viruses.  This is
where local assistance comes in.  With more advanced antivirus tools, the
amount of assistance needed by end users can be greatly reduced.  If the
antivirus program tells users how to report viruses, how to disinfect,
and how to alert neighboring users, little local assistance is needed.


INCIDENT RESPONSE

The incident response procedure ensures that people reporting virus
incidents get swift and accurate advice and assistance.  The response
should step the user through containment, disinfection, and capture of
incident information.  The central CERT takes initiates a response, even
if the local team could already have replied.  A combination of canned
text and tailored messages works well here.  Canned text is pulled
together for the location, the type of infection, and the generalized
containment policy.  Tailored messages address specific aspects of the
infected person's problem.  The central CERT gives first aid, notifies
the local CERT, and copies the corporation's "research" team.  The
research team provides technical support and looks for subtleties in
incidents.  Their participation in "following the action" gives them
experience of real users under virus attack.  After the first aid
from central, local site contacts are expected to provide additional
hand-holding as necessary.

NEW VIRUS ANALYSIS

This procedure is invoked when the virus seen by the user is either new,
or a variant of a known virus.  The user is asked to send a disarmed
copy of the virus to the central CERT.  For file infecting viruses, this
means renaming the filetype.  For boot sector viruses, a disk image is
normally requested, preferably electronically, but sometimes by mail.
CERT logs in the sample and gets the suspected virus to the research
team.  The research team determines whether this is a new virus or a
variant.  If it is, a reliable signature is extracted, and made available
to the site reporting the virus.  This is necessary for proper cleanup,
as it is important to check for further contamination on the infected
system, and any other systems that had contact with the infected system.
If possible, disinfection will also be provided for the new virus.

This procedure is one that demands the highest degree of technical
expertise, and is the most time critical.  The user wants early
confirmation of the new virus.  He also wants a reliable signature.
Automated advanced techniques found in the best antivirus labs, help
ensure both responsiveness and accuracy.  However, as the process
cannot be fully automated, it depends on highly skilled research experts.


INCIDENT CLOSURE

This procedure is intended to ensure proper cleanup of viruses, and to
capture all incident statistics.  It is invoked after the site has had
sufficient time to contain, disinfect, and check neighboring systems.  A
fill-in-the-blanks closure report is requested, asking for the number of
machines infected, the number of diskettes found to have the infection,
etc.  The local CERT is key to gathering closure information on viruses.
Once the central CERT has all the closure reports it is likely to get
for a given month, the closure reports are balanced against the initial
report log.  This helps ensure the most accurate data possible for virus
incident recording.

INCIDENT TREND ANALYSIS

This procedure puts it all together.  Given a meticulous job done with
all the other procedures, the analysis of incidents portrays trends,
differentiates virus prevalence by geography, identifies leading viruses
and emerging new viruses, and compares experience between corporations.
In particular, it detect "hot spots" or locations needing special actions
either for too large a ratio of machines to incidents, or too wide a
spread of one particular virus.  These sites are candidates for special
"saturation" treatment with antivirus tools.  This is one of many ways
incident analysis dictates future antivirus actions in a corporation.

TOOLS DEPLOYMENT

This procedure gets the antivirus tools out to the corporate users in an
efficient manner, allowing regular updates to include the latest virus
signatures.  In a corporate environment, quarterly updating makes sense.
The antivirus programs should announce to the users when they are out-of
date.  With quarterly updates, a seven-month out-of-date message is
reasonable.  This assumes that some sites skip a quarterly release, and
it allows a one-month buffer for rolling out at the site.  Corporations
should require, but not expect, 100% utilization of the antivirus tools.
We are dealing with human nature here, and not everyone will think that
antivirus defense is a priority task for them.  However, with more and
more people distributing diskettes these days, we need to get corporate
deployment to 90% of our population.

ANTIVIRUS EDUCATION

While it is good to have educated users, and we should take every
natural opportunity to teach users about virus prevention, the
best time to educate people about viruses is when they are infected.
That is when you have their attention.  A good deal of virus
education is wasted on users who tune in for the entertainment
value of the topic, but walk away without changing their habits
relative to virus protection.  We have found that the best way to
disseminate education is to have the education in the antivirus
program, so that when a user is infected, he can learn effectively.

RECALL CAPABILITY

While it is hoped that a company doesn't have to do this too often,
it is necessary to know what to do if a recall of systems or diskettes
is necessary as a result of the accidental shipment of an infection.
Ethics requires prompt acknowledgement of any infection of others, but
it doesn't always require full, public confession.  Recalls are best done
directly with the infected parties, with very accurate information on
the infection, its damage and spread characteristics, and a cleanup
solution, complete with the offer of tools and assistance.  This approach
can earn respect even after you have accidentally infected someone.

EVALUATING PROCESS EFFECTIVENESS

The corporate antivirus disciplines are aimed at effective management of
a nuisance problem.  Disciplines are set up to encourage hygiene, and to
ensure near-perfect information so that the virus problem is properly
managed.  To avoid a false sense of security, we need to regularly test
the assumptions we make with regard to our antivirus disciplines.
The critical assumptions we make are:
  a) Antivirus tools are sufficiently well deployed.  Even though not
     everyone is using virus detection tools, a sufficiently high
     percentage of corporate users must, especially all "high risk"
     users - those who distribute diskettes or systems.
  b) Antivirus tools are updated frequently.  This means at least
     quarterly for "high risk" users, and at least twice per year for
     the general population.
  c) Confirmed viruses are being reported centrally.  Instead, users
     might just eradicate them and go on with their business.
  d) The deployed antivirus tools are adequate to detect viruses likely
     to be encountered.   Otherwise, newer viruses, not in signature
     lists, might get a foothold within the corporation.

If we are are tracking our corporate statistics and see growth, decline,
or stability, we can't ensure that this is reflective of corporate virus
prevalence unless we can reasonably validate our assumptions.  For
example, a trend to user laxness might diminish updating tools or
reporting.  We might conclude there are fewer viruses.  Alternately,
sudden virus religion, brought on perhaps by media attention or corporate
decree, might surface an increase in reported incidents.  Thus we must
test how our assumptions are holding up, not just for a snapshot in time,
but on a continuing basis.

We can take some measures to ensure consistent behavior of our users.
These measures include:
  a) Clear reporting actions highlighted when tools detect viruses.
  b) A "no recriminations" policy and attitude for infected users.
  c) A general attitude of helpfulness from central.
  d) Ease of access to latest versions of antivirus tools.
  e) User awareness of virus risk and benefit of using antivirus tools.
We still need to test whether the processes are consistently
implemented.  Regular surveys are a good method.  The surveys can
validate percentage using antivirus tools and frequency of update.
Surveys can also test user satisfaction with the tools, virus help desk,
etc.  If the population is uniformly networked, e.g., all LAN-attached,
we could automate the confirmation of these assumptions, or even
automate the use of the latest tools by everyone.  The trouble is, few
corporations have uniformly networked PC users, so we have to assess
the practices of stand alone PC users as well as those on a LAN.



CONCLUSION

Every company that depends on computers is going to have to deal with
the problem of harmful code.  If the company depends on an environment
or platform in which viruses already exist, such as PCs, there may be
a greater sense of urgency.  Even if the dominant environment of that
company has been virus free up to now, we know of no environment that
enjoys a natural immunity to viruses.  The problem isn't going to go
away, so it shouldn't be ignored.  On the other hand, the problem isn't
so serious or difficult that it defies effective countermeasures.
We can deal with the problem.  We can prevent infection by known viruses,
and we can reduce the risk of infection by new viruses.

We decided to get organized to deal with the phenomenon of harmful code,
and we decided to do it in a way that would prepare us not on only for
handling today's incidents, but for building the process and procedure
for dealing with newer classes of harmful code in the future.  Of course
we prefer to see the problem get no worse, but we would rather be poised
for an unpredicted escalation.

As corporations busy themselves with economic survival in the nineties,
the virus defense problem will continue to run hot and cold.  When there
are serious epidemics, corporations will spend a lot of money to make the
problem go away.  When the problem is quietly managed, corporations will
drop their guard, and possibly set themselves up for serious loss.  There
is a better and more economical way to deal with this nagging virus
problem in the information age, and that is with information.  The more
a corporation knows about its own experience with viruses, the better it
can choose an economical course to combat the problem effectively.  The
antivirus disciplines we have outlined here seem to work wonders at
getting the problem under control and properly dealing with the problem.

              ACKNOWLEDGEMENTS

   IBM T.J. Watson Research
       High Integrity          Steve White, Dave Chess, Bill Arnold,
       Computing Lab           Jeff Kephart, John Morar, et al

   IBM Antivirus Services
      IBM Central CERT &       Tom McCullough, Yann Stanczewski,
      Customer Support         Andy Hayter, Mike Rogers, & David Dean

   IBM Security Architecture   Bill Vance, Art Gilbert, & Ken Deed

   IBM Corporate Security      Phil Dolan & David Armstrong

   International Affiliates    Mark Drew, Jan Terpstra, Sue Ling,
                               John Norton, & Chris Jessen

    ...whose ideas, experience, dedication, and knowledge
    have been shared freely and drawn upon for this paper.

 

