Bad plumbers and leaking software

Insufficient testing and delayed patches make for unreliable software products, writes William Knight.

Written by William Knight

Like a filthy carpet can feed unwelcome vermin, so bad practice in software development can support criminal intent. Only rigorous process will stop them feeding on crumbs from the developer's table.

On 2 November 1988 Robert Morris released an internet worm, a small piece of C code that employed the buffer overflow tactic.

It was a simple concept, the equivalent of theft by putting a hose through a letterbox and waiting for the owner's private possessions to float out of the window.

Careful software construction would have prevented the overflow by using the equivalent of a ball-cock but, like a shoddy plumber, the software developer can often decide that the problem is unlikely to happen and ignore the issue.

Perhaps worse, inexperience might lead them to believe that a buffer overflow may not even be due.

The C programming language has long been susceptible to such errors, so failure to test for these faults is inexcusable.

Recently, however, a new threat lurking in the grubby carpet has been exposed. The Witty worm struck flawed software from Internet Security Systems on a Saturday morning.

Just one day after the flaw was publicised, vulnerable systems were quickly out of action before patches could be installed.

In other words, Internet Security Systems told users that its tank was about to overflow, but water flooded the building while it was waiting for the plumber.

It's never easy to get a tradesman at the weekend, so timing was a critical part of the virus writer's grand plan.

Other viruses have taken advantage of coding difficulties. Klez, Swen, Tanatos and Netsky made use of a flaw in Internet Explorer, causing automatic execution of attachments on HTML emails.

The Slammer worm exploited what Microsoft called "an unauthenticated remote compromise" in MS SQL Server 2000, which amounts to another buffer overflow attack.

Combining with a design feature of SQL Server, the worm had machines answering remote 'pings' from unknown sources and engaging in never ending conversations with one another, resulting in international meltdown.

The exploitation of coding flaws suggests badly-designed or poorly-tested software. Software development can be extremely complex, as the solution space is vast and there are thousands of ways to solve a problem.

Possible wormholes can only be filled through methodical design, proper testing and considered choice of development lifecycle.

It might be excusable to release software that falls victim to a new and ingenious attack: the unpredictable nature of faults makes life difficult for software testers, who must creatively imagine possible failure modes according to experience and wit.

But in the case of well-known and likely errors, exploitation only points to bad process.

While not all of us build software for worldwide use, all projects have a primary concern of quality and a duty of care to their users.

In particular, developers must make sure that they employ techniques which minimise the risk of creating holes, and then assure quality by review and thorough testing.

It's possible that the writing's on the wall for current methods of customer protection. Witty hit the day after the error in the code had been discovered and publicised, so it could be argued that the vendor should have kept quiet. But this in itself could be considered negligent, so there is little choice but to publish.

Colleen Shannon and David Moore, at the Cooperative Association for Internet Data Analysis, have this to say: "The fact that all victims were compromised ... the day after a vulnerability in that software was publicised indicates that the security model in which end users apply patches to plug security holes is not viable."

If patches merely alert the virus writer, and litigation is looming for unknowing virus spreaders, then the application of better practice in development before the product is released is something we must forcibly demand from our vendors.

William Knight is a software developer.

  • Have your say
  • Send to a friend
  • Print this
  • Share

Tags:

reader comments

related articles

Security

Security

The latest wave of cyber-crimes and acts of vandalism have demonstrated once again that many systems are still vulnerable to attack. 15 Apr 2004

 

related whitepapers

today's top stories

Face facts: social media is the future

No organisation can afford to ignore the way business communications are changing 18 Mar 2010

Is the data watchdog about to pounce?

Experts believe the Information Commissioner’s Office is itching to use its new power to impose hefty fines for data breaches. Martin Courtney reports 18 Mar 2010

Lloyd’s of London gears up for regulation

CIO Peter Hambling tells Angelica Mari about how the insurance market has updated its IT infrastructure to comply with new regulations 18 Mar 2010

Protests greet new Digital Economy Bill amendment

ISPs, digital rights groups and Liberal Democrat supporters cry foul 05 Mar 2010

IT Leaders' Forum in association with IBM

A unique opportunity to hear from expert speakers and engage in a debate about the future of the CIO job function 29 Jan 2010

Advertisement

Keys to successful Service‐Oriented Architecture implementation

This white paper explores best practices and general design patterns for service oriented architecture (SOA).

The Roadmap to IT Maturity — Matching Strategy to Infrastructure for Business Success

This paper defines a roadmap for matching infrastructure strategy to business success.

Advertisement

Keep up to date with the latest products, services and technologies from the world's leading IT companies; ITHound.com brings you over 6,000 white papers, case studies and analyst reports.

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

More available - click 'submit' to view

Existing User

Newsletter user login:

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

Latest poll

NHS centralised data

NHS centralised data

Do you think the NHS can be trusted to safely look after personal data electronically?

View poll results

Latest audio and video articles

Video

HP unveils S Series notebooks

'Prosumer' line overhauled 01 Mar 2010

Web Seminar Listings

Preparing for enterprise-scale Windows 7 migration

The web seminar on 18 Feb will discuss how Windows 7 migration can increase IT efficiency in large enterprises, freeing up budgetary and personnel resources to focus on business innovation. Our panel of experts will examine the strategies, tools and services IT leaders can use to migrate successfully and reap the rewards of increased efficiency. 19 Feb 2010

Latest in-depth articles

Smiths Group CIO Brian JonesAnalysis

Q&A: Brian Jones, CIO, Smiths Group

How should conglomerates be looking at the new IT technologies coming through? Brian Jones explains. 19 Mar 2010

Analysis

What security strategy should enterprises adopt after the recession?

Act now to put your your firm on higher growth path advise CISOs 19 Mar 2010

Primary Navigation