Trojan Horse Delivered In Automatic Update

Titlesystem to prevent any type of external
Trojan Horse Delivered In Automatic Updatecommunication to its local peers and external
Trojan Horse - One Mans "Worse Case Scenario"(Internet) hosts. It does this in such as way that
Predictionthe only immediate method to recover from this
This is a fictional article about a Trojan Horseis a system roll-back, system repair, or restore
Virus, or you could say it is one mans predictionfrom near-line media, such as tape or disk. And as
of a "worse case scenario". Because of the fieldfar as system recovery is concerned, I can tell
I'm in, I maintain a personal list of my top 10you that many people even in corporate entities
"worse case scenarios". Every time I perform ado not perform the most basic steps to be
security assessment I run into something new orprepared for a quick system disaster recovery. In
identify a situation that is ripe for a potentialsome cases, some of the most important
vulnerability. I think we could all agree that norecovery services have been disabled because of
respectable or ethical company would intentionallylack of system resources or disk space (which is
deliver a malicious piece of code as part of aamazing given how inexpensive this is anymore).
helpful update solution. However, the reality is thatWhat Could Be The Impact Of This "Trusted"
human beings are behind technology and humanTrojan Horse
beings are unpredictable and fallible.Just about every time you install a new application
Many major operating system vendors haveor piece of software you increase the time it
automatic update services. Many hardwaretakes to boot your PC and in some cases
vendors and other software packages havedecrease its performance. On thing that drives
followed this trend, incorporating automatedme crazy is printing software. For the life of me I
update services into their products. In somecannot understand how or why printer support
cases, the services for automatic updates run assoftware could total 400MB in size, but they
the local "system" account. This account has thesometimes do. Not only that, they tend to load all
ability to access and modify most of thekinds of unnecessary real-time running applets. HP
operating system and application environment.printers are notorious for this. Be very aware of
When automatic updates were relative new,what it is you are loading and only load those
many people would perform the updatescomponents that you need. Even some
manually, however, as time has progressed, manyoff-the-shelf software packages load adware and
now trust these services and allow the updatesother not so helpful applets. Also, when you
to proceed in a truly automated fashion.uninstall software, not all the software gets
The Final Step Before The Hammer Fallsuninstalled in many cases. One thing I suggest is
So let's expand upon our "worse case scenario". Ato purchase a registry cleaner. This can
new service pack is just about ready for release.dramatically decrease boot times and in many
The last step prior to public release is qualitycases increase the overall performance of your
control / validation. The team of peoplePC.
performing this task includes a significantlyPeople are already concerned about identity theft,
disgruntled employee (Or may he/she is goingor at least they should be. I recently spoke with a
through a horrible life crisis and has not much tobusiness associate that told me that even with
lose). When people are in pain or distress it is noteverything he does to keep his identity secure he
uncommon for them to project this same feelinghas been the victim of identity theft not once,
onto others in any way they can. So, instead ofbut twice. If your user id's, online accounts,
performing their job in the normal fashion, theypasswords, financials, or other confidential
decide to incorporate a malicious payload into theinformation winds up on the Internet for any
forthcoming update.anonymous person to see, you can bet it will be
The First Step For The Trojan Horse: Evasionused in a way to cause you problems. Even if
This payload has some unique characteristic, threeonly 10% of the global systems fell victim to this
to be precise. First, it is constructed in such asTrojan Horse, the cut off of communications
way to not appear as something malicious. Thecould cost businesses billions of dollars and
anti-virus and anti-spyware programs currently onpotentially impact their reputation as "secure"
the market won't be able to detect it throughinstitutions.
anomalous detection techniques.Conclusion
The Second Step For The Trojan Horse:If we don't think that this "worse case scenario"
Information Collectioncan happen, then we're kidding ourselves.
Secondly, it has been instructed to wait 12 hoursRecently, one of the market leaders in the
to activate to start searching your computer anperimeter defense business had to recall a service
network for important files that may containpack because it contained a significant "bug" that
financial, healthcare, and other confidentialcould result in a security breach; a service pack
information such as user accounts and passwords.that can be delivered through and intelligent
It then sends this information to anonymousupdate service. Obviously there has to be a
systems on the Internet. Because this "Trojancertain level of trust between us, the consumer,
horse" has been incorporated into an automatedand the vendors of hardware / software we rely
update by someone with reasonable skills, it ison. I'm not entirely sure what "fail-proof" solution
instructed to only perform the collection of datacan be put in place to prevent something like this
for 12 hours. Given the number of global systemsfrom happening. Although I'm sure there are quite
that allow automated updates, 12 hours should bea few checks and balances in place already. The
more than enough. The person behind this realizesbottom line is, if you or I can image a scenario like
that someone will quickly identify that somethingthis, there is always a chance of it happening. In
malicious is going on and start to roll-out amy case, I usually wait for several days to apply
defense solution to halt the process.new service packs and hot-fixes. Hopefully
The Final Step: Incapacitatesomeone else will find the problem, correct it, and
Finally, the Trojan Horse will cease it's datathen I'll apply it.
collection and deliver it's final blow. Because of theYou may reprint or publish this article free of
level of system privilege it is running at, it modifiescharge as long as the bylines are included.
the communication protocols and services on the