Conficker worm hits hospital devices
April 30, 2009 By Elise AckermanA computer worm that has alarmed security experts around the world has crawled into hundreds of medical devices at dozens of hospitals in the United States and other countries, according to technologists monitoring the threat.
The worm, known as "Conficker," has not harmed any patients, they say, but it poses a potential threat to hospital operations.
"A few weeks ago, we discovered medical devices, MRI machines, infected with Conficker," said Marcus Sachs, director of the Internet Storm Center, an early warning system for Internet threats that is operated by the SANS Institute.
Around March 24, researchers monitoring the worm noticed that an imaging machine used to review high-resolution images was reaching out over the Internet to get instructions -- presumably from the programmers who created Conficker.
The researchers dug deeper and discovered that more than 300 similar devices at hospitals around the world had been compromised. The manufacturer of the devices told them none of the machines were supposed to be connected to the Internet _ and yet they were. And because the machines were running an unpatched version of Microsoft's operating system used in embedded devices they were vulnerable.
Normally, the solution would be simply to install a patch, which Microsoft released in October. But the device manufacturer said rules from the U.S. Food and Drug Administration required that a 90-day notice be given before the machines could be patched.
"For 90 days these infected machines could easily be used in an attack, including, for example, the leaking of patient information," said Rodney Joffe, a senior vice president at NeuStar, a communications company that belongs to an industry working group created to deal with the worm. "They also could be used in an attack that affects other devices on the same networks."
Joffe, who is scheduled to testify before Congress on Friday, said he will ask lawmakers to remove the barriers to coordination between federal agencies so that cyberthreats like Conficker can be addressed.
In addition to the medical-imaging machines, Joffe said the working group has seen thousands of other machines located in hospitals reach out to the Conficker mastermind by contacting another computer on the Internet for instructions. Researchers have not determined the function of these machines. They could be a personal computer sitting on a secretary's desk or more sensitive medical devices linked to patient care.
"Hopefully, the malware writers didn't have a lot of insight into how these medical devices work," said Patrik Runald, chief security adviser for F-Secure, a computer-security company based in Finland. Runald said the worm had also been found at a hospital in Sweden and several hospitals in England earlier this year.
And the danger isn't contained to hospitals.
"Microsoft Windows is a common operating system for embedded devices that is used in all industries," Joffe said. "There is no reason to believe that other industries don't have the same problem."
At the peak of the worm's infection in early spring, the Conficker Working Group estimated there were more than 10 million devices infected worldwide. Runald, whose company is part of the Conficker Working Group, said about 3 million devices are currently compromised as the others were cleaned up. But while experts have patched infected machines, they have not been able to stop the spread of the worm.
Conficker spreads by copying itself onto machines running Microsoft's Windows operating system that lack the security patch from October. Conficker installs itself and periodically reaches out for directions from its maker that cause it to rewrite its code, increasing its capabilities for malicious action and decreasing its chance of detection.
Joffe said he doubted that whoever made Conficker was specifically targeting medical devices or parts of the country's critical infrastructure, but that doesn't reduce the risk that key industries could be crippled by the worm.
"Once they work out what they've got, who knows who they will sell access to," he said. "This has to be fixed."
___
(c) 2009, San Jose Mercury News (San Jose, Calif.).
Visit the World Wide Web site of the Mercury News, at http://www.mercurynews.com/
Distributed by McClatchy-Tribune Information Services.
-
Conficker Worm Prepares For A New Release On April 1
Mar 27, 2009 |
not rated yet |
0
-
Huge computer worm Conficker stirring to life
Apr 09, 2009 |
not rated yet |
0
-
Don't fret about Conficker: Here's what to do
Mar 31, 2009 |
not rated yet |
0
-
New homeland security tool to detect Conficker worm
Mar 30, 2009 |
not rated yet |
0
-
Conficker worm digs in around the world
Apr 01, 2009 |
not rated yet |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Need help reading 3-D
15 hours ago
-
A way to send and receive wireless data
21 hours ago
-
Calling function with no input argument
Feb 10, 2012
-
Force free body diagram problem on gym equipment
Feb 10, 2012
-
Empirical data regarding shower heads and water
Feb 10, 2012
-
feed hold button on CNC lathe
Feb 09, 2012
- More from Physics Forums - General Engineering
More news stories
Google might launch Drive for cloud storage soon
(PhysOrg.com) -- Google's next big move, according to the Wall Street Journal, is a cloud storage service called Drive. Hardly first to the plate, Google is simply catching up to introducing its cloud reposi ...
Love a click away in Indonesia's Twitter Republic
He was a geeky kid from Yogyakarta, she a glamorous city girl in Jakarta. In a country with one of the world's most vibrant social networking scenes they fell in love on Twitter.
5 hours ago |
not rated yet |
0
Europeans protest controversial Internet pact
Tens of thousands of people marched in protests in more than a dozen European cities Saturday against a controversial anti-online piracy pact that critics say could curtail Internet freedom.
20 hours ago |
4.6 / 5 (9) |
0
Walney offshore wind farm is world's biggest (for now)
(PhysOrg.com) -- The Walney wind farm on the Irish Sea--characterized by high tides, waves and windy weather--officially opened this week. The farm is treated in the press as a very big deal as the Walney ...
Navy to begin tests on electromagnetic railgun prototype launcher
The Office of Naval Research (ONR)'s Electromagnetic (EM) Railgun program will take an important step forward in the coming weeks when the first industry railgun prototype launcher is tested at a facility ...
Feb 06, 2012 |
4.7 / 5 (16) |
92
|
Latin America mining boom clashes with conservation
Latin America is experiencing a mining boom as prices rise fuelled by a hike in global demand, but the region is also being hit by a wave of violent protests, strikes and rallies by environmentalists.
Explained: Sigma
It's a question that arises with virtually every major new finding in science or medicine: What makes a result reliable enough to be taken seriously? The answer has to do with statistical significance -- but ...
Political leaders play key role in how worried Americans are by climate change: study
More than extreme weather events and the work of scientists, it is national political leaders who influence how much Americans worry about the threat of climate change, new research finds.
New power source discovered
(PhysOrg.com) -- Researchers at the Massachusetts Institute of Technology (MIT) and RMIT University have made a breakthrough in energy storage and power generation.
NASA budget will axe Mars deal with Europe: scientists
US President Barack Obama's budget proposal to be submitted next week for 2013 will cut NASA's budget by 20 percent and eliminate a major partnership with Europe on Mars exploration, scientists said Thursday.
Entire genome of extinct human decoded from fossil
(PhysOrg.com) -- In 2010, Svante Pääbo and his colleagues presented a draft version of the genome from a small fragment of a human finger bone discovered in Denisova Cave in southern Siberia. The ...
Apr 30, 2009
Rank: 2 / 5 (4)
Apr 30, 2009
Rank: 2 / 5 (4)
May 01, 2009
Rank: 3 / 5 (4)
Hospitals should not be run like anyone's home office.
May 01, 2009
Rank: 1 / 5 (1)
May 01, 2009
Rank: 1 / 5 (1)
Guess it will take a 911 on the cyber-side to wake them up. Of course, just like 911, I'm sure our vigilance will lag or, indeed, become sympathetic towards the terrorists just like today.
Conflicker so far has been relatively harmless, but consider the implications if it was designed with a really nasty payload. Power grid, hospitals, and more could be severely impacted. It could literally make 911 look like a walk in the park. I am not an alarmist, but, think about it, how severely would we be affected if our computer systems were basically nullified?
May 01, 2009
Rank: not rated yet
There's an underlying battle going on, between get-rich-quick Internet companies and the law protecting personal information and property. Being in Silicon Valley, I say that, naturally, companies such as Yahoo! and Google look for youth who have high expectations for themselves, impatience with the adult world, and little understanding of law. (After all, they don't need to know law to answer any questions on the SAT.)
These younger types would cause havoc on your home computer, if they could break in, and tell you that "they were teaching you a lesson". (That's a literal quote from one of the tech gurus at Excite@Home, a major Internet ISP from a few years ago.)
But "stringing them up" is not the answer. These people act as they do because either: 1) They've been left behind by normal society, and have a grievance, or 2) They are the catspaws for amoral big business interests that are perfectly willing to pay them $100,000 USD a year -- just so long as they return $10,000,000.
May 01, 2009
Rank: 4 / 5 (1)
VaGent
May 01, 2009
Rank: not rated yet
May 04, 2009
Rank: not rated yet
Jun 01, 2009
Rank: not rated yet
The problem here is the fact that the FDA declines standard OS patches as "necessary utilization and productivity enhancement."
Effectively, if I have an FDA dosing device that runs off the windows OS I'm not allowed to patch it, use antivirus on it, or install ANYTHING, that was not in the original manufacturing specification until the FDA signs off on it on a device by device basis. Two identical devices each require an individual sign off. 90 days per device, you do the math.