ALKHOBAR, 2 September 2003 — August was a bad month for computer users everywhere. Thanks to a combination of the Internet, a few nasty programmers and plenty of compulsive clickers, hundreds of thousands of computer systems were blasted SoBig. Computer users throughout Saudi Arabia were not immune
to the viruses and worms. Clicking away insanely on every e-mail attachment in their inboxes, the Kingdom’s users unleashed the malicious code menace locally and helped contribute to the avalanche of mail clogging up networks around the world.
“I have to admit that anti-virus software isn’t usually a big seller, but the last two weeks those products have been flying off the shelves. We’ve had a boom in sales of anti-virus packages,” said Biswajit Chouwdhury, multimedia salesman, Jarir Bookstore, Al-Khobar Corniche, “You should have seen our service center, too. It was so busy. The service center looked like a computer hospital. The machines were all lined up just waiting for the PC Doctor to come and get rid of their viruses. We had one laptop that was only two days old and it got infected. Most people only think about anti-virus software after their computers have been attacked.”
How bad has the malicious code problem been in the Kingdom? “Outrageous,” is how Sami Saber, technical manager, Nesma Internet, described the situation.
“I can only give you figures for Nesma Internet,” said Saber, “But it’s easy to see how extreme the malicious code problem was in August. In one peak hour in August we received 5,000 virus-laden mails. In our worst day percentage-wise, we scanned around 264,961 files and found that 22,000 e-mails were infected. Over the last five days of August we had to remove over 40,000 infected files.”
Saber felt that most of the spread of computer viruses in the Kingdom is in large part due to computer users lacking education on the subject. He gave as an example, the casual computer users who access Nesma Internet by purchasing Internet cards. The PCs of some of these users are infected with malicious code. Even though Nesma administrators cut off those machines as soon as it is discovered that they are spewing out virus-infected mails, some of the users just go back out, buy new Internet cards and get online again without cleaning their computers.
Nesma Internet has been fighting to reduce the spread of malicious code. It has closed certain ports on the Nesma servers and has implemented an anti-Spam solution. In addition, the company is at the end of a beta testing phase in the use of anti-virus software to scan e-mail for Nesma subscribers.
“We wanted to do something that would differentiate Nesma Internet from other Saudi Internet service providers,” said Saber. “Since last week we have been very pleased with the performance of the anti-virus solution we installed. We believe our subscribers will see the high value of it as well. To have Nesma automatically scan e-mail for malicious code is something that many of our subscribers have requested. However, I want to emphasize that Nesma subscribers should still use and update the anti-virus software installed on their PCs. In addition, everyone must remember that anti-virus software alone is not enough to protect PCs and networks. Computer users must update their operating systems and other programs to reduce vulnerabilities. We have noticed that many Microsoft XP users are not taking advantage of the automatic Windows update feature. Vulnerabilities in their operating systems aren’t being patched and their machines are being corrupted.”
Saber said that Nesma Internet’s staff and equipment have been working full out to handle the current malicious code crisis. He admitted that it’s been a “tough two weeks.” While Saber is down in the ISP trenches with the users, watching over the Kingdom’s network is Eyas S.Al-Hajery, Ph.D., general director, Internet Services Unit, KACST.
“A new virus will hit the Internet every now and then. This is the ‘norm’ for the last few years,” said Al-Hajery. “If users are careful in dealing with their incoming e-mails and downloads, are up to date with patches and updates for their software, and run an up to date virus scanner, the problems of viruses would be very much contained and controlled. The problem of Internet security in general is that every user is exposed once he or she is online. There are measures to minimize the threat of this exposure, but it definitely can’t be eliminated.”
Al-Hajery commended any Saudi ISP that voluntarily chose to scan subscriber e-mail for malicious code and he suggested that ISPs could also scan web traffic. He commented that such measures would significantly reduce the risk to local Internet users from malicious programming. He did caution though that such actions on the part of the ISPs would not eliminate individuals’ responsibilities in exercising due-care.
As to whether the Saudi Internet could handle the e-mail overload, plus the normal user requirements Al-Hajery said, “Currently the total available international bandwidth is much more than the bandwidth consumed at peak times. We have 6 STM-1 links each with a capacity of 155 Mb/s (mega bit per second) with a total of more than 900 Mb/s, while the peak traffic doesn’t go beyond 360 Mb/s. The slowness at peak times could be a result of some ISPs not having enough capacity connecting them to the ISU. For this reason, ISU-KACST has put a page at its site that describes in real time the ISP line utilization.”
Local Internet users may view the line utilization of all Saudi ISPs at www.isu.net.sa/index.htm. It’s interesting to note that several ISPs are running at over 100 percent line utilization during all peak times. If your ISP is increasing profitability by scrimping on bandwidth, perhaps it’s time to look at another provider. Currently, there are 21 ISPs functioning after two major consolidations earlier in the year. Al-Hajery thought that there could be more consolidations to come, however nothing was officially on the table. Internet rates are another area of unhappiness among local users. Al-Hajery was very clear in his position on this issue.
“The current Internet pricing was approved July 2002,” he said. “We feel the rates should be reviewed to consider a reduction. KACST puts the pricing rates that it charges ISPs based on the pricing that STC charges KACST for the international circuits. KACST is willing to pass on whatever reduction it will receive from STC.”
For the near future, Internet users everywhere will continue to be under attack. The malicious program called “SoBig,” which is transmitted as an e-mail attachment and then resends itself via the Internet, is still causing problems globally. SoBig.F is the sixth variant of this program created by an unknown attacker. IT security experts claim that during the past eight months the creator(s) of SoBig have tried again and again to implant a range of secret tools for stealing information and sending Spam. IT Security firms are already preparing for SoBig.G.
All users of Windows XP, NT and 2000, should update their security patches at windowsupdate.microsoft.com. Every computer should have a firewall and anti-virus software, activated all the time and updated automatically. Another excellent defense against viruses, worms and all malicious code is to avoid opening file attachments. Before opening any attachment, contact the sender and verify what the attachment contains. Remember that in many virus attacks people’s address books are co-opted by the malicious program to send out e-mail with a copy of the virus attached. Consequently, friends and business contacts are often the ones most likely to send you a malicious e-mail. Don’t forget that with spoofing, anyone’s e-mail address can be taken over and abused. Think before you click. Your anti-virus software might not detect very new viruses and worms. If there’s any doubt about the contents of the attachment don’t open it! Your computer will be grateful.
The malicious code situation is getting worse every year and some experts are calling for regulations to force vendors to develop less buggy software and create more resilient systems. The penalties for unleashing malicious code must be strengthened globally. Jeffrey Lee Parson, 18, of Hopkins, Minn., has been arrested and charged with writing the variation of the Blaster worm. If found guilty, he might be sentenced to 10 years in prison. Parson was unlucky. Malicious code writers in many other countries, including Saudi Arabia, face either no penalty or a minimal one, no matter how much damage their virus or worm might cause.
The last bit we have on offer this week is something for considered thought. The University of Calgary in Canada has announced a new undergraduate course for its fall session. Computer Science 599.48: Computer Viruses and Malware, will be taught by Prof. John Aycock. The course descriptions states, “This course will focus on malicious software, or malware, such as computer viruses, worms, and Trojan horses. Malware techniques will be studied, along with countermeasures and so-called ‘benevolent’ forms of malware. Legal and ethical issues will be covered, as will more general computer and network security issues. Students should have strong low-level programming skills.
Course assignments will involve creating malware under controlled lab conditions.”
The 16 students taking the course must work on their assignments only in a designated lab. They must sign an agreement that they will comply with security procedures in the lab and that they understand that misuse of the information in this course could result in civil and criminal penalties under the laws of Canada and of other countries. There is a hot debate on the Internet right now about whether it is a good idea for a university to teach 20-year-old students to write malicious code.
What do you think?
(Comments to: [email protected].)

