The internet worm program: an analysis

Eugene H. Spafford

ACM SIGCOMM Computer Communication Review · 1989 · 397 citations · 4 references

Concepts

TL;DR

On 2 November 1988, a worm program infected the Internet. The worm exploited vulnerabilities in BSD‑derived UNIX utilities, allowing it to infiltrate machines and replicate itself, as revealed by reverse‑engineering and VAX assembly analysis. The worm infected thousands of machines, disrupting Internet connectivity, and the report provides a detailed component analysis, reviews exploited security flaws, offers mitigation recommendations, and assesses the author’s coding style and intent.

Abstract

On the evening of 2 November 1988, someone infected the Internet with a worm program. That program exploited flaws in utility programs in systems based on BSD-derived versions of UNIX. The flaws allowed the program to break into those machines and copy itself, thus infecting those systems. This program eventually spread to thousands of machines, and disrupted normal activities and Internet connectivity for many days.This report gives a detailed description of the components of the worm program---data and functions. It is based on study of two completely independent reverse-compilations of the worm and a version disassembled to VAX assembly language. Almost no source code is given in the paper because of current concerns about the state of the "immune system" of Internet hosts, but the description should be detailed enough to allow the reader to understand the behavior of the program.The paper contains a review of the security flaws exploited by the worm program, and gives some recommendations on how to eliminate or mitigate their future use. The report also includes an analysis of the coding style and methods used by the author(s) of the worm, and draws some conclusions about his abilities and intent.

References

4