文档详情

Verizon Case Study分析和总结分析和总结.docx

发布:2024-07-25约7.06千字共2页下载文档
文本预览下载声明

VerizonWasRecklessInItsFailureToTimelyAndEffectivelyActUponMicrosoft’sRepeatedWarningsRegardingThe“Critical”RiskThatTheSlammerWormPosedToTheVerySystemPlatformsThatVerizonEmploys.

AccordingtoVerizon,duringtheweekendofJanuary25,2003,certaincomputersystemsoperatedbyVerizonanditsaffiliatedcompanieswereinfectedbyanInternetcomputervirusknownas“theSlammerWorm.”(Petitionat3-4.)VerizonfurtherstatesthatthevirusexploitedthevulnerabilitiesoftheMicrosoftSQLServer2000andpropagatedsuchhighvolumesoftrafficwithinVerizon?ssystemthatVerizonwasunabletosatisfyitsthreepre-orderwholesalemeasures,specifically,thosesetforthinPAPPO-2-02.(Petitionat3)Afterdescribingtheremedialeffortsitmadeafterlearningoftheinfection(Petitionat4-6),VerizonthencontendsthatVerizoncouldnotbereasonablyexpectedtohavetakentimelypreventativemeasurestoinoculateitssystemsfromtheSlammerWorm.(Petitionat6-8.)

Verizon?scontentionsthatitcouldnothaveanticipatedandtimelyinoculateditsystemsagainsttheSlammerWormvirusarewithoutmerit.Thefactsdemonstratethatthesoftwaremaker,Microsoft,hadissuedrepeatedwarningsformonthsregardingthisvirus.ThewarningsexplicitlyrankedthesecurityrisktothesystemsusedbyVerizonas“critical.”Theusersofsuchsystemswerewarnedto“immediately”inoculatetheirsystemsagainsttheSlammerWorm.Verizontooknoactionformonths.OnlyafterthevirusstruckdidVerizonfinallytakeaction.Verizonhasasubstantialinvestmentinitscomputersystems.Prudencedictatesthatitwouldhavewell-trainedinformationtechnology(IT)managersandthatthesemanagerswouldbealerttovirusessuchastheSlammerWorm,which,asVerizonnotes,attacks“asecurityvulnerabilityinMS[Microsoft]SQLServer2000andMSDE2000.”(Petitionat8.)TheSlammerWormwaswidelyknowntotheITcommunitywellbeforeJanuar

显示全部
相似文档