Large scale downtime sounds the alarm for global information technology security
2024-07-22
On the 19th, the Microsoft Windows system and other applications and services of the company experienced a large-scale outage, causing multiple industries such as aviation, railways, shipping, finance, healthcare, and hotels to be unable to operate normally. The work and life of many enterprises and individual users were severely disrupted. Microsoft CEO Satya Nadella confirmed in a post on social media X that a software update released by the security technology company "CrowdStrike" that provides services to Microsoft was the main cause of the global outage. The scope and severity of the impact of this downtime event are extremely rare, sounding an alarm for governments, industries, and individual users around the world. Jonathan Ali, a cybersecurity expert at the British Institute of Engineering and Technology, pointed out that the scale of this outage may be "unprecedented" and poses a significant challenge to global information technology (IT) industry teams, but it also provides important experience for software engineering professionals. It will take time to completely eliminate the impact. According to foreign media reports, the US based "Zhongdao" company has over 20000 customers worldwide, including tech giants such as Microsoft and Amazon. On the 19th, the CEO of the company, George Kurtz, posted on social media X that the incident did not involve a cyber attack, but rather stemmed from a "defect" in the software update released by the company for Microsoft's Windows system. The issue has been identified, isolated, and repair measures have been deployed. Kurtz also said in a media interview that day, 'We deeply apologize for the impact we have caused to our customers, travelers, and all those affected.' The company is working hard to resolve the issue, but some systems may take 'some time' to recover from this malfunction. Although "Zhongdao" company has collaborated with Microsoft to quickly restore most of its services, experts believe that further evaluation of the long-term impact of this downtime event is needed. Adam Smith, a cybersecurity expert at the British Computer Society, pointed out that the repair program must be applied to a large number of computers around the world, which will take some time. But if the computer enters a blue screen and infinite loop, recovery may be more difficult, taking several days or even weeks. Jules Ali believes that the company "Strike" is making this incident a top priority to address. "The long-term impact of this downtime has not yet been fully understood, but they will affect the timely adoption of future key security updates." Experts who remain vigilant about IT system risks believe that downtime highlights the vulnerability of global Internet infrastructure, and need to be vigilant about the complexity of IT systems and the potential risks of highly relying on network infrastructure in various fields. Ian Corden, an expert from the British Institute of Engineering and Technology, said that major IT system disruptions occurring around the world reflect the increasing dependence on digital services in areas such as the economy, defense, and national security, highlighting the importance of digital service security and resilience. Omoronia, an expert from the School of Computer Science at the University of Bristol in the UK, believes that we need to be constantly vigilant about the cloud infrastructure and other critical systems that we rely on every day. Today's network infrastructure is very complex and heavily dependent, and for those responsible for building this infrastructure, these risks are often not obvious. There are also complex situations in this incident that are still unknown to the public. For example, many foreign media have mentioned issues with Microsoft Windows system and other applications and services of the company. Some media quoted a Microsoft spokesperson as saying that the problem with Microsoft 365 service on the night of July 18th to 19th is not related to the software update of "Zhongdao" company. Overall, industry insiders generally believe that the reason for the widespread downtime of Microsoft's Windows system is due to errors made by the "crowdsourcing" company in software updates. Industry insiders suggest that companies should thoroughly review the potential risks of their network security solutions before deploying security software. The lesson here is clear: investing in cybersecurity is not just about acquiring the latest or most popular tools, but also about ensuring that these tools are reliable and resilient, "said Al Lacani, founder and CEO of digital security enterprise IDEE, in a statement. The urgent need to improve emergency response capabilities has affected the world and exposed the shortcomings of some" lifeline "industries and large enterprises that heavily rely on IT systems in emergency response capabilities. For example, the global aviation industry has been severely impacted by downtime. According to data from flight tracking websites cited by the Associated Press, as of the evening of the 19th Eastern Time, nearly 2800 flights in the United States have been cancelled, nearly 10000 flights have been delayed, and approximately 4400 flights worldwide have been cancelled. Industry insiders point out that enterprises should establish and improve emergency response plans for network failures, conduct regular drills to ensure quick response and recovery in the event of a failure. Corden pointed out that in order to mitigate the impact of network failures, enterprises should install backup systems, leave infrastructure redundancy, conduct regular disaster recovery testing, and establish strict software update protocols. In addition, enterprises should use advanced monitoring tools, provide IT personnel training on responding to unexpected situations such as downtime, and closely cooperate with third-party suppliers to ensure the development of effective security strategies. Australian National University computer expert Tom Worthington warns that widespread crashes demonstrate the risk of relying on a single technology to provide critical services, and that different software should be used to establish backup communication links. This does increase security and maintenance costs, but 'putting all your eggs in one basket may ultimately be embarrassing'. (New Society)
Edit:Xiong Dafei Responsible editor:Li Xiang
Source:www.ce.cn
Special statement: if the pictures and texts reproduced or quoted on this site infringe your legitimate rights and interests, please contact this site, and this site will correct and delete them in time. For copyright issues and website cooperation, please contact through outlook new era email:lwxsd@liaowanghn.com