The Robert Morris Worm

The Robert Morris Worm (also called the Internet Worm) was a worm released onto the Internet the evening of November 2, 1988, causing serious damage to the network. The worm was developed and released by Robert T. Morris, Jr., a graduate student at Cornell University. The damage caused was estimated between $100,000 and $97 million, and Morris was later convicted of violating the Computer Fraud and Abuse Act, for which he received a fine of $10,000, a suspended three year jail sentence, and 400 hours of community service.(1)

The primary damage caused by the worm was due to resources exhaustion. The worm was designed to check whether a target host was already infected so that duplicate copies were not created on the same host, but due to a flaw in the code many copies were created on each machine, causing a serious downgrade in performance as the worms used more and more resources. The worm caused secondary damage when system administrators began disconnecting their machines from the Internet in an effort to either avoid spreading the infection or to avoid the infection in the first place. As a tertiary effect of the worm, caused by the disconnection of so many systems, research and business relying on network connections was disrupted. In total, an estimated 6,000 installations had to either shut down or disconnect from the Internet. Many of the machines were disconnected for several days and closed for normal use. As in the case of the SQL Slammer worm of 2003, the Morris worm did not cause as much damage as it could have had it contained code instructing it to delete or encrypt files on its hosts.(2)

The Morris worm had a tremendous impact on the Internet community, mostly composed of academics and researchers at the time. The flaws in the Unix system that had allowed the worm to spread were fixed, and system administrators began to look for ways to boost security. The worm was released at about the same time that Clifford Stoll reported on his investigation of the "Cuckoo's Egg" hacker. The combination of events led the computing community to the conclusion that better organization was needed for dealing with malicious and non-malicious code flaws. One of the results was the formation of the Computer Emergency Response Team (CERT) at Carnegie Mellon University and other such centers that allowed system administrators to exchange information on problems and solutions.(3)


1 , 2 , 3 : Charles P. Pfleeger and Shari Lawrence Pfleeger, Security in Computing. 3rd Edition, New Jersey: Prentice Hall, 2003.

