Computer scientist forges new line of defense against malicious traffic
November 5, 2007Paul Barford has watched malicious traffic on the Internet evolve from childish pranks to a billion-dollar "shadow industry" in the last decade, and his profession has largely been one step behind the bad guys.
Viruses, phishing scams, worms and spyware are only the beginning, he says.
"Some of the most worrisome threats today are things called 'botnets' - computers that are taken over by an outside party and are beyond the user's control," says Barford, a computer scientist at the University of Wisconsin-Madison. "They can do all sorts of nasty things: steal passwords, credit card numbers and personal information, and use the infected machine to forward spam and attack other machines.
"Botnets represent a convergence of all of the other threats that have existed for some time," he adds.
One of the most menacing aspects of botnets is that they can go largely undetected by the owner of a personal computer. That feature has allowed botnets to grow exponentially online, with millions of infected computers bought and traded on an underground market that one security company estimates has surpassed $1 billion in activity, Barford says.
Motivated by this growing threat, Barford is developing a new technology that may head off hackers at the pass.
In June 2007, Barford and colleagues opened a spinoff company at the MG&E Innovation Center of University Research Park called Nemean Networks, LLC. The company is developing a new approach to detecting network intrusions that offers a significant improvement over the current state of the art. Nemean is based on four distinct patents that are either filed or are in process with the Wisconsin Alumni Research Foundation (WARF).
Nemean is named after the first of Hercules' 12 labors, in which Hercules must kill the Nemean lion whose coat was impenetrable by weapons. It's an apt metaphor for the technology, which seeks to hunt down a slight vulnerability in malicious traffic: the unique "signature" such traffic generates.
Most network-intrusion systems today are comparing traffic against a database, collected by hand, of previously recognized attack signatures. The innovation with Nemean is a method to automatically generate intrusion signatures, making the detection process faster and more precise.
The Achilles' heel of current commercial technology is the number of false positives they generate, Barford says. Hackers have become so adept at disguising malicious traffic to look benign, security systems now generate literally thousands of false positives for each genuine intrusion they find. Nemean virtually eliminates false positives.
In a test comparing Nemean against a current technology on the market, both had a high detection rate of malicious signatures - 99.9 percent for Nemean and 99.7 for the comparison technology. However, Nemean had zero false positives, compared to 88,000 generated by the other technology during the same time frame.
"The technology we're developing here really has the potential to transform the face of network security," says Barford. "Our objective is to build this company into a world leader in network security solutions."
Barford's research is supported by the National Science Foundation, the Army Research Office and the Department of Homeland Security. Nemean was developed and tested on the Wisconsin Advanced Internet Laboratory (WAIL), a unique test bed for examining complex behavior on the Internet. WAIL provides researchers with a microcosm of the Internet, allowing them to study security, speed, efficiency of transfer and other Internet issues. Funded by Cisco Systems CEO John Morgridge, WAIL is a computer science parallel to the model organism in biology.
While Barford has high hopes for Nemean, he says Internet security is a continuous process and there will never be a single cure-all to the problem. "This is an arms race and we're always one step behind," he says. "We have to cover all the vulnerabilities. The bad guys only have to find one."
Nemean is funded by an angel investment group composed of UW-Madison alumni who are working to foster technology transfer from the campus. The company also is working in close partnership with the Department of Information Technology (DOIT) at UW-Madison to test and evaluate the research prototype version of its first product.
Source: UW-Madison
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (30) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
-
Need help with my technical fest!
Jan 19, 2012
- More from Physics Forums - Computing & Technology
More news stories
Sony's Hirai refuses to abandon dire TV business
Struggling Japanese entertainment giant Sony will not abandon its cash-bleeding television business, its incoming CEO says, but he acknowledges tough decisions lie ahead including over redundancies.
6 minutes ago |
not rated yet |
0
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
2 hours ago |
5 / 5 (2) |
2
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
2 hours ago |
5 / 5 (4) |
7
|
Advanced power-grid model finds low-cost, low-carbon future in West
(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...
Technology / Energy & Green Tech
2 hours ago |
5 / 5 (1) |
3
|
Engineering images bring life to submerged city
(PhysOrg.com) -- Photo-realistic 3D mapping and digital reconstruction of an ancient underwater city in Greece have earned a team from the University of Sydney's Faculty of Engineering and Information Technologies ...
1 hour ago |
not rated yet |
1
The power of estrogen -- male snakes attract other males
A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...
Could Venus be shifting gear?
(PhysOrg.com) -- ESAs Venus Express spacecraft has discovered that our cloud-covered neighbour spins a little slower than previously measured. Peering through the dense atmosphere in the infrared, the ...
Experts reveal how plants don't get sunburn
(PhysOrg.com) -- Experts at the University of Glasgow have discovered how plants survive the harmful rays of the sun.
Team isolates nerve cells involved in storing long term memory and gene proteins associated with them
(Medical Xpress) -- A research team in Taiwan has succeeded in isolating two nerve cells in fruit fly brains that are believed to be the major players in allowing for the formation of long term memories. Furthermore, ...
Fool's gold may prove an unlikely alternative to overexploited catalytic materials
Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...
SLAC, Stanford team focuses on high-energy electrons to treat cancer
Accelerator physicists at SLAC and cancer specialists from Stanford are working on a new technology that could dramatically reduce the time needed for cancer radiation treatments. The team ran an initial experiment ...
Nov 06, 2007
Rank: 5 / 5 (1)
Nov 06, 2007
Rank: not rated yet
. . . . Does the internet have to be
such a dark place or is there a switch
somewhere to turn on the lights so we can
see who or what is at our doorstep
before we open it. . . . .
Also a method of retracing the digital
steps from the originating address of
the miscreant, who should be FOREVER
banned from entry to the WWW!
Prison time would help, as well!
Roy Stewart,
Phoenix AZ