Computer scientist forges new line of defense against malicious traffic

November 5, 2007

Paul Barford has watched malicious traffic on the Internet evolve from childish pranks to a billion-dollar "shadow industry" in the last decade, and his profession has largely been one step behind the bad guys.

Viruses, phishing scams, worms and spyware are only the beginning, he says.

"Some of the most worrisome threats today are things called 'botnets' - computers that are taken over by an outside party and are beyond the user's control," says Barford, a computer scientist at the University of Wisconsin-Madison. "They can do all sorts of nasty things: steal passwords, credit card numbers and personal information, and use the infected machine to forward spam and attack other machines.

"Botnets represent a convergence of all of the other threats that have existed for some time," he adds.

One of the most menacing aspects of botnets is that they can go largely undetected by the owner of a personal computer. That feature has allowed botnets to grow exponentially online, with millions of infected computers bought and traded on an underground market that one security company estimates has surpassed $1 billion in activity, Barford says.

Motivated by this growing threat, Barford is developing a new technology that may head off hackers at the pass.

In June 2007, Barford and colleagues opened a spinoff company at the MG&E Innovation Center of University Research Park called Nemean Networks, LLC. The company is developing a new approach to detecting network intrusions that offers a significant improvement over the current state of the art. Nemean is based on four distinct patents that are either filed or are in process with the Wisconsin Alumni Research Foundation (WARF).

Nemean is named after the first of Hercules' 12 labors, in which Hercules must kill the Nemean lion whose coat was impenetrable by weapons. It's an apt metaphor for the technology, which seeks to hunt down a slight vulnerability in malicious traffic: the unique "signature" such traffic generates.

Most network-intrusion systems today are comparing traffic against a database, collected by hand, of previously recognized attack signatures. The innovation with Nemean is a method to automatically generate intrusion signatures, making the detection process faster and more precise.

The Achilles' heel of current commercial technology is the number of false positives they generate, Barford says. Hackers have become so adept at disguising malicious traffic to look benign, security systems now generate literally thousands of false positives for each genuine intrusion they find. Nemean virtually eliminates false positives.

In a test comparing Nemean against a current technology on the market, both had a high detection rate of malicious signatures - 99.9 percent for Nemean and 99.7 for the comparison technology. However, Nemean had zero false positives, compared to 88,000 generated by the other technology during the same time frame.

"The technology we're developing here really has the potential to transform the face of network security," says Barford. "Our objective is to build this company into a world leader in network security solutions."

Barford's research is supported by the National Science Foundation, the Army Research Office and the Department of Homeland Security. Nemean was developed and tested on the Wisconsin Advanced Internet Laboratory (WAIL), a unique test bed for examining complex behavior on the Internet. WAIL provides researchers with a microcosm of the Internet, allowing them to study security, speed, efficiency of transfer and other Internet issues. Funded by Cisco Systems CEO John Morgridge, WAIL is a computer science parallel to the model organism in biology.

While Barford has high hopes for Nemean, he says Internet security is a continuous process and there will never be a single cure-all to the problem. "This is an arms race and we're always one step behind," he says. "We have to cover all the vulnerabilities. The bad guys only have to find one."

Nemean is funded by an angel investment group composed of UW-Madison alumni who are working to foster technology transfer from the campus. The company also is working in close partnership with the Department of Information Technology (DOIT) at UW-Madison to test and evaluate the research prototype version of its first product.

Source: UW-Madison


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.6 /5 (23 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • SeymoreM_Athy - Nov 06, 2007
    • Rank: 5 / 5 (1)
    Does anyone know the longterm effects on the human mind, when they are faced with the threat of having someone or something constantly trying to come into their home to steal their information or property, and at the same time not being able to see or know who the perpetrators are. Does the internet have to be such a dark place or is there a switch somewhere to turn on the lights so we can see who or what is at our doorstep before we open it.
  • irjsi - Nov 06, 2007
    • Rank: not rated yet
    S.M Athy
    . . . . Does the internet have to be
    such a dark place or is there a switch
    somewhere to turn on the lights so we can
    see who or what is at our doorstep
    before we open it. . . . .

    Also a method of retracing the digital
    steps from the originating address of
    the miscreant, who should be FOREVER
    banned from entry to the WWW!
    Prison time would help, as well!

    Roy Stewart,
    Phoenix AZ

November 5, 2007 all stories

Comments: 2

4.6 /5 (23 votes)
  • Stumble this up

  • Digg this

  • share this



  • hide
  • Relevant PhysicsForums posts

  • casio calculator that's similar to TI-89
    created 19 hours ago
  • Mathematica Question: Finding local maximums
    created 22 hours ago
  • Advice on what cell phone to get
    created 23 hours ago
  • Read multiple binary files to ascii
    created Nov 07, 2009
  • Engineering Translation software
    created Nov 06, 2009
  • Changing the language options on your phone.
    created Nov 03, 2009
  • More from Physics Forums - Computing & Technology

Other News

Computer scientists work to strengthen online security

Technology / Computer Sciences

created 1hour ago | popularity not rated yet | comments 1

If you forget your password when logging into an e-mail or online shopping Web site, the site will likely ask you a security question: What is your mother's maiden name? Where were you born?


Video fingerprinting offers search solution

Video fingerprinting offers search solution

Technology / Computer Sciences

created 1hour ago | popularity not rated yet | comments 0

(PhysOrg.com) -- The explosive growth of video on the internet calls for new ways of sorting and searching audiovisual content. A team of European researchers has developed a groundbreaking solution that is ...


Tesla Roadster

Tesla Roadster Goes 313 Miles on a Single Charge

Technology / Energy

created 4 hours ago | popularity 4.7 / 5 (7) | comments 1

(PhysOrg.com) -- Tesla is becoming synonymous with high performance electric cars. Indeed, the Tesla car company has been making efforts to create a brand of sports car that runs on electricity, and does so ...


Google to buy mobile ad network for $750 million

Technology / Internet

created 3 hours ago | popularity 5 / 5 (1) | comments 0

(AP) -- Google Inc. is stepping up its push to sell advertising on cell phones, announcing a deal Monday to buy a mobile ad network, AdMob, for $750 million in stock.


Commercialization of new solar technology to boost solar efficiency

Technology / Energy

created 1hour ago | popularity 5 / 5 (2) | comments 0

A pioneer in solar power in the 1990s before it became "sexy," University of Houston Professor Alex Freundlich recently entered into a collaborative research agreement with U.K.-based start-up QuantaSol for the development ...