Low-cost strategy developed for curbing computer worms

January 13, 2009

Thanks to an ingenious new strategy devised by researchers at University of California, Davis and Intel Corporation, computer network administrators might soon be able to mount effective, low-cost defenses against self-propagating infectious programs known as worms.

Many computers are already equipped with software that can detect when another computer is attempting to attack it. Yet the software usually cannot identify newly-minted worms that do not share features with earlier marauders. When network managers detect suspicious activity, they face a major dilemma, said Senthil Cheetancheri, who led efforts to develop the strategy. "The question is, 'Should I shut down the network and risk losing business for a couple of hours for what could be a false alarm, or should I keep it running and risk getting infected?'"

Cheetancheri, a graduate student in the Computer Security Laboratory at UC Davis when he did the work, has shown that the conundrum can be overcome by enabling computers to share information about anomalous activity. As signals come in from other machines in the network, each computer compiles the data to continually calculate the probability that a worm attack is underway. "One suspicious activity in a network with 100 computers can't tell you much," he said. "But when you see half a dozen activities and counting, you know that something's happening."

The second part of the strategy is an algorithm that weighs the cost of a computer being disconnected from the network against the cost of it being infected by a worm. Results of this ongoing process depend on the calculated probability of an attack, and vary from computer to computer depending on what the machine is used for. The algorithm triggers a toggle to disconnect the computer whenever the cost of infection outweighs the benefit of staying online, and vice versa.

The computer used by a person working with online sales, for example, might be disconnected only when the threat of an attack is virtually certain; the benefit she provides by continuing to work during false alarms far outweighs the cost of infection. On the other hand, a computer used by a copy writer who can complete various tasks offline might disconnect whenever the probability of an attack rises above even a very low level.

The study is published in "Recent Advances in Intrusion Detection, 2008," the proceedings of a symposium that was held in Cambridge, Mass., in September, 2008.

Source: University of California - Davis


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.4 /5 (5 votes)

Rank Filter

Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

  • physpuppy - Jan 13, 2009
    • Rank: 5 / 5 (1)
    he conundrum can be overcome by enabling computers to share information about anomalous activity. As signals come in from other machines in the network, each computer compiles the data to continually calculate the probability that a worm attack is underway.

    ...
    The algorithm triggers a toggle to disconnect the computer whenever the cost of infection outweighs the benefit of staying online, and vice versa


    If implemented, who wants to bet that someone will come up with malicious code that causes false positives and triggers this protection code to pull machines off the network.

  • Corban - Jan 13, 2009
    • Rank: not rated yet
    The worm would no longer deal damage to computers, but Physpuppy's got the right idea: what about a DDOS?
  • physpuppy - Jan 13, 2009
    • Rank: not rated yet
    If you're interested in this sort of thing - security and computer risks, this is an interesting forum with lots of good information:

    http://catless.ncl.ac.uk/risks

    (Forum On Risks To The Public In Computers And Related Systems

    ACM Committee on Computers and Public Policy, Peter G. Neumann, moderator)

  • NeilFarbstein - Jan 13, 2009
    • Rank: not rated yet
    you can run but you cant hide
  • superhuman - Jan 14, 2009
    • Rank: not rated yet
    The proper solution is to develop an open source standardized operating system and programming software designed with security in mind from the start. Computers are fast enough today to dedicate quite a lot of computing resources to security so a modular simple system with transparent logic capable of being validated with mathematical proofs and tested by everyone is the way to go.

    Once governments realize national security depends on software they will hopefully realize it's the way to go and will fund academic efforts aimed at reaching that goal. Don't count on software industry it's not in their interest to produce safe software that lasts.

    Current computer technology is mature enough and there is no longer any need for operating system and software to change every few years despite what micro$oft and others who profit on this wants you to think. Current OSes provide everything applications need expect for one thing - security, frequent changes of software is one of the primary reason for poor security.

    A properly written OS for business and government applications can easily last decades with only hardware, drivers and applications need to be updated if needed.

    The world desperately needs an open, standardized, transparent and safe software platform and it will be developed sooner or later, its inevitable, but the likes of Microsoft will do everything to postpone it.

January 13, 2009 all stories

Comments: 5

4.4 /5 (5 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories




  • hide
  • Relevant PhysicsForums posts

  • Problems with WRF and Fortran
    created 17 hours ago
  • Solidworks
    created 17 hours ago
  • Controling/Reading a CDROM drive.
    created Nov 10, 2009
  • casio calculator that's similar to TI-89
    created Nov 08, 2009
  • More from Physics Forums - Computing & Technology

Other News

Doctors embrace social networking

Technology / Hi Tech

created 1hour ago | popularity not rated yet | comments 0

In the waiting room, the patient's family members circled a Blackberry. About every 15 minutes, Dr. Carlos Wolf of Miami Plastic Surgery gave them a few keystrokes of information about how the patient was doing.


Retailers use social media to advertise deals

Technology / Internet

created 28 minutes ago | popularity not rated yet | comments 0

(AP) -- You may want to check Facebook and Twitter before heading to the mall the day after Thanksgiving.


Intel settles AMD claims but isn't off the hook (AP)

Intel settles AMD claims but isn't off the hook

Technology / Business

created 6 hours ago | popularity 5 / 5 (4) | comments 2

(AP) -- Intel Corp. is paying Silicon Valley rival Advanced Micro Devices Inc. $1.25 billion to squash a legal battle over Intel's sales tactics, a rift that led to antitrust charges against Intel in several ...


'Call of Duty' sells $310M in N Amer, UK in 24 hrs (AP)

'Call of Duty' sells $310M in N Amer, UK in 24 hrs

Technology / Software

created 6 hours ago | popularity 5 / 5 (2) | comments 0

(AP) -- First-day sales of Activision Blizzard Inc.'s "Call of Duty: Modern Warfare 2" broke records, raking in an estimated $310 million in North America and the United Kingdom alone.


GE to sell security unit to United Technologies

Technology / Business

created 5 hours ago | popularity not rated yet | comments 0

US conglomerate General Electric on Thursday announced it would sell its security unit to United Technologies Corp. for 1.82 billion dollars.