Software That's Resilient Against Hacker Attack

October 29, 2009 by John Messina weblog
Software That's Resilient Against Hacker Attack

Image Credit: Technology Review

(PhysOrg.com) -- A team of researchers headed by Martin Rinard, a professor of computer science at MIT, have developed new software that automatically patches errors in deployed software in a matter of minutes.

The is called ClearView and is designed to apply patches whenever it detects that something has gone wrong with the program. ClearView operates by monitoring a program's normal behavior and establishing a set of rules.

ClearView looks for certain types of errors that are mostly caused by an attacker introducing into the operating program. When ClearView detects a software intrusion, it identifies the rule that has been compromised and generates a set of repair patches designed to force the software to follow the compromised rules. ClearView then studies all possibilities to determine which selected rule is the most successful patch.

ClearView can be very successful when it is installed on multiple computers running the same software. By ClearView analyzing the malicious code and applying the most effective rule on one machine, it can then apply the patch to all other machines. ClearView applies the patch to the binary code, bypassing the source code which enables it to fix programs without human intervention.

ClearView was tested on a group of computers running Firefox and an independent team to launch an attack on the . The attack team used 10 different attacks to inject malicious code into Firefox. ClearView was successful in all 10 attacks by blocking the malicious code and shutting down the program before its intended attack took effect.

ClearView created patches that corrected the errors introduced by the malicious code and discarded any corrections that had a negative effect. ClearView, on average, came up with a working patch within five minutes of its first attack.

In a TR interview, Rinard stated: "What this research is leading us to believe is that software isn't in itself inherently fragile and brittle because of errors. It's fragile and brittle because people are afraid to let the software continue if they think there's something wrong with it." Some software engineering approaches, such as "failure-oblivious computing" or "acceptable computing," share this philosophy.

More information: Automatically Patching Errors in Deployed Software, 22nd ACM Symposium on Operating Systems Principles. [Paper] [Slides]

This video is not supported by your browser at this time.

Automatically Patching Errors in Deployed Software, Conference Audio.


Via: Technology Review

© 2009 PhysOrg.com

4.1 /5 (7 votes)  

Filter


Move the slider to adjust rank threshold, so that you can hide some of the comments.


Display comments: newest first

vantomic
Oct 29, 2009

Rank: 1 / 5 (1)
I'll just get started with the obvious comment...what makes the rules so safe? attack the rules.

This reminds me of the joke. If the blackbox in a plane is indestructible why not make the whole plane out of it.
Foolish1
Oct 29, 2009

Rank: not rated yet
"It's fragile and brittle because people are afraid to let the software continue if they think there's something wrong with it"

Afraid? Terrified is a better choice of words.
nkalanaga
Oct 29, 2009

Rank: not rated yet
So how long will it be before someone hacks ClearView and uses it to install malicious "patches"? I'd rather my software died if it was compromised.
jgelt
Oct 29, 2009

Rank: not rated yet
Bootable USB stick. Backup USB sticks.

No sharing a computer, nothing on the computer when the stick is pulled. Nothing for malware to eat.
Corruption or mere suspicion? Restore virgin image in 15 minutes.

Invulnerable except to outright mugging.
Let's get rid of the bloatware and get back to the one-use OS now, please!
malapropism
Oct 29, 2009

Rank: not rated yet
So how long will it be before someone hacks ClearView and uses it to install malicious "patches"? I'd rather my software died if it was compromised.

But it looks like they thought of this, the paper (section 4.1) states: "Infrastructure Attacks: Determine if attackers can subvert the ClearView patch generation and distribution mechanism to send out malicious patches. This paper omits the detailed results of this qualitative evaluation, but in summary the standard security measures already in place in the Determina commercial product (encryption, authentication, etc.) were judged to provide an acceptable level of protection against this class of attacks."

They also say that they weren't trying to fix everything in one go - and using this is still a lot better than being hacked.
malapropism
Oct 29, 2009

Rank: not rated yet
Bootable USB stick. Backup USB sticks.

No sharing a computer, nothing on the computer when the stick is pulled. Nothing for malware to eat.
Corruption or mere suspicion? Restore virgin image in 15 minutes.

Invulnerable except to outright mugging.
Let's get rid of the bloatware and get back to the one-use OS now, please!

But not a very usable suggestion for a high-availability, clustered-server & SAN situation.
finitesolutions
Oct 30, 2009

Rank: 5 / 5 (1)
Actually hackers, or anybody, are welcomed to hack my bank accounts :)
It can not be worse than it is now.
Rank 4.1 /5 (7 votes)
Related Stories
Relevant PhysicsForums posts

More news stories

Soraa LED light may dim 50-watt halogen rivals

(PhysOrg.com) -- Soraa, a Fremont, California company founded in 2008, this week launched its first product, a light that uses LEDS (light emitting diodes). The "Soraa LED MR16 lamp" is the "perfect" replacement ...

Technology / Semiconductors

created 21 hours ago | popularity 4.3 / 5 (17) | comments 18 | with audio podcast report

Samsung can continue selling Galaxy tabs in Germany: court

South Korea's Samsung Electronics can continue to sell its Galaxy Tab 10.1N tablet computer in Germany, a German court ruled Thursday, rejecting a bid by arch-rival Apple to have them banned.

Technology / Business

created 19 hours ago | popularity 3.7 / 5 (3) | comments 3

Google launches Chrome browser for Android smartphones

With more and more people connecting to the Internet through a phone or a tablet instead of a PC, Google Inc. is bringing its fast-growing browser, Chrome, to the newest Android-powered mobile devices.

Technology / Software

created 17 hours ago | popularity 5 / 5 (4) | comments 0

Digital photos could put kids at risk

A study published in the International Journal of Electronic Security and Digital Forensics this month suggests that parents and carers could be putting children at risk if they upload digital photos that are automatically "geota ...

Technology / Internet

created 15 hours ago | popularity 5 / 5 (1) | comments 3

First Google hire leaving for online academy

The first person hired by Google's founders is leaving the Internet giant to devote himself to an innovative online education website called Khan Academy.

Technology / Internet

created 9 hours ago | popularity 5 / 5 (1) | comments 0


'Dark plasmons' transmit energy

Microscopic channels of gold nanoparticles have the ability to transmit electromagnetic energy that starts as light and propagates via "dark plasmons," according to researchers at Rice University.

FDA-approved drug rapidly clears amyloid from the brain, reverses Alzheimer's symptoms in mice

Neuroscientists at Case Western Reserve University School of Medicine have made a dramatic breakthrough in their efforts to find a cure for Alzheimer's disease. The researchers' findings, published in the journal Science, show t ...

Hydrogen from acidic water: Researchers develop potential low cost alternative to platinum for splitting water

A technique for creating a new molecule that structurally and chemically replicates the active part of the widely used industrial catalyst molybdenite has been developed by researchers with the Lawrence Berkeley ...

Ultraviolet protection molecule in plants yields its secrets

Lying around in the sun all day is hazardous not just for humans but also for plants, which have no means of escape. Ultraviolet (UV) radiation from the sun can damage proteins and DNA inside cells, leading ...

Anyone can learn to be more inventive, cognitive researcher says

There will always be a wild and unpredictable quality to creativity and invention, says Anthony McCaffrey, a cognitive psychology researcher at the University of Massachusetts Amherst, because an "Aha moment" is rare and ...

Flexible paper robots

(PhysOrg.com) -- These inexpensive robots can stretch, bend and twist under control, and lift objects up to 120 times their own weight. Being soft, they can apply gentle and even pressure, and adapt to varied ...