Computer scientists set on winning the computer virus 'cold war'
May 24, 2007First came the virus. Then came the antivirus software. Ever since, virus programmers have been escalating their technology, trying to stay one step ahead of the computer security engineers and vice versa.
"Essentially, this is an arms race," says Somesh Jha, an associate professor of computer science at the University of Wisconsin-Madison. Jha and graduate student Mihai Christodorescu have taken the next step in that proliferation.
In collaboration with computer scientists at the University of California-Berkeley and Carnegie Mellon University, the two UW-Madison researchers have developed new software called the Static Analyzer for Executables (SAFE).
SAFE targets viruses, spyware and other malicious programs - called malware - based on their behavior. Commercial virus scanners, such as McAfee and Symantec, search programs for specific patterns, or signatures. They read through programs like a computer might search a document for a specific word. SAFE would not only pick up that one word, but would spot all of its synonyms as well.
SAFE examines the behavior of a program without running it. Then it compares the behavior with a list of suspicious behaviors, such as reading an address book and sending e-mails. The programs that perform suspicious behaviors are considered malware.
The traditional signature-based method leaves an opening for virus programmers to disguise the virus and render the commercial scanners useless. Each disguised variant has a unique signature that must be distributed. Right now, most virus scanners recommend downloading updates weekly, but more frequent updates may become necessary, he says.
"I don't think the approaches currently being used by commercial companies are going to be sustainable," Jha says.
SAFE requires updates only when viruses exhibit new behavior. It is proactive, rather than reactive.
"This is the next generation in malware detection," Jha adds.
Jha and Christodorescu began working on SAFE when they tested variations of four viruses on Norton and McAfee antivirus scanners and found that only the original variation of each virus was caught. SAFE caught all variations.
SAFE's advantages are not limited to convenience and sustainability. Programmers are beginning to write viruses that change every time they get sent to another computer. These transformations are written directly into the code, and can create infinite variations of the virus.
"[Attackers] are already becoming very sophisticated. They are using on-the-fly evasion techniques," Jha says. "As they use more sophisticated things to hide their malware, your detection has to become better and better."
Source: University of Wisconsin-Madison
-
A fresh perspective on internet security
Dec 21, 2011 |
not rated yet |
1
-
Genes ex silico: Computer-designed virus yields phenotype expression benefits
Aug 29, 2011 |
4.8 / 5 (6) |
0
-
Learning lessons from an HIV cure
Jun 17, 2011 |
5 / 5 (3) |
3
-
Hackers aim ruse at Apple computer users
May 26, 2011 |
4 / 5 (1) |
3
-
Scientist develops new and free way to send large files around the Web
May 18, 2011 |
3.6 / 5 (5) |
9
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (31) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (3) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
Of microchemistry and molecules: Electronic microfluidic device synthesizes biocompatible probes
Jan 26, 2012 |
5 / 5 (1) |
0
-
Synergistic relations between computer science and technology.
Feb 06, 2012
-
how do iphone gloves work?
Feb 05, 2012
-
iPhone battery over time
Jan 30, 2012
-
Best alternate Tablet to an iPad for writing math or physics equations?
Jan 26, 2012
-
Sending SMS to a website
Jan 20, 2012
-
Need help with my technical fest!
Jan 19, 2012
- More from Physics Forums - Computing & Technology
More news stories
Expat French get Internet vote for first time
French citizens will for the first time this year be able to vote in a parliamentary election over the Internet, an experiment that could be extended to other elections if successful.
1 hour ago |
not rated yet |
0
"Twisted Metal" gamers get shot at real gunplay
Fans of "Twisted Metal" will get to welcome a long-awaited sequel of the car-battle videogame with a real-world bang by blasting an ice cream truck to bits with a machine gun.
56 minutes ago |
not rated yet |
0
New error-correcting codes guarantee the fastest possible rate of data transmission
Error-correcting codes are one of the triumphs of the digital age. Theyre a way of encoding information so that it can be transmitted across a communication channel such as an optical fiber o ...
Technology / Computer Sciences
7 hours ago |
5 / 5 (3) |
4
|
Small modular reactor design could be a 'SUPERSTAR'
(PhysOrg.com) -- Though most of today's nuclear reactors are cooled by water, we've long known that there are alternatives; in fact, the world's first nuclear-powered electricity in 1951 came from a reactor ...
Technology / Energy & Green Tech
6 hours ago |
4.2 / 5 (10) |
14
|
Advanced power-grid model finds low-cost, low-carbon future in West
(PhysOrg.com) -- The least expensive way for the Western U.S. to reduce greenhouse gas emissions enough to help prevent the worst consequences of global warming is to replace coal with renewable and other ...
Technology / Energy & Green Tech
6 hours ago |
5 / 5 (2) |
6
|
Putting the squeeze on planets outside our solar system
(PhysOrg.com) -- Using high-powered lasers, scientists at Lawrence Livermore National Laboratory and collaborators discovered that molten magnesium silicate undergoes a phase change in the liquid state, abruptly ...
Employers feel no love for unscrupulous practice of 'service sweethearting'
A new study led by two Florida State University marketing professors finds that some frontline service employees who are rewarded for hikes in customer loyalty and satisfaction also may engage in "service ...
Human cognitive performance suffers following natural disasters, researchers find
Not surprisingly, victims of a natural disaster can experience stress and anxiety, but a new study indicates that it might also cause them to make more errors - some serious - in their daily lives. In their upcoming Human Fa ...
The power of estrogen -- male snakes attract other males
A new study has shown that boosting the estrogen levels of male garter snakes causes them to secrete the same pheromones that females use to attract suitors, and turned the males into just about the sexiest ...
Curry spice component may help slow prostate tumor growth
Curcumin, an active component of the Indian curry spice turmeric, may help slow down tumor growth in castration-resistant prostate cancer patients on androgen deprivation therapy (ADT), a study from researchers ...
Fool's gold may prove an unlikely alternative to overexploited catalytic materials
Catalytic materials, which lower the energy barriers for chemical reactions, are used in everything from the commercial production of chemicals to catalytic converters in car engines. However, with current catalytic materials ...