Researchers put lid on can of worms
By Rene Millman,
Researchers have devised a way of tagging worms and containing them before they damage computer systems.
The research was carried out by Peng Liu, associate professor of information services and technology and director of the Cyber Security Lab at Penn State University.
The technology, dubbed Proactive Worm Containment (PWC), doesn't rely on signature databases but looks at a packet's rate or frequency of connections and the diversity of connections to other networks - which, the researcher said, allowed PWC to react far more quickly than other technologies.
"A lot of worms need to spread quickly in order to do the most damage, so our software looks for anomalies in the rate and diversity of connection requests going out of hosts," said Liu.
When a host infected with a worm is identified, the technology contains that host so that no packets with worm code can be sent out. Liu said that only a few dozen infected packets may be sent out to other networks before PWC can quarantine the attack. In contrast, the Slammer worm, which attacked Microsoft SQL Server, on average sent out 4,000 infected packets every second, Liu said.
He said that the technology also uses two other techniques to ensure that the host is uninfected. These techniques use vulnerability-window and relaxation analyses to overcome the denial-of-service effect that could be caused by false positive.
"PWC can quickly unblock any mistakenly blocked hosts," Liu said.
The researchers are currently beta-testing the software and said it could be easily integrated with existing signature-based worm filtering systems.
You may also like...
Sponsored Links
advertisement
You may also like...
Latest Security Analysis & Insight
What is your password worth?
Would you be tempted to sell off company passwords for a fee? If not, seems like you're in the minority, acccording to research.
- Macs under attack?
- Intel: security inside
- Are you spending too much on IT security?
- Does the government want to snoop on your data?
- Eurocrats versus the cyber criminals
- The truth about spam
- Google and privacy: What’s the problem?
- Q&A: Symantec’s CISO on the source code hack
- RSA: Back from the breach?
Latest Security Reviews
Check Point 2210 Appliance review
Rating: ![]()
advertisement
Most popular
- Apple iPad 3 vs iPad 2 head-to-head review
- Hutchison denies it will pull plug on Three UK
- EMC World 2012: Tucci declares Documentum is here to stay
- ICO: Fines for cookie law breakers
- EMC World 2012: EMC talks up cloud, security and big data
- Dell PowerEdge R820 review
- Sony Vaio T13 Ultrabook review: First look
- BlackBerry 7 OS certified to carry 'Restricted' UK government information
- Facebook floatation marred by Nasdaq glitch
- CIO: Career is over?
Latest News Videos in Security
IT PRO Podcast: Are UK data protection laws flawed?
We bring in two experts to talk about the problems with UK data protection law and the way it is managed.
Register for IT PRO
You'll get exclusive member benefits including free whitepapers, downloads, Webinars and weekly newsletters full of the latest IT PRO news, reviews, insight and expertise.





