Researchers invent system to control and quarantine worms attacking computer networksFebruary 09, 2007A new anti-worm technology developed by Penn State researchers can not only identify and contain worms milliseconds after a cyber attack, but can also release the information if the quarantine turns out to be unwarranted. Because many current security technologies focus on signature or pattern identification for blocking worms, they cannot respond to attacks fast enough, allowing worms to exploit network vulnerabilities, according to the researchers. As a result, several minutes can elapse between when a signature-based system first recognizes that a packet or datagram is a worm and when it creates a new signature to block further spread. But when signature-based systems shorten the signature-generation time, they often miss those worms capable of mutating automatically. The researchers' new technology — Proactive Worm Containment (PWC) — doesn't rely on signature generation. Instead it targets a packet's rate or frequency of connections and the diversity of connections to other networks — which allows PWC to react far more quickly than other technologies. "A lot of worms need to spread quickly in order to do the most damage, so our software looks for anomalies in the rate and diversity of connection requests going out of hosts," said Peng Liu, associate professor of information sciences and technology at Penn State and lead researcher on the PWC system. When a host with a high rate is identified, then PWC contains that host so that no packets with the worm code can be sent out. Liu estimates that only a few dozen infected packets may be sent out to other networks before PWC can quarantine the attack. In contrast, the Slammer worm, which attacked Microsoft SQL Server, on average sent out 4,000 infected packets every second, Liu said. Because high connection rate transmissions do not always indicate worms, PWC includes two novel techniques that can verify that suspect hosts are clean or not infected. These techniques use vulnerability-window and relaxation analyses to overcome the denial-of-service effect that could be caused by false positives, he added. "PWC can quickly unblock any mistakenly blocked hosts," Liu said. The PWC software can be integrated seamlessly with existing signature-based worm filtering systems. The researchers are currently beta testing PWC. Because PWC targets connection rates to identify worms, it may miss slow-spreading worms. But current technologies already can pick those up, Liu said. Worms pose a serious threat to networks, compromising network performance and even leading to denial of services. SQL Slammer, for instance, not only slowed Internet traffic but also disrupted thousands of A.T.M. machines. Additionally, worms can open the door for attackers to machines within infected networks. A provisional patent has been filed by Penn State on the software, "Proactive Worm Containment (PWC) for Enterprise Networks," invented by Liu; Yoon-Chan Jhi, a doctoral student in the Department of Computer Science and Engineering; and Lunquan Li, an IST doctoral student. Penn State |
|||||||||||||||||||||
| Related Quarantine Current Events and Quarantine News Articles Medical ethics experts identify, address key issues in H1N1 pandemic The anticipated onset of a second wave of the H1N1 influenza pandemic could present a host of thorny medical ethics issues best considered well in advance, according to the University of Toronto Joint Centre for Bioethics, which today released nine papers for public discussion. Leicester research paves way for first use in Europe of an insect to fight invasive plant Researchers at the University of Leicester have paved the way for the first ever use in Europe of an insect (biocontrol) to combat an invasive plant species in Britain. Vaccinating children may be effective at helping control spread of influenza, experts say Targeting children may be an effective use of limited supplies of flu vaccine, according to research funded by the Wellcome Trust and the EU. Pandemic passenger screening Four major US national laboratories have worked together to develop a computer model to help airport authorities screen passengers for pandemic influenza. Spring fishing season arrives... and with it, amphibian diseases Waterdogs, they're called, these larvae of tiger salamanders used as live bait for freshwater fishing. Study calls for increased research in flu transmission to prepare for pandemic flu outbreak Researchers at Rhode Island Hospital have completed a study to better understand the impact of infection control measures during a possible flu pandemic. Study of ancient and modern plagues finds common features In 430 B.C., a new and deadly disease-its cause remains a mystery-swept into Athens. The walled Greek city-state was teeming with citizens, soldiers and refugees of the war then raging between Athens and Sparta. Masks, hand washing, prevent spread of flu-like symptoms by up to 50 percent Wearing masks and using alcohol-based hand sanitizers may prevent the spread of flu symptoms by as much as 50 percent, a landmark new study suggests. Pandemic flu models help determine food distribution and school closing strategies The 1918 flu pandemic killed more than 40 million people worldwide and affected persons of all age groups. While it is difficult to predict when the next influenza pandemic will occur or how severe it will be, researchers at the Georgia Institute of Technology have developed models to help organizations like the American Red Cross and Georgia Department of Education prepare emergency response plans. Captive breeding introduced infectious disease to Mallorcan amphibians A potentially deadly fungus that can kill frogs and toads was inadvertently introduced into Mallorca by a captive breeding programme that was reintroducing a rare species of toad into the wild, according to a new study published today in the journal Current Biology. More Quarantine Current Events and Quarantine News Articles |
|||||||||||||||||||||
|
|||||||||||||||||||||
|
|||||||||||||||||||||