Code defends against 'stealthy' computer worms

Feb 01, 2010

Self-propagating worms are malicious computer programs, which, after being released, can spread throughout networks without human control, stealing or erasing hard drive data, interfering with pre-installed programs and slowing, even crashing, home and work computers. Now a new code, or algorithm, created by Penn State researchers targets the "stealthiest" of these worms, containing them before an outbreak can occur.

"In 2001 the 'Code Red' worms caused $2 billion dollars worth of damage worldwide," said Yoon-Ho Choi, a postdoctoral fellow in information sciences and technology, Penn State. "Our can prevent a worm's propagation early in its propagation stage."

Choi and his colleagues' algorithm defends against the spread of local scanning worms that search for hosts in "local" spaces within networks or sub-networks. This strategy allows them access to hosts that are clustered, which means once they infect one host, the rest can be can be infected quickly. There are many types of scanning worms, but Choi calls these worms the stealthiest because they are the most efficient and can evade even the best worm defenses.

A worm outbreak can begin with the infection of a single computer. After infection, a worm begins to probe a set of random, local or enterprise IP addresses, searching for more vulnerable hosts. When one is found the worm sends out a probe, or packet, to infect it.

"A local scanning worm can purposely scan a local or enterprise network only," said Choi. "As the size of the susceptible population increases, the worm's virulence increases."

The researchers' algorithm works by estimating the size of the susceptible host population. It then monitors the occurrence of infections within it and sets a threshold value just equal to or below the average number of scans necessary to infect a host by an infected host.

If the scanning worm's number of scans carrying a specific destination port number exceeds the threshold, the algorithm quarantines the worm. The algorithm then breaks down the network into many small networks, or cells, which in some cases might be only one computer. A worm can spread within the cells, but not between the cells. This way the algorithm can isolate an infected host or small cluster of infected hosts housing the worm.

"By applying the containment thresholds from our proposed algorithm, outbreaks can be blocked early," said Choi.

To test the effectiveness of their algorithm the researchers ran a series of computer simulations and emulations using different scanning strategies of local scanning worms. Results showed that their algorithm was an efficient estimator of worm virulence and could determine the size of the susceptible host population after only a few infections.

"Our evaluation showed that the algorithm is reliable in the very early propagation stage and is better than the state-of-the-art defense," said Choi.

Choi, working with Lunquan Li, assistant professor, Institute of Microelectronics, Chinese Academy of Sciences, Beijing, and his Penn State colleagues, Peng Liu, associate professor, and technology, and George Kesidis, professor, electrical engineering and computer science and engineering, published their work in the February issue of Computers and Security.

According to Choi, local scanning worms are constantly evolving. They are becoming more complicated and increasingly efficient. As a result, worm outbreaks pose a real threat to networked systems. Because many networked home and office computers are susceptible to local scanning this algorithm may be an effective defense against damaging worm outbreaks.

Explore further: Fujitsu develops technology to quickly detect latent malware activity in internal networks

Related Stories

A new way to protect computer networks from Internet worms

Jun 04, 2008

Scientists may have found a new way to combat the most dangerous form of computer virus. The method automatically detects within minutes when an Internet worm has infected a computer network. Network administrators can then ...

Low-cost strategy developed for curbing computer worms

Jan 13, 2009

Thanks to an ingenious new strategy devised by researchers at University of California, Davis and Intel Corporation, computer network administrators might soon be able to mount effective, low-cost defenses against self-propagating ...

The phony goat gets the worm

Mar 28, 2006

IBM researchers have designed a new way to detect and thwart attacks on computer networks. Code named "Billy Goat," the intrusion detection tool provides both early detection of worm attacks and fewer false alarms than other ...

Help! How to avoid fast-moving computer worm

Jan 28, 2009

Since early January, a worm that has been referred to by several names, including "Downadup," "Kido" and "Conficker," has been infecting millions of computers around the world. The worm exploits a previously discovered vulnerability ...

Recommended for you

Microsoft CEO is driving data-culture mindset

7 hours ago

(Phys.org) —Microsoft's future strategy: is all about leveraging data, from different sources, coming together using one cohesive Microsoft architecture. Microsoft CEO Satya Nadella on Tuesday, both in ...

Enabling dynamic prioritization of data in the cloud

Apr 14, 2014

IBM inventors have patented a cloud computing invention that can improve quality of service for clients by enabling data to be dynamically modified, prioritized and shared across a cloud environment.

User comments : 0

More news stories

Microsoft CEO is driving data-culture mindset

(Phys.org) —Microsoft's future strategy: is all about leveraging data, from different sources, coming together using one cohesive Microsoft architecture. Microsoft CEO Satya Nadella on Tuesday, both in ...

Floating nuclear plants could ride out tsunamis

When an earthquake and tsunami struck the Fukushima Daiichi nuclear plant complex in 2011, neither the quake nor the inundation caused the ensuing contamination. Rather, it was the aftereffects—specifically, ...

Patent talk: Google sharpens contact lens vision

(Phys.org) —A report from Patent Bolt brings us one step closer to what Google may have in mind in developing smart contact lenses. According to the discussion Google is interested in the concept of contact ...

Quantenna promises 10-gigabit Wi-Fi by next year

(Phys.org) —Quantenna Communications has announced that it has plans for releasing a chipset that will be capable of delivering 10Gbps WiFi to/from routers, bridges and computers by sometime next year. ...