You are here: silicon.com > Software > Security Strategy

Security Strategy

HP wants to throttle worms

The virtual kind, obviously

By CNET Networks

Published: 11 December 2002 14:54 GMT

By Patrick Gray

Researchers at Hewlett-Packard laboratories in Bristol have been working on a new technology designed to choke internet worms and viruses in an attempt to slow them down and control their spread.

Matt Williamson, the researcher spearheading the research, has released a paper on "virus throttling". It details the logic behind the new concept, and outlines some of the techniques that HP is currently researching and implementing.

The core logic of virus throttling hinges on the idea that a computer infected by a worm will often try to connect to as many different machines as possible within the shortest time-frame, whereas a computer under the control of a human will behave quite differently.

Human web browsing will result in a connection rate of less than two outgoing internet connection attempts per second. The Nimda and Code Red worms, on the other hand, would pump out up to 500 connection attempts per second.

No human interaction with a computer could cause such a high connection rate, so Williamson and his team are working out how to best choke these rapid-fire connection attempts, hence dramatically slowing down the spread of a given worm.

"Since a machine that is infected, but throttled, isn't spreading the virus any more, the overall speed of infection is reduced. Also, since there will be fewer machines actively spreading the virus, the load on network infrastructure - routers for instance - will be reduced," Williamson said.

Although tests have already been conducted, that the research is still at an early stage.

"We have a number of ideas and new approaches to take it further," he said.

Williamson and the rest of his team have actually tested the early stage system on live viruses. They have used worms such as Nimda in a controlled environment at the Bristol laboratories.

They have found that although the system won't completely stop worms and viruses from spreading, it slows the rate at which they spread down to a controllable level.

The research group say the next step is to create custom worms designed to perform for test operations, such as varying propagation speed. Jonathon Griffin, a member of Williamson's research team, says they are seeking to create a "test virus" that they can deploy in a controlled environment.

"It will be like a cross between a virtual wind tunnel and an electronic test track for us," he said.

Eventually the system may prove to be very effective at detecting and possibly acting on worm infections.

By Patrick Grayx writes for ZDNet Australia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Clive Longbottom Windows 7: Not perfect - but ready for prime time Microsoft's latest OS fixes most of Vista's ills - but still has challenges ahead

Stephen Kleynhans Mind the details with Windows 7 Just because it might work better than Vista, it doesn't mean you can be sloppy


  • Jobs
Data warehousing (DWH) / Business Intelligence (BI) Architect (Data Stage Informatica, Ab Initio, Cognos, Business Objects, Hyperion)

Data warehousing (DWH) / Business Intelligence (BI) Architect (Data Stage Informatica, Ab Initio, Cognos, Business Objects, Hyperion) Architect ...

Application Support Developer, Trading/Spread Betting - London

Application Support Developer, Trading/Spread Betting - London You will join a leading product support team with responsibility for any software ...

C++/JAVA Developer required for Financial Spread Betting Firm - 50-55K

A leading City based financial and sports spread betting firm are looking for a senior C++/Java Server side developer to join their leading IT group ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: