All the latest UK technology news, reviews and analysis

Software developed to stop zero-day attacks

by Iain Thomson

15 Jan 2009

Be the first to comment

  • Tweet this
Computer virus
Conventional anti-virus software is ineffective against new malware

Researchers at Intel and the Computer Security Laboratory at the University of California, Davis have devised a new way to counter zero-day attacks.

Conventional anti-virus software can detect known viruses, but is ineffective against new malware, or so-called zero-day attacks.

The new technique involves logging suspicious activity in individual computers on a network, and matching it against other connected systems.

"The question is whether I should shut down the network and risk losing business for a couple of hours for what could be a false alarm, or keep it running and risk getting infected," said Senthil Cheetancheri, a UC Davis graduate student who led efforts to develop the strategy.

"One suspicious activity in a network with 100 computers can't tell you much. But when you see half a dozen activities and counting, you know that something's happening."

The second part of the system is an algorithm that rates the cost of shutting down a computer against the cost of letting malware run loose on the network. The software can either allow the IT manager to make a decision, or be configured to take action automatically.

The system can also evaluate the importance of individual machines. For example, the cost of taking down a network server is much higher than for a seldom used computer, so the algorithm would shut down the latter, less valuable, system first.

The team has developed an experimental detection engine and is now trying to make sure that it runs without hogging server time and bandwidth and interfering with other applications.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

30%

1%

12%

57%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Riso

Colour printing: why the bill keeps outstripping the budget

The wrong printers, for the wrong tasks on the wrong contracts

Qlikview

Magic quadrant for business intelligence platforms

Who leads the BI pack and who should we be watching out for?

Sales and Service Administrator

Our client, a specialist in their industry, is working...

Project Manager

JOB DESCRIPTION Job Title: Project Manager...

Java Entwickler

Für unseren Kunden, ein spannendes IT Unternehmen in...

Application Support Analyst with Oil & Gas Trading & Operations

Application Support Analyst with Oil & Gas Trading...

To send to more than one email address, simply separate each address with a comma.