Forum for Science, Industry and Business

Sponsored by:     3M 
Search our Site:

 

Detecting unknown computer viruses

03.03.2006


PhD Student Tom Lysemose is the world’s first to have developed software that is able to effectively detect attacks by an unknown computer virus.



Possible customers include the large anti-virus companies. A problem with today’s anti-virus software is that they can only protect from known viruses. Unknown viruses are not stopped.

A great number of viruses exist. Some of these viruses need active handling by the user in order to infect a computer, such as when someone is tricked into opening an infected e-mail attachment. Other viruses are more crafty. Without a user being aware that he has made a single mistake, the virus can attack software and take control of the computer, resulting in, for example, all documents being deleted.


The explanation for how these unpleasant events are possible is that very many computer programmes contain programming errors. The most common is called Buffer Overflow.

-Embarrassingly enough, this programming error is also made by those who write anti-virus software, such as Symantec, explains Tom Lysemose. But he points out that such programming mistakes are common for all programmers who write in C, one of the world’s most common programming languages.

-The web browser Internet Explorer is one such example. Programming errors can also be found in the IP-telephony system Skype and database software from Microsoft called SQL Server. In 2003 things went terribly wrong. That’s when the virus Slammer automatically took control over a great deal of database servers. These are super-fast machines, so the virus could spread extremely fast. Although the virus was not especially destructive, it spread so widely that it slowed down the entire Internet. Systems over the entire world were affected, and even some banks’ automated teller machines were shut down,” says Tom Lysemose.

To understand Lysemose’s software, one needs a quick introduction to how Buffer Overflow is a unfortunate programming error.

Within a computer’s internal memory are a series of containers called buffers. When running a programme that communicates over the Internet, such as a web browser, the technology functions so that the contents in the buffers of the network server are transferred to the buffers in the computer.

One example is when a password is entered on a web page. The password is stored in its own buffer on the local computer. Consider, for example, that this buffer could only have enough space for eight characters. If the programmer forgets to check the buffer size, the buffer runs over if someone enters more than eight characters.

Unfortunately, not all programmers are aware of this. If those who write software have not included a routine that checks if enough room exists in the buffer, the areas that are physically next to the buffer will be overwritten. This is extremely regrettable. The computer gives no warning and continues to run as if nothing has happened.

Unfortunately, the overwritten areas can hold important instructions for the software that’s running, such as "Please provide an overview of all my documents".

This is exactly the type of weakness that virus creators exploit. They can make a virus that sends a larger data packet than the computer’s buffer capacity. If the hacker discovers exactly where the most important instructions are located, the virus can be programmed so that it overwrites these instructions with completely different commands, such as "Delete all of my documents now". And then the user is out of luck.

This is exactly when Tom Lysemose’s innovation comes in. His programme, which is named ProMon, cannot prevent an unknown virus from attacking a buffer and the areas around it, but ProMon monitors programmes to ensure that they do not do things that they are not programmed to do. This means that ProMon will stop a programme if the programme suddenly begins to do another thing.

This solution is a new way of thinking about virus prevention. All modern software is built up of modules. Modules communicate with each over and with the operating system on the computer. Between the modules are well defined transaction limits.

-The point is that ProMon works within a programme, such as the web browser Internet Explorer, in order to monitor the interaction between the programme’s modules. As long as the programme performs legitimate transactions between its modules, ProMon does nothing. But if an illegal transaction occurs, ProMon decides a virus has attacked and promptly stops the programme,” explains Tom Lysemose.

He stresses that his anti-virus software can monitor any programme. His programme is not alone on the market, but all the tests that Tom Lysemose has performed have shown that his programme is 30 times faster than his competition from Massachusetts Institute of Technology.

The product will be introduced to the large anti-virus companies in March

Thomas Evensen | alfa
Further information:
http://www.ifi.uio.no/english/
http://www.forskningsradet.no

More articles from Information Technology:

nachricht New software speeds origami structure designs
12.10.2017 | Georgia Institute of Technology

nachricht Seeing the next dimension of computer chips
11.10.2017 | Osaka University

All articles from Information Technology >>>

The most recent press releases about innovation >>>

Die letzten 5 Focus-News des innovations-reports im Überblick:

Im Focus: Neutron star merger directly observed for the first time

University of Maryland researchers contribute to historic detection of gravitational waves and light created by event

On August 17, 2017, at 12:41:04 UTC, scientists made the first direct observation of a merger between two neutron stars--the dense, collapsed cores that remain...

Im Focus: Breaking: the first light from two neutron stars merging

Seven new papers describe the first-ever detection of light from a gravitational wave source. The event, caused by two neutron stars colliding and merging together, was dubbed GW170817 because it sent ripples through space-time that reached Earth on 2017 August 17. Around the world, hundreds of excited astronomers mobilized quickly and were able to observe the event using numerous telescopes, providing a wealth of new data.

Previous detections of gravitational waves have all involved the merger of two black holes, a feat that won the 2017 Nobel Prize in Physics earlier this month....

Im Focus: Smart sensors for efficient processes

Material defects in end products can quickly result in failures in many areas of industry, and have a massive impact on the safe use of their products. This is why, in the field of quality assurance, intelligent, nondestructive sensor systems play a key role. They allow testing components and parts in a rapid and cost-efficient manner without destroying the actual product or changing its surface. Experts from the Fraunhofer IZFP in Saarbrücken will be presenting two exhibits at the Blechexpo in Stuttgart from 7–10 November 2017 that allow fast, reliable, and automated characterization of materials and detection of defects (Hall 5, Booth 5306).

When quality testing uses time-consuming destructive test methods, it can result in enormous costs due to damaging or destroying the products. And given that...

Im Focus: Cold molecules on collision course

Using a new cooling technique MPQ scientists succeed at observing collisions in a dense beam of cold and slow dipolar molecules.

How do chemical reactions proceed at extremely low temperatures? The answer requires the investigation of molecular samples that are cold, dense, and slow at...

Im Focus: Shrinking the proton again!

Scientists from the Max Planck Institute of Quantum Optics, using high precision laser spectroscopy of atomic hydrogen, confirm the surprisingly small value of the proton radius determined from muonic hydrogen.

It was one of the breakthroughs of the year 2010: Laser spectroscopy of muonic hydrogen resulted in a value for the proton charge radius that was significantly...

All Focus news of the innovation-report >>>

Anzeige

Anzeige

Event News

ASEAN Member States discuss the future role of renewable energy

17.10.2017 | Event News

World Health Summit 2017: International experts set the course for the future of Global Health

10.10.2017 | Event News

Climate Engineering Conference 2017 Opens in Berlin

10.10.2017 | Event News

 
Latest News

Electrode materials from the microwave oven

19.10.2017 | Materials Sciences

New material for digital memories of the future

19.10.2017 | Materials Sciences

Physics boosts artificial intelligence methods

19.10.2017 | Physics and Astronomy

VideoLinks
B2B-VideoLinks
More VideoLinks >>>