App Store Logo

Still Life

Snow blankets University Park

Snow blankets University Park

February 6, 2010

Many are registered during York's bone marrow drive

Many are registered during York's bone marrow drive

February 3, 2010

Haitian earthquake victims receive help from Hershey medical staff

Haitian earthquake victims receive help from Hershey medical staff

February 3, 2010

Comedian Dunham entertains audience

Comedian Dunham entertains audience

January 29, 2010

Pink Zone game benefits breast cancer research

Pink Zone game benefits breast cancer research

January 24, 2010

Gala raises money for Four Diamonds

Gala raises money for Four Diamonds

January 22, 2010

MLK events culminate in evening celebration

MLK events culminate in evening celebration

January 20, 2010

Penn State, local students collaborate to celebrate MLK

Penn State, local students collaborate to celebrate MLK

January 17, 2010

Heard on Campus: Tony Leach, Essence, at the Forum

Heard on Campus: Tony Leach, Essence, at the Forum

January 15, 2010

The 94th annual PA Farm Show is under way

The 94th annual PA Farm Show is under way

January 10, 2010

Lady Lions hold Special Olympics clinic

Lady Lions hold Special Olympics clinic

January 9, 2010

A look back at Bowl Week

A look back at Bowl Week

January 4, 2010

Featured Video

Penn State 2010

Penn State 2010

2009 State of the University Address

2009 State of the University Address

Managing the Roost: Penn State's Crow Relocation Project

Managing the Roost: Penn State's Crow Relocation Project

Penn State's creamery, from the cow to the cone

Penn State's creamery, from the cow to the cone

Penn State introduces Tony Leach as laureate for 2009-2010

Penn State introduces Tony Leach as laureate for 2009-2010

Beaver Stadium Behind the Scenes and On the Air

Beaver Stadium Behind the Scenes and On the Air

Natural Fusion, Penn State's Solar Decathlon Team 2009

Natural Fusion, Penn State's Solar Decathlon Team 2009

'Expert Opinion' show examines sports gambling

'Expert Opinion' show examines sports gambling

'Expert Opinion' looks at men's college basketball issues

'Expert Opinion' looks at men's college basketball issues

'Expert Opinion' tackles college football rankings

'Expert Opinion' tackles college football rankings

Researchers invent system to control worms attacking computer networks

Thursday, February 8, 2007

A new anti-worm technology developed by Penn State researchers can not only identify and contain worms milliseconds after a cyber attack, but can also release the information if the quarantine turns out to be unwarranted.

Because many current security technologies focus on signature or pattern identification for blocking worms, they cannot respond to attacks fast enough, allowing worms to exploit network vulnerabilities, according to the researchers. As a result, several minutes can elapse between when a signature-based system first recognizes that a packet or datagram is a worm and when it creates a new signature to block further spread.

But when signature-based systems shorten the signature-generation time, they often miss those worms capable of mutating automatically.

The researchers' new technology -- Proactive Worm Containment (PWC) -- doesn't rely on signature generation. Instead it targets a packet's rate or frequency of connections and the diversity of connections to other networks -- which allows PWC to react far more quickly than other technologies.

"A lot of worms need to spread quickly in order to do the most damage, so our software looks for anomalies in the rate and diversity of connection requests going out of hosts," said Peng Liu, associate professor of information sciences and technology at Penn State and lead researcher on the PWC system.

When a host with a high rate is identified, then PWC contains that host so that no packets with the worm code can be sent out. Liu estimates that only a few dozen infected packets may be sent out to other networks before PWC can quarantine the attack. In contrast, the Slammer worm, which attacked Microsoft SQL Server, on average sent out 4,000 infected packets every second, Liu said.

Because high connection-rate transmissions do not always indicate worms, PWC includes two novel techniques that can verify that suspect hosts are clean or not infected. These techniques use vulnerability-window and relaxation analyses to overcome the denial-of-service effect that could be caused by false positives, he added.

"PWC can quickly unblock any mistakenly blocked hosts," Liu said.

The PWC software can be integrated seamlessly with existing signature-based worm filtering systems. The researchers are currently beta-testing PWC.

Because PWC targets connection rates to identify worms, it may miss slow-spreading worms. But current technologies already can pick those up, Liu said.

Worms pose a serious threat to networks, compromising network performance and even leading to denial of services. SQL Slammer, for instance, not only slowed Internet traffic but also disrupted thousands of A.T.M. machines. Additionally, worms can open the door for attackers to machines within infected networks.

A provisional patent has been filed by Penn State on the software, "Proactive Worm Containment (PWC) for Enterprise Networks," invented by Liu; Yoon-Chan Jhi, a doctoral student in the Department of Computer Science and Engineering; and Lunquan Li, an IST doctoral student.

Contact