Technology Review - Published By MIT
Log in to My.TechnologyReview.com | Register
Advertisement
[1] 2 Next »

Friday, March 21, 2008

Defending Laptops from Zombie Attacks

Intel is developing more-accurate ways to tell when a machine has been infected.

By Kate Greene

  • Audio »
    • Listen - Flash
    • Listen - MP3
    • Subscribe to podcast
    • What is this?
    • Powered by
smaller text tool iconmedium text tool iconlarger text tool icon
Credit: Technology Review

Researchers at Intel have developed laptop-based security software that adjusts to the way an individual uses the Internet, providing a more dynamic and personalized approach to detecting malicious activity. The software is aimed at corporations that pass out laptops and mobile devices to employees, since IT departments usually install the same one-size-fits-all security software on all their hardware. The homogenous security approach is quick and easy, says Nina Taft, a researcher at Intel Research Berkeley, but because standard software doesn't take into account different people's patterns of computer use, it can produce false positives and entirely miss some attacks.

"One reason security breaches are so rampant is that most of our machines look the same," says Taft. They have the same operating systems, same applications, same protocols, and same Internet traffic thresholds in the security settings, she says. "When a hacker breaks into one machine, he can break into all of them . . . We're trying to inject diversity into computers."

The type of security software deployed by most IT departments has a component that looks at Internet traffic coming in and out of a computer. When traffic exceeds a preset threshold, the software suggests that the computer is infected. It might, for instance, have been recruited as part of a "botnet," in which it is remotely controlled by a malicious computer that instructs it to communicate with other infected machines. (Much spam is sent from botnets.) Some people, however, habitually send out large amounts of information, which can trigger the security alarm, while others who stay well below the threshold can unknowingly harbor malicious activity.

As part of a project called Proteus, Intel researchers have developed several algorithms that can make more nuanced judgments. One algorithm uses standard statistical and machine-learning techniques to monitor a person's Internet use and create individualized traffic thresholds. A second algorithm gauges how people's Internet use changes throughout the day. Taft has found that people's habits are significantly different when they use company laptops to log in to networks other than the company's. "Ninety percent of people have quite a different behavior when they're at work than when they're at home," she says. Tying different traffic thresholds to different location profiles could improve security software's ability to detect compromised machines.

"I think the basic takeaway is, if you can be really precise in capturing user behavior, you can make the work of the attackers much harder," Taft says. In order to successfully infect a machine that maintained a number of different usage profiles, a malicious hacker would need to know when each applied and what its traffic threshold was. "You limit the range of possibilities they have for succeeding," Taft says.

[1] 2 Next »

Comments

Featured Content

Featured Articles
New blade servers help midsize businesses go big
For today’s midsize businesses, the move to blade servers is not a matter of if but when. New product portfolios are enabling midsize businesses to benefit from the cost savings, energy efficiency, and performance improvements of these compact yet powerful servers.

More »

White Papers
White papers from HP give insight into the latest technology entering the marketplace.

Blade Servers for the Masses
HP introduced the c3000 to address the needs of the smaller server deployments. Learn about the many advantages of implementing an HP blades server in your organization.

> Cost Analyses for Midsize and Enterprise Businesses
> Power, Cooling, and Space
> Maximizing Management Services

Rightsizing Blades for the Midmarket
Blades are expected to represent more than 25 percent of server shipments in 2011. Read about the capabilities of the HP c3000 and the challenges HP will face as it extends the BladeSystem into the midmarket.  

> Computing Needs vs. Available Resources
> Operating Expenses and Effort
> Flexible and Simplified Infrastructure

Current Issue

Technology Review July/August 2008
The Business of Social Networks
The future of the Web is social. But can social-networking sites ever make money?
•  Subscribe
Save 41%
•  Table of Contents
•  MIT News

Magazine Services

Career Resources

MIT Technology Insider

Stories and breaking news from inside MIT about the latest research, innovations, and startups--in a convenient monthly e-newsletter. Subscribe today
TECHNOLOGY RESOURCES
Advertisement
MIT Massachusetts Institute of Technology