From the Lab

From The Lab: Information Technology

  • May 2005
  • By Monya Baker (edit)

From the world of information technology, here are the latest publications, experiments, and breakthroughs, and what they mean.

   

Kill the Bots!
Software thwarts malicious hackers

Context: The malicious computer programs known as "worms" infect more than 30,000 new computers every day. Unbeknownst to their owners, the compromised machines follow orders to send spam, say, or to access particular websites. If enough of these so-called zombie machines simultaneously contact a particular Web server, they can knock it out of commission. Professional hackers have used the threat of such "distributed denial-of-service attacks" to extort money from businesses. Last year, one company's business manager was indicted for paying hackers to use zombies to take down competitors' websites. The zombies dodge a Web server's defenses by disguising themselves as legitimate users and then block access to the server by overloading not only its network bandwidth, but also its CPU, memory, disk space, and database resources. Now, led by Dina Katabi, researchers from MIT, Princeton University, and Akamai Technologies have developed Kill-Bots, a clever, simple, and cheap means of distinguishing friend from foe. Unlike other products, it allocates a server's system resources only after a user is confirmed as legitimate.

Methods and Results: Kill-Bots, a software modification to a server's operating system, kicks in whenever a website is in danger of being overwhelmed by traffic. The software asks requesters to solve a simple graphical puzzle before it grants access to server resources like buffer space. Humans can solve these puzzles easily; zombies cannot do so at all. Addresses that repeatedly request site access without solving the puzzle are blacklisted automatically. When the load on the Web server decreases, it stops issuing puzzles and accepts requests from nonblacklisted addresses, so even real users who did not solve the puzzle can gain access.
In experiments, a Kill-Bots-protected Web server successfully endured five times as many hits as an unprotected Web server. Not only did the Web server stay online, but protected websites also maintained speedy response times, even during the height of the attack.

 

To read the entire article you must log in:

Most of our content — all daily news, blogs, and videos — is free. Magazine stories are paid. To read this story, you must have a subscription or you must use a reading credit. Registration to Technology Review is free and entitles registrants to three free reading credits.

Username or REGISTER
Password  
   
 
Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Sponsored Content

Technologies from National Instruments

Adding Data Logging
Log measured data to a file and open it in Microsoft Excel

> Click here for more National Instruments Videos <
Whitepaper

Temperature Measurements with Thermocouples: How-To Guide

This document is part of the “How-To Guide for Most Common Measurements” centralized resource portal. This tutorial provides a detailed guide for measurement and device considerations to take temperature measurements using thermocouples. Get an introduction to thermocouples, which are inexpensive sensing devices widely used with PC-based data acquisition systems. Also review some specific thermocouple examples and learn how thermocouples work and ways to integrate them into a data acquisition measurement system.

View full PDF > Listen to story >
Find us on Youtube

Videos

Meet 2011 TR35 Winner Jesse Robbins

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

ARM Holdings

Calxeda

Silver Spring Networks

Zynga

More

Advertisement

Facebook

Advertisement