Science News

... from universities, journals, and other research organizations

Taking Cues From Mother Nature To Foil Cyber Attacks

Nov. 27, 2003 — ARLINGTON, Va. -- Taking their cues from Mother Nature and biodiversity, computer scientists at Carnegie Mellon University and the University of New Mexico are collaborating on a National Science Foundation (NSF)-supported project to study "cyber-diversity" for computer systems as a way to fend off malicious viruses, worms and other cyber attacks.


Share This:

In nature, diseases are most devastating when an infection-causing organism encounters a "monoculture," a vast swath of genetically similar individuals, each susceptible to the organism's method of attack. In the same vein, computer viruses and worms exploit the same flaw on every computer running the same software.

"We are looking at computers the way a physician would look at genetically related patients, each susceptible to the same disorder,'' said Mike Reiter, a professor of electrical and computer engineering and computer science at Carnegie Mellon and associate director of CyLab, a Carnegie Mellon initiative focused on advancing cybersecurity technology and education. "In a more diverse population, one member may fall victim to a pathogen or disorder, while another might not have the same vulnerability."

"Our project seeks to reduce computer vulnerability by automatically changing certain aspects of a computer's software," said Dawn Song, an assistant professor of electrical and computer engineering and computer science at Carnegie Mellon. "Adapting this idea in biology to computers may not make an individual computer more resilient to attack, but it aims to make the whole population of computers more resilient in aggregate."

The existence of the same flaw on many computers is routinely exploited by attackers via Internet worms such as Code Red, which infected over 350,000 systems in just 13 hours using a single vulnerability.

Earlier approaches toward diversity in software attempted to develop different versions of the same software by independent teams, the idea being that the versions would naturally evolve different sets of vulnerabilities. However, such a manual approach is economically expensive and takes a long time, the researchers said.

"We are investigating various new methods for automating the diversity process at different system levels," said Stephanie Forrest, professor of computer science at New Mexico. "Our automated approach has the potential to be more economical and could introduce more diversity into computer systems." Attackers would then have less information about individual computers and would have to approach each computer differently.

"This work, bridging technical disciplines and taking the economics of security solutions into account, represents the kind of innovative thinking that NSF's Cyber Trust program hopes to stimulate in the research community," said Carl Landwehr, NSF program director. The Carnegie Mellon and New Mexico collaboration is supported by a $750,000 award from NSF, the independent federal agency that supports fundamental research and education across all fields of science and engineering.

Share this story on Facebook, Twitter, and Google:

Other social bookmarking and sharing tools:

|

Story Source:

The above story is reprinted from materials provided by National Science Foundation.

Note: Materials may be edited for content and length. For further information, please contact the source cited above.


APA

MLA

Note: If no author is given, the source is cited instead.

Search ScienceDaily

Number of stories in archives: 137,376

Find with keyword(s):
 
Enter a keyword or phrase to search ScienceDaily's archives for related news topics,
the latest news stories, reference articles, science videos, images, and books.

Recommend ScienceDaily on Facebook, Twitter, and Google:

Other social bookmarking and sharing services:

|

 
  more breaking science news

Social Networks


Follow ScienceDaily on Facebook, Twitter,
and Google:

Recommend ScienceDaily on Facebook, Twitter, and Google +1:

Other social bookmarking and sharing tools:

|

Breaking News

... from NewsDaily.com

In Other News ...

Science Video News


Cell Phone Viruses

As cell phones, PDAs, and other wireless devices become more sophisticated, hackers are starting to spread viruses that can infect them. Software. ...  > full story

Strange Science News

 

Free Subscriptions

... from ScienceDaily

Get the latest science news with our free email newsletters, updated daily and weekly. Or view hourly updated newsfeeds in your RSS reader:

Feedback

... we want to hear from you!

Tell us what you think of ScienceDaily -- we welcome both positive and negative comments. Have any problems using the site? Questions?

Post this page to your favorite social bookmarking site:
Include this item in your blog or web site:
Cite this article in your essay, paper, or report:
Email this page's link to a friend or colleague: