Re: PhD Topic suggestions

Nick FitzGerald <nick-jd3pj1bJWvoG2Il/[email protected]> Sun, 21 Dec 2003 12:13:18 +1300
Newsgroups gmane.comp.security.virus.openantivirus.general
Organization Personal account
Message-ID <3FE58E5E.27783.19A2930F@localhost>
gnuorder <gnuorder-odAbcf0Mc9JJm/[email protected]> wrote:

> Yes, it is for this reason alone that this wont work.  In the case of
> microsoft patches for windows there are a lot of cases where a patch is
> worse than the exploit it is suppose to fix.  Windows patches dont limit
> themselves to patching just the hole they are advertised to fix as well.
>  And different versions of windows react differently to patches and/or
> the hole that the worm would infect.  Like the recent blaster worm was
> intended to infect XP but would cause Win2k to crash and reboot if I
> remember correctly. 
> 
> Now it would be nice to have a worm that could identify infected or
> vulnerable computers and inform the user with an email or something and
> maybe shutting down the computer but that would be exploited by spammers
> at the very least.

If you think you have something useful to contribute to this thread, 
please at least read and think about everything that has already been 
said.  In light of your comments above, it is clear that you ignored 
Frisk's advice for anyone wanting to talk about "good viruses" who has 
not read Vesselin Bontchev's seminal papers on topic to correct that 
shortcoming in their knowledge first.  Vesselin's papers are neither 
difficult to read nor comprehend, so your abject lack of understanding 
of what is clearly wrong with the above means you did not read them (or 
perhaps the clarity of your written expression belies your stupidity?).

> A better idea is to have nodes ask for updates from a central server
> because then the number and time of updates could be controlled as well
> as the source of updates.  

And then it has nothing to do with viral technology -- a conclusion 
much more elegantly drawn out in Vesselin's papers...

In short, the number of extra checks and balances and additional work 
required to make a self-replicating program safe (for any reasonable 
conception of "safe") is much greater than that involved in producing a 
non-replicating solution to the same problem set.  Further, those 
checks and balances so significantly constrain the extent of a viral 
solution's potential deployment, that the notion of a widely or 
universally deployable "solution" to some network security issue using 
such techniques quickly evaporates.  In short, you will always end up 
concluding that, despite opinions to the contrary from a few luminaries 
such as Fred Cohen, a "good virus" is always a bad idea (to paraphrase 
Vesselin).


-- 
Nick FitzGerald
Computer Virus Consulting Ltd.
Ph/FAX: +64 3 3529854



-------------------------------------------------------
This SF.net email is sponsored by: IBM Linux Tutorials.
Become an expert in LINUX or just sharpen your skills.  Sign up for IBM's
Free Linux Tutorials.  Learn everything from the bash shell to sys admin.
Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click