Re: PhD Topic suggestions

Kevin Wang <kjw-eXSdB+/[email protected]> Sat, 27 Dec 2003 09:36:53 -0800
Newsgroups gmane.comp.security.virus.openantivirus.general
Message-ID <[email protected]>
 From gnuorder
> Now it would be nice to have a worm that could identify infected or vulnerable computers and inform the user with an email or something and maybe shutting down the computer but that would be exploited by spammers at the very least.

One small note.

In the announcement that a diebold ATM machine (windows based) had been
infected with a worm, there was a small note that the machine had been
automatically isolated from the network.

This sounds like some sort of intrusion detection coupled with the
ability to shut down an ethernet port remotely.  Naturally the best way
to do this is to power off said machine, but turning off the ethernet
port at the switch would be just as good in terms of isolation.

Naturally, this requires some sort of centralized trust structure (who
does the network trust to make these sorts of changes), but fixing
the propogation medium may be the best way to isolate viruses.  It is
certainly a good way of isolating the damage.

At work, after a recent security intrusion (script kiddie broke into
a unix machine), they shut down all outgoing connections. No more
transparent NAT to the outside world.  web proxy was required, and to
ssh out you needed specific permissions (by ip address).  ftp is also not
working at the moment, though they keep talking about fixing it.
But this security policy also helps contain viruses and prevents outgoing
infections once it has started.

   - Kevin


-------------------------------------------------------
This SF.net email is sponsored by: IBM Linux Tutorials.
Become an expert in LINUX or just sharpen your skills.  Sign up for IBM's
Free Linux Tutorials.  Learn everything from the bash shell to sys admin.
Click now! http://ads.osdn.com/?ad_id=1278&alloc_id=3371&op=click