A Network Worm Vaccine Architecture

  • Authors:
  • Stelios Sidiroglou;Angelos D. Keromytis

  • Affiliations:
  • -;-

  • Venue:
  • WETICE '03 Proceedings of the Twelfth International Workshop on Enabling Technologies: Infrastructure for Collaborative Enterprises
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

The ability of worms to spread at rates that effectivelypreclude human-directed reaction has elevated them to afirst-class security threat to distributed systems. We presentthe first reaction mechanism that seeks to automaticallypatch vulnerable software. Our system employs a collectionof sensors that detect and capture potential worm infectionvectors. We automatically test the effects of these vectorson appropriately-instrumented sandboxed instances of thetargeted application, trying to identify the exploited softwareweakness. Our heuristics allow us to automaticallygenerate patches that can protect against certain classes ofattack, and test the resistance of the patched applicationagainst the infection vector. We describe our system architecture,discuss the various components, and propose directionsfor future research.