Design, Implementation and Test of an Email Virus Throttle

  • Authors:
  • Matthew M. Williamson

  • Affiliations:
  • -

  • Venue:
  • ACSAC '03 Proceedings of the 19th Annual Computer Security Applications Conference
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper presents an approach to preventing the damagecaused by viruses that travel via email. The approachprevents an infected machine spreading the virus further.This directly addresses the two ways that viruses causedamage: less machines spreading the virus will reduce thenumber of machines infected and reduce the traffic generatedby the virus.The approach relies on the observation that normalemailing behaviour is quite different from the behaviour of aspreading virus, with the virus sending messages at a muchhigher rate, to different addresses. To limit propagation arate-limiter or virus throttle is described that does not affectnormal traffic, but quickly slows and stops viral traffic. Thepaper includes an analysis of normal emailing behaviour,and details of the throttle design. In addition an implementationis described and tested with real viruses, showingthat the approach is practical.