Skip to main content
Back to USENIX
  • Conferences
  • Students
Sign in

USENIX Conference Policies

  • Event Code of Conduct
  • Conference Network Policy
  • Statement on Environmental Responsibility Policy

Implementing and Testing a Virus Throttle

In this paper we build on previous theoretical work and describe the implementation and testing of a virus throttle - a program, based on a new approach, that is able to substantially reduce the spread of and hence damage caused by mobile code such as worms and viruses. Our approach is different from current, signature-based anti-virus paradigms in that it identifies potential viruses based on their network behaviour and, instead of preventing such programs from entering a system, seeks to prevent them from leaving. The results presented here show that such an approach is effective in stopping the spread of a real worm, W32/Nimda-D, in under a second, as well as several different configurations of a test worm.

Jamie Twycross, Hewlett-Packard Labs, Bristol

Matthew M. Williamson, Hewlett-Packard Labs, Bristol

BibTeX
@inproceedings {270144,
author = {Jamie Twycross and Matthew M. Williamson},
title = {Implementing and Testing a Virus Throttle},
booktitle = {12th USENIX Security Symposium (USENIX Security 03)},
year = {2003},
address = {Washington, D.C.},
url = {https://www.usenix.org/conference/12th-usenix-security-symposium/implementing-and-testing-virus-throttle},
publisher = {USENIX Association},
month = aug
}
Download

Links

Paper: 
http://www.usenix.org/events/sec03/tech/full_papers/twycross/twycross.pdf
Paper (HTML): 
http://www.usenix.org/events/sec03/tech/full_papers/twycross/twycross_html/index.html
  • Log in or register to post comments

© USENIX
EIN 13-3055038

  • Privacy Policy
  • Contact Us