Proactive detection of code injection worms

Charles Renert Determina

Some of today's most dangerous worms are finding ways to compromise systems by injecting and running the code of their choosing on a remote host. Different from classic email-borne worms, these new threats (e.g. CodeRed, Slammer, Blaster) take advantage of recently published vulnerabilities to launch their payloads. Code injection worms are especially dangerous for two primary reasons:

    1) they are not detectable by traditional AV software
    2) they spread extremely rapidly because they require no user interaction.

Reactive strategies to prevent damage from these worms are too slow, and often risky to deploy. Only proactive detection techniques are truly effective against these worms - techniques that do not need updating because they stop both current threats and those that are as yet unwritten. In this paper, I examine the state of the art for proactive detection of this growing threat class.


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

Jobs

In Virus Bulletin's jobs pages among others:
Virus Bulletin currently has 190,859 registered users.