Welcome | Sign In
TechNewsWorld.com
Malware

HP Claims Virus Throttler Snuffs Out Worms

Print Version
E-Mail Article
Reprints
HP Claims Virus Throttler Snuffs Out Worms

Although the idea is a good one, SecurityCurve analyst Ed Moyle said, he's unconvinced it will work. "I suspect that the implementation might fall short of the ideal in determining threats ahead of time," he said.


Listen to Your Customers, Grow Your Bottom Line.
Learn how loyal customers can be your best advocates for evangelizing your products and brand, while helping you to dramatically gain new business. Download "Customer Experience Management: Engaging Loyal Customers to Evangelize Your Brand."

Hewlett-Packard (NYSE: HPQ) has worked out the bugs in software it says will slow down the spread of worms and viruses within servers.

Virus Throttler -- which HP had said it was shelving back in August because it was having trouble integrating it with Microsoft (Nasdaq: MSFT) Windows server software -- is now back, HP CTO Tony Redman said Tuesday at the company's Software Universe in Madrid. HP said it solved the problem by creating access through a network driver.

Ready for ProLiant

The software will be available beginning in early 2005 on ProLiant servers running Windows 2000 and 2003 and for HP ProCurve network switching devices. HP is conducting Windows compatibility testing on the product.

Redmond said HP is working on a version of the software for PCs, but would not say when it might be released. He was even vaguer on the potential for a Linux version, saying only that HP is working on it, but that the multiple releases of Linux make it difficult.

The company has also tested it on 50 of its own servers, which it intentionally infected with viruses to monitor the throttler technology's capabilities. Redmond said the software worked without interfering with the servers' normal performance.

Analyst Doubts

Although the idea is a good one, SecurityCurve analyst Ed Moyle said, he's unconvinced it will work.

"I suspect that the implementation might fall short of the ideal in determining threats ahead of time. Specifically, without analyzing the malware and producing a signature for it, I think HP might find it difficult to determine which machines are infected and which aren't," Moyle told TechNewsWorld.

"Almost everyone will agree with the statement that reducing the infection rate for infected machines while maintaining network throughput for non-infected machines would be a boon to our industry. However, I don't think this is by any means a 'malware panacea,'" he said.

Detects Malicious Behavior

The software, developed at HP Labs in Bristol, England, works by detecting intrusions through behavioral patterns. Viruses will attempt to rapidly make the same connection over and over again, for instance. Once this type of activity is recognized, Virus Throttler slowly clamps down on the activity. Systems administrators will be alerted so they can decide what other steps are necessary to eliminate the infection.

But just as the industry works on new ways to hamper malware, malware writers are working to get around the barriers.

"I think that it is likely that malware authors will come up with ways to try to get around this technology. For example, there are a number of papers in the hacker community discussing how to circumvent IDS (Intrusion Detection) technology -- it's only a matter of time before someone will discover, test, and publish methods to circumvent this. If, for example, HP uses 'number of connections per second' to attempt to classify something as malware/non-malware, malware authors could re-tool their software to slow down the connection rate," Moyle said.


Print Version E-Mail Article Reprints More by Susan B. Shor


More by Susan B. Shor

Salesnet President Jonathan Tang Ready to Take On Salesforce.com
February 07, 2006
"We think it's Salesnet's time now. We've been around since the beginning, we've been lying low, but you're going to start to see more of us. We've done it through organic growth and happy customers. We continue to focus on customers."
Comcast Follows Time Warner in Offering 'Family' Programming Tier
December 23, 2005
"The demand for this type of tier is coming from the FCC and Christian conservatives. It has nothing to do with legitimate consumer demand," Todd Chanko, senior analyst at Jupiter Media, told the E-Commerce Times.
High-Risk Flaw Found in Symantec's Software
December 22, 2005
"Part of the significance of this vulnerability announcement is that your machine can be exploited without you needing to do anything at all. You don't even have to open an e-mail or attachment, and this happens with the default configuration of the product," said Forrester Research senior analyst Michael Gavin.
Don't miss a story -- sign up for our FREE e-mail newsletters and view the latest headlines at a glance.
Tech News Flash [ View Sample ]
E-Commerce Minute [ View Sample ]
ECT News Network Weekly Newsletter [ View Sample ]
Free eBook: Secure Your Datacenter
Click here to download today.
Shortcuts
ECT News Network Information
Reader Services
Corporate
ECT News Network