Virus prevention - body talk

By mimicking the human body's immune system computers will be able to fight off the threat of virus infections.

Written by Toby Howard, Personal Computer World

Is your PC virus free? Do you regularly run virus checking software? Do you virus check email attachments before saving them to disk or, heaven forbid, executing them? If you do, is your checker's virus list up to date? If the answer to any of these questions is 'no', ask yourself why.

Is it too much hassle? Yes, it often is, but don't despair. There's new research under way to make virus checking programs a thing of the past.

In future, you may just need to make sure your computer's immune system is healthy and it will do the rest.

Professor Stephanie Forrest and her colleagues and students at the University of New Mexico in Albuquerque are taking a new approach to combating the problem of computer viruses. They're copying the way our body deals with invaders, by creating a computer analog of the human auto-immune system.

Our immune system works by being able to distinguish things which are 'self', and therefore generally safe, from things which are 'non-self', and likely to be dangerous. There are two main strategies: 'innate immunity' and 'acquired immunity'. For innate immunity, cells called phagocytes patrol our bloodstreams, programmed to spot and kill invading microbes.

The phagocytes end up in the lymph nodes carrying the remains of any microbes, and stimulate our second line of defence, which is the acquired immunity.

This is the job of the lymphocyte, a kind of white blood cell. Each lymphocyte is programmed to recognise a particular protein, which it classifies as either 'self' or 'non-self'. The body creates massive numbers of lymphocytes, randomly programmed to recognise different proteins. Before they enter the bloodstream, however, they undergo a maturation phase in the thymus.

It's here that lymphocytes that happen to recognise 'self' proteins are weeded out and killed, leaving only those that recognise 'non-self' to be released into the bloodstream.

Autonomous programs

It's this approach that Forrest is trying to mimic, to implement an immune system for a computer, see www.cs.unm.edu/~forrest/. Instead of lymphocytes, she's using autonomous programs that run and check data coming across network connections, looking for unexpected code in memory. It's a challenging problem to apply the principles of a living immune system to a machine.

The machine immune system needs to have a reliable definition of 'self', must respond to attempted infections and remember new infections it comes across, and must itself - as a system - be immune from attack.

But what do the concepts of 'self' and 'non-self' mean for a computer? Forrest is experimenting with using a record of low-level operating system function calls to construct a 'self' profile for a given PC, based on the idea that most machines have users who tend to run the same programs regularly.

After performing a statistical analysis of the patterns of system calls over a period of time, a 'self' database can be constructed that reflects the normal usage patterns of the machine. 'Non-self' is then defined as any unrecognised pattern of operating system calls.

Whenever a program runs, its system calls are monitored and checked against the usage patterns in the 'self' database. If unusual patterns are detected, it could indicate viral attack. (Of course, the database would need to be updated when new, authorised software is installed.) Related research is concerned with immunising against hacker attacks coming from the internet by checking for uncommon data patterns in incoming TCP/IP packets.

It's unlikely that a machine's immune system can ever be anywhere near as sophisticated and reliable as our own, but it's an intriguing idea that your PC could soon stay virus free, and you won't have to lift a finger.

Tags:

Further reading

Sircam worms its way to number one

Email virus officially the major villain of the year   More...

UK web users under siege

95 per cent of home users targeted by hackers, claims research.   More...

McAfee gets ASP patent

Software patent unlikely to put wind up Microsoft.   More...

Related articles

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

04 Jul 2008

5.51 MBPodcast Special: Views from the Valley More...

03 Jul 2008

3.46 MBGreen grid computing, Trojans stop play and location-based services More...

02 Jul 2008

3.2 MBOnline TV, SME security and flexible laptops More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Online pornography

US rebate cheques spent on porn

Economic stimulus package works wonders   More...

Louis Vuitton

UK online fake goods market worth £800m

Legal experts warn of dramatic rise in 'e-fencing'   More...

Advertisement

Fibre-optics

New fibre-optic connections overtake cable

Broadband first-timers choosing fibre where possible   More...

Stars and Stripes

Cyber-crooks celebrate Independence Day

Security firms warn users to take extra care   More...

Advertisement