Researchers Dig On New Anti-Worm System

Researchers Dig On New Anti-Worm System

Written By
Matthew Hines
Matthew Hines
Feb 16, 2007
2 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Earlier this week, researchers at Penn State University issued a report about a new software system they say can better defend against Internet worm viruses.

And while much more attention is being given of late to spyware programs responsible for stealing real world assets from both businesses and consumers, the recent ripple caused by the Storm Worm attack proved the approach still has potency.

Researchers at messaging security software maker Commtouch estimated that more than 7,000 distinct variants of Storm Worm appeared over the first few days of its mid-January outbreak, with more than 40,000 variants identified by the company as of Feb. 1.

The Penn State group claims to improve on existing signature-based and pattern-based worm defense systems with a technology dubbed PWC (Proactive Worm Containment).

Unlike the more traditional worm identification and blocking tools, the researchers claim their anti-virus system monitors a packet’s rate or frequency of connections — and the diversity of its connections to other networks — to speed response to potential outbreaks, according to a report filed on the University’s Penn State Live site.

Just as most experts say signature-based anti-virus tools are insufficient to stop zero days threats and other more cutting-edge attacks on the network and desktops, organizations need a more proactive approach to faster moving worm threats to ward them off effectively, the PSU researchers said.

“A lot of worms need to spread quickly in order to do the most damage, so our software looks for anomalies in the rate and diversity of connection requests going out of hosts,” Peng Liu, an associate professor at Penn State and lead researcher on the PWC system, is quoted as saying in the report.

The defense mechanism involved controls the flow of packet outbreaks and more aggressively quarantines suspicious traffic, while employing intelligent false-positive prevention tools, according to the researchers. In that manner the PWC is also better suited to defend against denial-of-service attacks, the group claims.

One shortcoming of the system admitted by its inventors is an ability to capture slow-spreading worms. However, your old school signature-based system should be able to catch those, said Liu and his group.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.