ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Security threats Toolkit

Tech monoculture study wins funding

Published: 26 Nov 2003 10:40 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

The National Science Foundation has granted $750,000 to two universities to study how diversifying information systems and software could help fend off future cyberattacks, the agency said on Tuesday.

The study, proposed by Carnegie Mellon University and the University of New Mexico almost a year ago, will seek to identify commonalities in software that could be used as the basis for attacks. Such common vulnerabilities would point to a computer "monoculture" -- a population so homogeneous that a single threat could destroy it.

"We are looking at computers the way a physician would look at genetically related patients, each susceptible to the same disorder," Mike Reiter, a professor of electrical and computer engineering and computer science at Carnegie Mellon, said in a statement. "In a more diverse population, one member may fall victim to a pathogen or disorder while another might not have the same vulnerability."

Massive digital epidemics -- such as the Code Red, Slammer and MSBlast worms -- have infected hundreds of thousands of computer systems, leaving scientists to wonder if worse is in store for the Internet.

The focus on computer monocultures is not new. In fact, the project echoes themes addressed in a controversial paper submitted by seven well-known security researchers, who warned that Microsoft's dominance in software could make possible a cyberattack that would be catastrophic for corporations. The paper, sponsored by a Microsoft opponent, had been dismissed by some of the software giant's supporters as partial and based on weak science.

However, the monoculture issue has many historical antecedents outside of the computer industry and has been studied in other software engineering projects, according to the National Science Foundation announcement.

Earlier attempts at using diversity to hamper the spread of Internet threats used multiple development teams for the same software project, assuming that different teams would make different mistakes. That was expensive, the Carnegie Mellon and University of New Mexico researchers noted.

The researchers intend to create an application that could generate diversity in key aspects of software programs, thus making the same vulnerability less effective as a means of attack against the population as a whole.

"Our automated approach has the potential to be more economical and could introduce more diversity into computer systems," Stephanie Forrest, professor of computer science at the University of New Mexico, said in a statement.

The research could be good for Microsoft. In the end, the techniques the academic researchers develop could help the software giant and other organisations break up their monocultures without losing market share.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
70 out of 154 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:








Related Jobs

Business Solutions Manager

Our success is built on innovation, curiosity and diversity, and on seeing each others differences as an advantage. University degree or equivalent ...

Systems Engineering Manager-Storage,De-duplication,VTL,NFS,CiFS,iSCSI

Systems Engineering Manager-Storage, Data De-duplication, VTL, NFS, CiFS, FCP, iSCSI, Veritas Netbackup, Disaster Recovery, Windows, Linux, UNIX ...

E-Science Centre, Science & Technology Facilities Council, Oxfordshire

The STFC e-Science Centre (http://www.escience.stfc.ac.uk/ ) focuses on the exploitation of e-Science technologies throughout STFCs programmes ...

Featured Talkback

What was achieved there is recognised to be of fundamental importance to both winning the war (Churchill visited to say 'thank you' to them) and the development of the computer. Maybe Bill Gates doesn't want to support this museum because it underlines where electronic computing started i.e. here, not the U.S.

By: 1000103773

Read full story:
Bletchley Park faces bleak future

Sentry Posts Blog

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

The Google Apple Merger: Fantasy or Fu...

The Google Apple Merger: Fantasy or Future? Author: Eric Everson, Founder MyMobiSafe.com Market research suggests that Microsoft controls upwards of 90% of the respective computer-based... More

1 comment