Active Immunization Against Internet Viruses, Worms & Trojans主动免疫对互联网的病毒,蠕虫及木马
Active immunization is an extremely interesting technique in fighting against internet based viruses, trojans and worms.主动免疫是一个非常有趣的技术在打击基于Internet的病毒,特洛伊木马和蠕虫。 Laurent Oudot of the Rstack team created a洛朗oudot的rstack队创造了 prototype原型 in 2003.在2003年。 He identified hosts compromised with msblast.exe worm using他指出主机妥协与msblast.exe蠕虫使用 honeyd - a popular honeypot and then immunized them using the same exploit (to obtain a shell) as the worm itself and run a simple script to clean the system of the worm. -流行的蜜罐,然后免疫他们使用相同的利用(获得一个s hell)由于蠕虫病毒本身并运行一个简单的脚本来清洁系统的蠕虫病毒。
There are strong implications of this concept.有强烈的影响,这个概念。 Technically a script kiddie too can use the same backdoor created by a worm and create more hamrful exploits.在技术上是一个脚本kiddie也可以使用相同的后门所造成的蠕虫,以及创造更多hamrful利用。 All he has to do is use honeypots to look for new exploits.所有他要做的是使用蜜罐,以寻找新的功勋。 However that is something he can do even today and some does it.不过,这是他可以做即使到了今天,有些是否。
Then there are strong moral implications.然后有强烈的道德影响。 Is it fair to immunize a exploited system irrespective of their owners knowledge and will?这是否公平进行免疫接种1剥削制度,不论其拥有的知识和会? What happens if something gies wrong?发生什么事,如果gies错了吗?
Let’s take a real-life scenario.让我们以一个真实的生活情景。 Suppose you have a child in your community with a highly infectious disease who is attending school and his parents are away.假设您有一个孩子在您的社区与一种传染性很强的疾病,谁是上学和他的父母不在。 Would you wait for his parents to come back, inform the cops, inform the school authorities or directly immunize the child yourself.你会等待他的父母回来,告知警察,通知学校当局,或直接进行免疫接种,儿童自己。 You will probably do one of more of the above depending on the virulence of the infection and perceived risk to your own children.你可能会做一个更多的上述视乎有关毒感染与知觉风险,以自己的孩子。 It is the same with the internet.它是相同的与互联网。
Personally I think if I am being attacked by a system, willingly or not, then I have the right to immunize it.我个人认为如果我被攻击的系统,心甘情愿地或不能够的话,我有权进行免疫接种。 Frankly it will be much easier once such actions are explicitly backed by law.坦白说,这将容易得多,一旦这些行动是明确支持由法律规定。
The same technique when applied to a large corporation becomes much simpler in terms of ethics and morality.同样的技术时,适用于大公司,成为简单得多,在伦理道德。 The corporation has full rights to its machines and active immunization is the way to go.该公司已充分权利,其机器和主动免疫是路要走。
The downside is that crackers too can fight back by introducing code which seals the backdoor it created after its has infected the system.坏处是,饼干也可以反击引入代码,印章后门它创造了后,其已受感染的系统。 Future communication with the owner will be through polling only.未来的沟通与业主将通过投票只。 Again access to corporate intranet is simpler and needn’t use the backdoor.再次进入企业内部是简单,不必使用后门。 Overall I think active immunization is a very useful strategy for large corporation and can also be implemented on internet if adopted by hosting providers for their own networks.整体我认为主动免疫是一个非常有益的策略,大公司,也可以实施在互联网上,如果通过托管服务提供商为自己的网络。
Filed under提起下 Computer Security计算机安全 , , Headline News头条新闻 , , How To如何 , , Microsoft微软 , , Open Source Software开放源码软件 , , Web网页 , , Web Services Web服务 | |
| |
RSS 2.0 2.0 | |
Trackback Trackback跟踪 this Article |此文章|
Email this Article电子邮件此文章
You may also like to read您也可以想读 |




