Archive for November, 2011

A Self-Learning Worm Using Importance Scanning

INTRODUCTION
A worm attacks vulnerable computer systems and employs self-propagating method to flood the Internet rapidly Worms, such as Code Red [10], Slammer [9], and Witty [17], have infected hundreds of thousands of hosts and become a significant threat to network security and management. It is therefore of great importance for defenders to characterize the spread of worms that employ distinct scanning methods and to study countermeasures accordingly.

Different scanning methods have been employed by previous worms. For instance, Morris worm used topological scanning that relies on the information contained in the victim
host to find new targets. Code Red v2 and Slammer worms employed random scanning that selects targets randomly. Code Red II and Nimda worms exercised localized scanning that preferentially searches for targets on the “local” address space.

Autograph Toward Automated, Distributed Worm Signature Detection

Introduction and Motivation
In recent years, a series of Internet worms has exploited the confluence of the relative lack of diversity in system and server software run by Internet-attached hosts, and the ease with which these hosts can communicate. A worm program is self-replicating: it remotely exploits a software vulnerability on a victim host, such that the victim becomes infected, and itself begins remotely infecting other victims. The severity of the worm threat goes far beyond mere inconvenience. The total cost of the Code Red worm epidemic, as measured in lost productivity owing to interruptions in computer and network services, is estimated at $2.6 billion [7].

Models of Internet Worm Defense

Content Filtering
We consider two schemes analyzed by Moore et al. “Requirements for Containing Self-Propagating Code”
Content filtering—Idea is that worm packets look a lot alike. One can find
signatures based on hashes of packet content to recognize I’m told that actual commercial products exist that do this Our model : after a delay T0, worm scans are recognized by packet content.
Filters at local network boundaries protect those networks. Fraction fopen of hosts have “open path” to attack still.
Phase I – the worm spreads before detection.
Phase II – the susceptible population drops from s(T0) to
(1 – fopen) × s(T0), dynamics otherwise are the same.

Address Blacklisting
Address Blacklisting—likely infected hosts are added to blacklists. Fraction fopen hosts remain unprotected.
Our model :
Detection delay T0 of infected host, detection framework started at time
D0
Phase I—original spreading dynamics
Phase II—At time D0 + T0 blacklisting takes effect. Split populations into
that which is covered by blacklisting (sp) and that which is unprotected
(su): At time D0 + T0:

So You Wanna Be A Photoshop Expert

Now that you have decided that Photoshop is going to help make your photographs sell better than Pokémon toys, how are you going to learn the program? You have a lot of choices, but it really depends on your style of learning as to how you go about it. Some people are extremely self-motivated and disciplined. These people can sit down with a manual and a few books, and teach themselves. Plan to devote a number of hours each day, and give yourself projects to work on. It definitely takes a commitment, but most people, once they experience what the program can do, can’t drag themselves away. Start with the tutorials on your Photoshop CD, and move on to a book like the Adobe Classroom in a Book. By the time you have finished these, you should feel confident enough to work on your own projects.

eTrust Antivirus Groupware Options User Guide

Using an electronic messaging system is a common way for today’s corporations to communicate. Quite often, the messaging system becomes an essential method for sharing information and documents, both within and outside of the enterprise. Unfortunately, these same systems can have gaps in security that enable infections to rapidly spread through an organization—posing risks to both data and productivity.

According to an International Computer Security Association (ICSA®) survey, email attachments are the most common sources of infections. Macro viruses, worms, and other malicious code can come in through email to slow down and debilitate your system. For example, infectors such as the Winword Concept macro virus and the Melissa virus have become among the fastest spreading viruses in history. According to the ICSA, the well-known LoveLetter virus is a mass-mailer, and therefore has the potential to spread quickly. The virus arrives as a VBS file attached to an email message.

PCI DVB-S2 Card for Satellite HDTV

Key Functions
1. Digital HDTV & Radio receiving (DVB-S2 and DVB-S):
Watch digital satellite TV programs on your PC
Listen to digital stereo radio
Support DiSEqC 1.2 & 2.0

2. High Definition & Crystal Clear Video Quality:
Support DVB-S2 HDTV
4:3 & 16:9 selectable aspect ratio
Experience best video quality at high resolution up to 1080i

3. Internet via Satellite:
DVB data service
High-speed Data download via satellite bandwidth

4. Personal Video Recording:
Instant & pre-scheduled record programs as MPEG II format
Wake Up Schedule Recording
Time-Shifting

5. TV Function:
Electronic Program Guide (EPG)
Transponder, region, and Frequency range Auto Scan
Multiple Frame Capture
Multi Channel Preview
Favorite List
Hot Keys
Supported by ProgDVB.Skygrabber…

Download PCI DVB-S2 Card for Satellite HDTV