- Nokia's new N97 vs. the iPhone
- 10 Microsoft research projects
- Hard to get justice in MySpace case
- Smartphone smackdown: Storm vs. iPhone
- Apple removes antivirus support page
Intel is working on a research project that would immediately notify PC users if they inadvertently download a rootkit like the XCP (extended copy protection) software found on certain music CDs shipped by Sony , researchers said Tuesday.
Intel held an open house for press, analysts, students and employees in Folsom, Calif., Tuesday to showcase some of its projects and talk a little about its vision of the future of computing. That future involves relieving humans of serving as the gatekeepers for reams of information flowing between computers and people, said David Tennenhouse, vice president of Intel's Technology Group and director of research at the company.
"We need to connect the computers directly to the data, so the human beings don't have to be the I/O channel, and elevate the role of the human being to a more supervisory role," Tennenhouse said.
One interesting project involves placing a small chip on a PC's motherboard to constantly monitor programs for modifications that might be the result of a malicious attack, said Travis Schluessler, a researcher with Intel.
Sony's XCP software implemented copy-protection policies with rootkit software. Rootkits are pieces of software designed to access a system and make changes or implement policies without being detected by the operating system or antivirus software. Security experts say malicious hackers might have used Sony's rootkit software to launch undetectable attacks.
Security vendors recently admitted that Sony's XCP rootkit caught them by surprise, even though it had been installed on thousands of systems for months before an independent researcher identified it, and their products need significant upgrades to detect rootkits.
The idea behind the Intel project is to protect systems from malicious programs that make their way onto a system and attack application software running in the system's memory, Schluessler said. Many modern worms and viruses, such as the Slammer and Blaster worms, attempt to disable programs running in memory or alter those programs to run the attacker's code and then propagate themselves across a network, he said.
The succinctly named "OS Independent Run-Time System Integrity Services" project attempts to limit memory-resident attacks by detecting changes in application code as they happen, allowing IT administrators to take immediate action, Schluessler said. Under this scenario, an "integrity measurement manager" running on a chip outside of the main CPU (central processing unit) or memory would identify a rootkit or malware that started to make changes to the program in memory. That detection would trigger any number of responses set by the IT department.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment