When a software vulnerability is disclosed, virus writers rush to release a virus or worm that exploits the vulnerability before customers can apply a patch that fixes it. Today, anti-virus researchers typically have to rapidly obtain the new virus or worm, analyze it and produce a signature to send to users. The problem with signature-based anti-virus protection is that if the threat spreads faster than a signature can be produced, computers get infected.
A new security technology called generic exploit blocking shields systems from malicious threats before they appear. When incorporated into desktop and network firewalls, the technology prevents infections rather than responding to them.
Generic exploit blocking differs from traditional signature-based protection technologies. Like traditional signatures, generic exploit blocking requires analysis to determine characteristics and create fingerprints. But the code being analyzed differs. Generic exploit blocking analyzes the targeted vulnerable software rather than the attacking viruses. This difference is significant because it lets security researchers deliver protection before an exploit has been posted or released in the form of a new virus or worm. The goal of generic exploit blocking is to characterize a system vulnerability and then build a signature that can detect and block all potential attacks against that vulnerability.
The need for this technology was established in July 2002, when Microsoft announced a vulnerability in Microsoft SQL Server database. To exploit the vulnerability, an attacker simply had to send a packet that was 61 bytes or longer, and whose first byte had a value of 4, to network Port 1434 on an unpatched machine running SQL Server. A generic exploit-blocking signature for this vulnerability would have blocked the threat.
Security software vendors could send signatures to firewalls in the form of virus definition updates. A firewall on the corporate server or desktop PC then would filter all incoming and outgoing packets with this signature. Had a signature been deployed shortly after a vulnerability was announced, the MS-SQL Slammer worm would have been blocked from its inception.
In a similar fashion, many high-profile vulnerabilities seen over the past two years could have been protected with this technology. For example, a generic exploit-blocking signature could have been sent out after the April 13, 2004, announcement of the LSASS vulnerability in Microsoft Windows. Such a signature would have prevented the spread of the Sasser and W32.Korgo worms from their inception. As this technology emerges in products, it will reduce dramatically the impact of new computer worms and hacking attacks.
Generic exploit blocking is an effective deterrent to the majority of network attacks, including threats such as Slammer, Blaster and Nimda. Moreover, it is appropriate for enterprise and consumer security products, from desktops to servers and home routers. Generic exploit blocking can be incorporated into any device that filters network packets. As packets flow through a protected device, generic exploit blocking software attempts to match each vulnerability signature against the data, blocking packets that match.
Complementary capabilities
Technologies such as generic exploit blocking will not replace traditional reactive signature-based techniques for detecting viruses and worms. Rather, generic exploit blocking provides complementary capabilities to protect a system from future attack weeks or months before an exploiting worm or virus is created.
When combined with automated updating mechanisms that deliver security signatures efficiently, reliably and regularly, generic exploit blocking and traditional reactive signature techniques let businesses mitigate the risk of falling victim to Internet hazards.
Clyde is vice president and CTO for Symantec. He can be reached at rclyde@symantec.com.Nachenberg is chief architect of Symantec Research Labs for Symantec. He can be reached at cnachenberg@symantec.com.




