Fellow NW blogger Layer 8 has the scoop on an Ohio State University breakthrough for thwarting Internet worms within minutes of an infection:
The key, researchers found, is for software to monitor the number of scans that machines on a network send out. When a machine starts sending out too many scans — a sign that it has been infected — administrators should take it off line and check it for viruses. A scan is just a search for Internet addresses — what we do every time we use search engines such as Google. The difference is, a virus sends out many scans to many different destinations in a very short period of time, as it searches for machines to infect.




