Computing Reviews
Today's Issue Hot Topics Search Browse Recommended My Account Log In
Review Help
Search
Computer virus-antivirus coevolution
Nachenberg C. Communications of the ACM40 (1):46-51,1997.Type:Article
Date Reviewed: Dec 1 1997

Nachenberg has produced a reasonably clear and succinct, although poorly edited, overview for the nonspecialist of the current status of the conflict between those who create computer viruses and those who wish to avoid becoming their victims.

Early computer viruses were easy to detect because they occurred in predictable places and bore unchanging code that simple antivirus programs could find and eliminate. As antivirus programs became more effective, virus writers countered by developing techniques that allowed their products to escape detection. The cycle of threat and response continues today. “Coevolution” is the author’s apt term for the never-ending threat-response cycle in which attackers and defenders engage. The term is consistent with the biological metaphor implicit in the term “computer virus.”

The author calls viruses of the newest type he describes “polymorphic,” because their code changes as they propagate. They encrypt their invariant code under different keys for each instantiation. Even the embedded decryption routines vary, because they are made up of different sequences of instructions with the same effect. The antivirus programs that can detect polymorphic viruses use what the author calls “generic decryption”: they emulate the target computer to produce the underlying invariant code without actually executing it.

The author ends with some speculation about the inevitable next rounds in this war without end. His well-grounded speculation will, regrettably, not fill readers with optimism.

Reviewer:  S. A. Kurzban Review #: CR120767 (9712-1041)
Bookmark and Share
 
Invasive Software (K.6.5 ... )
 
 
Invasive Software (D.4.6 ... )
 
Would you recommend this review?
yes
no
Other reviews under "Invasive Software": Date
Rogue programs: viruses, worms and Trojan horses
Hoffman L. (ed) Van Nostrand Reinhold Co., New York, NY,1990. Type: Divisible Book
Sep 1 1991
Computer viruses and anti-virus warfare
Hruska J., Ellis Horwood, Upper Saddle River, NJ, 1990. Type: Book (9780131710672)
Sep 1 1991
The computer virus handbook
Levin R., Osborne/McGraw-Hill, Berkeley, CA, 1990. Type: Book (9780078816475)
Sep 1 1991
more...

E-Mail This Printer-Friendly
Send Your Comments
Contact Us
Reproduction in whole or in part without permission is prohibited.   Copyright 1999-2024 ThinkLoud®
Terms of Use
| Privacy Policy