• DocumentCode
    3198378
  • Title

    NETSS: a networked environment for testing suspicious software

  • Author

    Ashburn, Matthew W. ; Lach, John ; Sulcoski, Mark

  • Author_Institution
    Dept. of Electr. & Comput. Eng., Virginia Univ., Charlottesville, VA
  • fYear
    2004
  • fDate
    16-16 April 2004
  • Firstpage
    163
  • Lastpage
    170
  • Abstract
    The increasing popularity of malicious software attacks concerns computer security professionals. While several platforms exist to evaluate malware, this project aimed to create a physical system to verify and expand on previous research. The project developed NETSS: a networked environment for testing suspicious software, a system designed to emulate the Internet. Unlike virtual alternatives, NETSS consists of four physical machines that are sandboxed, directing all outbound Internet traffic to a single internal server that responds to popular network service requests. With logging functions enabled, analysts may run a suspicious piece of software for evaluation. During testing, NETSS was used to analyze and identify a popular worm that appeared in a suspicious e-mail. The project also began development of the Ashburn-Sulcoski index, which quantifies malware threat potential. This index provides US Government agencies and other professionals a standard to quantify malware threats. Although the project produced a working index, refinement continues
  • Keywords
    Internet; computer crime; invasive software; program testing; unsolicited e-mail; virtual machines; Ashburn-Sulcoski index; Internet emulation; Internet traffic; NETSS systems; computer security professionals; malicious software attacks; malware evaluation; malware threats; network service requests; networked environment; physical machines; sandboxed machines; suspicious software testing; Computer security; IP networks; Network servers; Software design; Software systems; Software testing; System testing; Telecommunication traffic; Web and internet services; Web server;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Systems and Information Engineering Design Symposium, 2004. Proceedings of the 2004 IEEE
  • Conference_Location
    Charlottesville, VA
  • Print_ISBN
    0-9744559-2-X
  • Type

    conf

  • DOI
    10.1109/SIEDS.2004.239877
  • Filename
    1314676