Quarantine technology

Quarantine technology

In December, 1988, shortly after the Morris Worm, Jay Nickson started work on "Quarantine", an anti-malware and file reliability product. released in April, 1989, "Quarantine" was the first such product to use file signature instead of viral signature methods.

The original "Quarantine" used Hunt's B-tree database of files with both their CRC16 and CRC-CCITT signatures. Doubling the signatures rendered useless, or at least immoderately difficult, attacks based on CRC invariant modifications. Release 2, April 1990, used a CRC-32 signature and one based on CRC-32 but with a few bits in each word shuffled. The subsequent MS-AV from Microsoft, 'designed' by Checkpoint, apparently relied on only an eight bit checksum -- at least out of a few thousand files there were hundreds with identical signatures.

"Quarantine"
*allowed suspect files to be
** Deleted
** Moved to a quarantine area
** Flagged in a report
* Standard executable were scanned, or, one could use up to twenty file matching patterns
* Twenty exclusion patters were also available
* Twenty directory paths could be included, or twenty excluded.

In 1990 "Quarantine" received the LAN Magazine, Best of Year, Security award. In that year "Quarantine" was reportedly responsible for finding the first stealth virus at the University of Toronto, when all pattern matching virus detectors had failed.

The 1990 version also allowed

* Background processing
* Checking of executables and libraries as a file is opened
** Timing of checks, e.g. if one opened a word file, WORD and all its libraries could be checked:
** immediately
** Every half an hour
** once a day or every ten day, etc.

"Quarantine" allowed system managers to track all modifications of a selected files or file structures, hence "Quarantine" users also got early warnings of failing disks or disk interface cards.

The efforts and expenses to convert "Quarantine" to other platforms went unrewarded as Tripwire's 1991 copy of "Quarantine" for *nix was better funded and publicized than OnDisk could afford to match.

Jay's later efforts include modularized reliability and intrusion approaches that include either SHA-1 or MD5 signatures, or both if you like. "Quarantine" stopped shipping in 1994.


Wikimedia Foundation. 2010.

Игры ⚽ Нужен реферат?

Look at other dictionaries:

  • Quarantine (disambiguation) — Quarantine is a medical term for the act of keeping an object in enforced isolation for a period of time to limit or prevent the spread of disease or infection. Quarantine may also be:* Quarantine (computer game), a video game for the 3DO and IBM …   Wikipedia

  • Technology in Revelation Space — This article lists elements of technology in the fictional Revelation Space universe created by Alastair Reynolds. Contents 1 Abstractions and entoptics 2 Cache Weapons 3 Conjoiner Drive 4 …   Wikipedia

  • General Administration of Quality Supervision, Inspection and Quarantine — The General Administration of Quality Supervision, Inspection and Quarantine (AQSIQ; Chinese: 中华人民共和国国家质量监督检验检疫总局) is a ministerial level department under the State Council of the People s Republic of China that is in charge of national quality,… …   Wikipedia

  • Medieval technology — Pumhart von Steyr, a 15th century supergun …   Wikipedia

  • Ministry of Science and Technology of the People's Republic of China — 科学技术部 Agency overview Dissolved State Science and Technology Commission Jurisdiction National Headquarters Beijing Minister responsible …   Wikipedia

  • agricultural technology — Introduction       application of techniques to control the growth and harvesting of animal and vegetable products. Soil preparation       Mechanical processing of soil so that it is in the proper physical condition for planting is usually… …   Universalium

  • Ministry of Industry and Information Technology of the People's Republic of China — 中华人民共和国 工业和信息化部 Agency overview Formed March 2008 Dissolved Ministry of Information Industry Jurisdiction …   Wikipedia

  • Mora National Fish Hatchery and Technology Center — The Mora National Fish Hatchery and Technology Center is one of seven federal fish hatchery technology centers in the United States. Located in Mora County, New Mexico, on State Route 434 (milepost 1.5),[1] it is mainly involved in the… …   Wikipedia

  • Antivirus software — Antivirus redirects here. For antiviral medication, see Antiviral drug. Antivirus or anti virus software is used to prevent, detect, and remove malware, including but not limited to computer viruses, computer worm, trojan horses, spyware and… …   Wikipedia

  • Food irradiation — The Radura logo, used to show a food has been treated with ionizing radiation. Food irradiation is the process of exposing food to ionizing radiation[1] to destroy microorganisms, bacteria, viruses, or ins …   Wikipedia

Share the article and excerpts

Direct link
Do a right-click on the link above
and select “Copy Link”