Abstract
Computer viruses can be classified into four types: viruses, worms, Trojan Horses, and malicious codes. In the thesis we discuss viruses and worms. To begin with, we will explain the way that media are infected by viruses, including disks, mails, downloads, and execution of unknown files. We will also explain the way that viruses or worms attack, including leakage of computer OS, file-sharing, or internet chat. After understanding the propagations of viruses, we propose ways of defense. Essentially, we could employ the error messages(ICMP) generated by the router to detect the new invading viruses. The most important part of the thesis is an experiment of a worm targeting the behavior of Spybot.Worm, a well-known worm. We try to understand what kinds of attack the worm does under what environment, and the procedure in which the worm infect computers. Spybot.Worm takes different attacks on different types of computers. The key point of our observation is that the worm code is divided into hundreds of packets, which are transmitted in order. Based on the observation, we propose a whole new approach to detect new viruses. The new detecting approach is done in the router by way of matching correlations of the packets, like gene correlation. Thus we can determine if the new virus is in the internet, and where the infected computer is. The experiment of Spybot.Worm provides us with some new discoveries on worm’s attack. The details of the experiment are reported in the thesis as a reference for future investigation about viruses. We also suggest some improvements on the environments of the experiment and record some disadvantages of the experiment procedure. Predicting virus is a recent focus in the development of Computer Science. The conclusion of this thesis is that we can fight against viruses not only in clients but also in the routers for much better defense.