Tuesday | 14 October, 2008
CIO
Good Software Gone Bad
Fred Hapgood 15 May, 2001 16:08:47

Ten years ago, computer security guru Fred Cohen made a revolutionary suggestion, one that inverted the roles of hardware and software. In traditional IS architectures, hardware persists while software is transient; the same processor executes instructions from many programs. This is why we say that software runs on hardware. Cohen suggested building an architecture around mobile programs, applications that would move around a network, recruiting and organizing hardware as needed. In this vision, the programs would endure while the hardware would come and go. In effect, the hardware would run on the software.

The primary function that Cohen saw for his mobile programs was ensuring reliable and efficient resource distribution. Most computers spend almost all their time doing nothing; Cohen's theory stated that mobile programs could find and harvest this unused capacity. If you allowed them to copy themselves-an intrinsic part of the vision-they could distribute themselves in huge numbers throughout the whole universe of unused capacity, attacking very large problems with vast amounts of parallel processing.

Cohen, now a senior member of the technical staff at Sandia Nation Laboratories and a senior partner with Fred Cohen and Associates consultancy, also defined a set of situations-primarily where programs needed to interact with many databases-when it seemed to make sense for a program to send copies of itself to each database rather than have one master program sitting in a central location and sending requests. Cohen even wrote two Unix programs, both essentially bill-collection agents, to illustrate his concepts. CIO thought his ideas were provocative and potentially important, and in April 1992 we ran an excerpt from one of his articles. After all, this is how the brain seems to work: Memories appear to persist even as individual neurons are born and die.

In retrospect, Cohen should have drawn on this biological connection and given his theory some name like "digital neurobiology." If he had done so, he probably would have been fighting off potential investors. He was a virus specialist, however, (he even claims to have invented computer viruses) and that is what he called his mobile programs-viruses. From his point of view, the term was technically accurate. His articles came with titles like "Harnessing the Subtle Power of Computer Viruses." (Our own excerpt was titled "The Virtuous Virus.") At that time, unfortunately, technology culture was in no frame of mind to burden itself with complicated distinctions between good viruses and bad viruses. Today, computer viruses are a nuisance, threatening the loss of a day or two of productivity, if that. In those days, it was not clear that the threats posed by viruses could not bring down a company altogether. When Cornell graduate student Robert Morris's experiments with a virus got out of control, he was arrested, convicted, fined and booted out of college. At one point, Cohen himself briefly lost network privileges when an overzealous system administrator discovered the nature of his research. The idea of releasing viruses deliberately, for good reasons or bad, was simply beyond the pale, and Cohen's ideas sank without a trace.

Then in the late '90s a number of programs appeared that let users contribute unused computing resources to problems of public interest. The most famous is David Anderson's SETI@home, which distributed the problem of examining radio telescope data for patterns that might indicate extraterrestrial intelligence. The concept caught on quickly, and today dozens of projects in science and medicine are soliciting volunteers ("Help solve the protein folding problem!"), while a number of companies, including one started by Anderson himself (Austin, Texas-based United Devices), sell programs meant to carry what is now called "distributed" or "grid" computing into corporate networks and enterprise computing.

Nobody ever even breathes the term virus when discussing grid computing, but the concept has much in common with Cohen's idea: Programs spread out through the landscape, looking for, recognizing and recruiting unused resources.

Of course grid computing clients are not autonomous-users authorize each contribution. But a number of researchers believe that as questions get more complicated and access devices simpler, queries will naturally become self-executing and autonomous. Recently two Dartmouth researchers, David Kotz and Robert S. Gray, predicted (in a paper called "Mobile Code: The Future of the Internet") that in a few years nearly all major Internet sites will host some form of mobile agents-or as Cohen would have called them, viruses"Please open this e-mail message, it contains a good virus." Yeah right. Tell it to et@cio.com.

More about SETI, United Devices
Market Place
 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
  • +

    CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II 05 October, 2007 06:00:00

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #78: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires 28 September, 2007 17:34:25

    For his new book, The Outsider's Edge: The Making of Self-Made Billionaires, social researcher Brent D Taylor spent four years of intensive research investigating the psychological make-up and backgrounds of some of the world's richest men and women, including IT luminaries Bill Gates, Larry Ellison and Steve Jobs. Taylor discovered that, despite working in different industries and coming from different upbringings, they all have one thing in common -- they are all outsiders.
  • +

    CIO Live Podcast #77: Panasonic Speeds Up Trans-Pacific File Transfers, Part III 21 September, 2007 07:00:00

    Part three in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #76: Panasonic Speeds Up Trans-Pacific File Transfers, Part II 14 September, 2007 07:00:00

    Part two in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    CIO Live Podcast #75: Panasonic Speeds Up Trans-Pacific File Transfers, Part I 07 September, 2007 07:00:05

    Part one in our three-part special report from CIO's sister publication Network World in the US, as Paul Desmond reports from the Network World IT Roadmap Conference in Santa Clara, California. With development teams in the US and Japan, Panasonic needed a more efficient way to move very large files between the two locations. Iben Rodriguez, IT consultant for Panasonic Research and Development, explains how a storage-area network and virtual server technology helped speed up WAN performance.
  • +

    Cutting Through the Spin of Recent Vulnerability Disclosures 13 October, 2008 10:53:00

    The FUD surrounding the ClickJacking and TCP/IP vulnerabilities has the world seemingly frozen in fear. But once you cut through the spin, the vulnerabilities aren't all that they were made out to be.
    There are a few highly publicised vulnerabilities at the moment which haven't completely been disclosed and which, it is claimed, could threaten the whole Internet as-we-know-it. Only, when the vulnerabilities are finally disclosed, it seems that the whole incident has been somewhat Chicken Little.
  • +

    PCI app security: Who's guarding the data bank? 13 October, 2008 11:09:00

    Compliance strategies for PCI's new application security requirements
    While Willy Sutton never really said it, the truth is that people rob banks because that is where the money is. Today's criminals don't walk into banks with loaded guns and get-away drivers. Rather they connect from a remote location using a browser and are armed with hacking tools and spyware.
  • +

    Data-center security tools to not overlook 10 October, 2008 11:37:00

    With the rise of security suites, it's time to consider some emerging security tools and rethink others
    Protecting a corporate data center is like trying to keep an elephant safe from a swarm of flies. Despite your best efforts, bites happen. As the staples of security -- such as firewalls, antivirus software, spam and spyware filters -- come together in suites of products that allow for sophisticated management, there are other security tools either emerging or worth a rethink.
  • +

    IBM, Secret Service, others study identity/cybercrime issues 09 October, 2008 10:09:00

    Center for Applied Identity Management Research organization teams experts in criminal justice, financial crime, biometrics, cybercrime and cyberdefense, data protection, homeland security and national defense.
    IBM, LexisNexis and the Secret Service are among a group of corporations, government agencies and academic institutions that has formed to study and help solve identity management challenges around cybercrime, terrorism and narcotics trafficking.
  • +

    Strange account management at Amazon 09 October, 2008 09:51:00

    A careless login led to the discovery of some strange ccount management practices at one of the Internet's largest retailers.
    Via the RISKS mailing list comes an interesting tale of poor online account management at a major online retailer. According to Graham Bennett, accounts with Amazon display an odd behaviour that doesn't seem to have attracted much attention in the past.
CIO Webcast Innovation #8 - What are the biggest roadblocks to IT's involvement in innovation at your company?
Watch the latest latest edition of CIO Innovation which is now available for download.
Watch the webcast
Sign up to the CIO Innovation update email


CIO Live Podcast #79: Brent D Taylor, author of The Outsider's Edge: The Making of Self-Made Billionaires Part II
Listen to the latest edition of CIO Live which is now available for download.
Listen to the podcast
Sign up to the CIO Live email
Whitepaper

Email Archiving 101—Customer Case Study

Join Lee Benjamin, a Microsoft Exchange MVP and Ryan Shipkowski, network administrator for Matthews, to discuss the process and ROI of implementing an email archiving solution, with emphasis on a case study from Matthews International.