Internet Viruses Can Target Your Computer

No matter who you talk to, everyone has either had a computer virus or knows of someone who has gone through the agony of trying to get rid of the problem. Computer viruses are a hot topic that seem to affect everyone who owns a computer system, whether at work or at home.

The companies that produce software programs that catch and delete these computer viruses are constantly updating their databases for virus types and definitions so that they can better protect your system against all the newest viruses. Creating virus protection programs is a multi-billion dollar business that is growing more and more everyday.

The number of viruses being created and uploaded to the Internet is growing at an astounding rate of a new one every eighteen seconds! This definitely keeps the virus protection companies on their toes with research and development.

Because these viruses copy themselves to any computer system they come in contact with, the spread of viruses throughout a computer network or the Internet is a very fast and deadly thing to happen to your computer. Because computer viruses are a hot topic, they routinely are the subject of magazine articles and forum topics online. While some viruses do nothing more than frustrate you with pop-up ads or other messages, others are completely malicious and set out from the start to destroy the files and operating systems of your computer.

Of the 53,000 viruses that have been identified and classed, more than 80 percent of them have been classed as malicious and capable of harming your computer system or data files. These computer viruses behave in much the same way as biological viruses by contaminating any computer systems they come in contact with. These self-executing programs are generally very small and work at damaging the way your computer works or by damaging or completely removing key system files.

When computer viruses are a hot topic, more and more people find out about the destructive power of these programs. In this way a great many people find out about virus protection programs and rush out to get the newest protection programs or they ensure that their computer virus protection is up to date. Many magazine and news articles about computer viruses have the effect of sometimes panicking people into believing that their computers are at risk. Having a good anti-virus program and current updates is one of the best ways to protect your computer system against virus attacks.

This must also be coupled with good file habits such as scanning all downloaded files with the anti-virus program before opening them. It is always a good idea to take the time to ensure that the file you thought you were downloading is indeed the file you have. For instance, a file that labels itself as a movie file and is less than one megabyte in size is not a movie file. Movie files are generally nearly a thousand times that size and therefore, the file you have downloaded is most likely not a movie file and may in fact be a computer virus.

Computer viruses are a hot topic at the office when a virus attack manages to get past protection protocols put in place by the network administrators. All it takes is one person allowing some executable files they have been sent to open and start replicating itself through the network of computers to make life Hell for that company. Virus attacks can cripple office systems very quickly resulting in lost revenue and consumer confidence which can affect the way that stocks in that company are traded resulting in even further financial losses. That is why it is so important for larger businesses to have comprehensive computer virus protection programs in place.

These virus programs are much more detailed and powerful than the anti-virus programs that many consumers have protecting their computer systems. Because the fallout from a virus attack is much more financially damaging to a large corporation, the virus protection program needs to be much more robust and capable of protecting multiple systems within the corporation. Computer viruses are a hot topic among businesses simply because of the way that they can affect the company financially.

Firewall Protection - Why You Need It?

If your house has an alarm system, surveillance cameras, or any type of security equipment to prevent burglars, then you can compare it to a firewall. A firewall will monitor and limit connections to your computer from the internet and other users. A computer without a firewall is defenseless, and makes it easier for hackers or unwanted programs to invade your computer. There are two types of firewalls, hardware or software.

Routers are devices that act as hardware firewalls. They prevent other users and unwanted software from entering your network. Routers are not only great for firewalls, but also can be used for sharing and connecting computers to a network. Some people use Network Address Translation (NAT) routers as firewalls, even though NAT routers primary purpose is to share an internet connection with local computers. If you do not have a router firewall, you can use a software firewall that will do the job.

There are many software firewalls out there, but only a few are free. Most of the software firewalls are shareware, trials or subscription. Some free versions only have some features and if you want the full package, you will need to pay. Window XP comes with a decent firewall, but you need to make sure you have Service Pack 2 and the latest updates installed.

You can check to see if your Windows XP firewall is running by clicking Start / Control Panel / Windows Firewall, or another way is My Computer / Control Panel / Network Connections / Right click your "Local Area Network" and click properties / Click on the Advance tab then click Settings. You can click to turn your windows firewall on or off.

Software firewalls can be very complex as they contain several features. Some of the features are antivirus and antispyware, program control, e-mail protection and privacy control. These features help boost your protection for your computer, since a firewall alone cannot do everything. A disadvantage of having a software firewall instead of a hardware firewall is that it will use your computer's resources to function. Make sure you have enough memory to prevent your system from crashing. Software firewalls can manage inbound and outbound traffic by placing policies or rules. These policies will allow or reject your programs from accessing the internet, and prevent any unwanted internet programs from invading your computer. These policies are at the owners control and may change any setting as they wish.

Firewalls may give the user increased security by protecting your computer from hackers, as opposed to having no firewall. Hackers will try anything to get into your computer by searching through your computer's ports. Your computer has many ports. They are used to connect to the internet, but sometimes they are left open. Hackers can send a virus or spyware to these ports, and take control of your computer. To prevent this from happening, a firewall will make sure all unused ports are closed.

If you plan to access the internet without a firewall, it is like putting your hand in a beehive. The risk of you being stung are high, and it is the same risk for your computer to be hacked. Without a firewall your ports will be opened, and make it vulnerable for hackers. Therefore, choose a proper firewall that suits your needs

11 Ways to Prevent Computer Viruses

It doesn’t matter if you’ve been on the Internet for five minutes or five years, you’ve probably thought about ways in which you can prevent a computer virus from entering your machine. A virus can compromise your personal information and even destroy your computer completely. Luckily, there are many low cost things you can do to protect yourself and stay one step ahead of the hackers. Here are 11 things you can do to help prevent computer viruses from invading your computer.

1. Install a reliable anti virus program – From the first moment you turn your computer on, you should have a trusted anti virus program by your side. Even if you have a machine that isn’t hooked up to the Internet, a reliable anti virus program is a low cost and common sense addition to any machine. There are even free anti virus programs you can download that work almost as well as industry giants like Norton and McAfee.

2. Install anti-spyware and anti-malware programs – As good as the best anti virus programs are, they sometimes need a little bit of help. Thankfully, many of the top anti-spyware programs are completely free. Spybot Search and Destroy and CCleaner are just two free programs that can help prevent computer viruses from doing any damage on your machine. As helpful as these programs are, however, you must update them and run them on a regular basis for them to do any good.

3. Avoid suspicious websites – A good virus protection program will alert you when you visit a website that attempts to install or run a program on your computer. Many less than reputable adult websites do this, so if you get a warning, don’t go back, you may end up with a bug you can’t get rid of.

4. Never Open Email Attachments Without Scanning Them First – The most common way viruses are spread throughout the Internet is still via email. Some attachments, like pictures, now display in emails and don’t require an attachment to be manually opened, but other documents do. Make sure you use an email client that scans all email attachments before you are allowed to open them. This will help prevent computer viruses from getting a foothold on your machine.

5. Set up Automatic Scans – Many of the top anti virus programs, as well as the best anti-spyware programs, now have settings that will let them automatically run during down times or in the middle of the night. Of course, your computer must be on for this to happen, but having daily scans run when nothing else is going on is a great way to prevent even the latest computer viruses from sticking around too long.

6. Watch Your Downloads – Part of the fun of the Internet is downloading music, movies and other items. However, since these downloads are so massive, it can be easy to sneak a virus along for the ride. Only download these files from trusted sites that you can count on, or, at the very least, scan them before you open them.

7. Updates, Updates, Updates – There is a reason why Windows has a feature called Critical Updates. There is an entire branch of Microsoft dedicated to staying one step ahead of the hackers out there so when they manage to fix a possible security loophole, you need to download the patch right away. Help Microsoft help you prevent computer viruses from causing too much trouble.

8. Know What To Look For – Even if you are just a casual computer user, you should have an idea of how your machine operates, what normal pop up windows look like and what popular viruses are out there, that way, when your computer begins exhibiting tell tale signs, you’ll know. You can help prevent computer viruses by staying updated and educated.

9. Stay Away From Cracked Software – It is so secret that you can download illegal, cracked versions of some programs online. As tempting as it may be, these files are almost always infested with advanced and difficult to detect bugs. Play it safe and get your software from the source.

10. Install a Firewall – A firewall is a program that screens incoming Internet and network traffic. Along with your virus program, it can help prevent unauthorized access to your computer.

11. Be prepared to Lock Down – If you hear of a virus that is spreading like wildfire through the Internet, make an extra effort to be careful. Don’t open any suspicious emails or accept any downloads for a week or two until your virus protection program has been updated and you are, once again, safe.

Internet Viruses Can Target Your Computer

No matter who you talk to, everyone has either had a computer virus or knows of someone who has gone through the agony of trying to get rid of the problem. Computer viruses are a hot topic that seem to affect everyone who owns a computer system, whether at work or at home.

The companies that produce software programs that catch and delete these computer viruses are constantly updating their databases for virus types and definitions so that they can better protect your system against all the newest viruses. Creating virus protection programs is a multi-billion dollar business that is growing more and more everyday.

The number of viruses being created and uploaded to the Internet is growing at an astounding rate of a new one every eighteen seconds! This definitely keeps the virus protection companies on their toes with research and development.

Because these viruses copy themselves to any computer system they come in contact with, the spread of viruses throughout a computer network or the Internet is a very fast and deadly thing to happen to your computer. Because computer viruses are a hot topic, they routinely are the subject of magazine articles and forum topics online. While some viruses do nothing more than frustrate you with pop-up ads or other messages, others are completely malicious and set out from the start to destroy the files and operating systems of your computer.

Of the 53,000 viruses that have been identified and classed, more than 80 percent of them have been classed as malicious and capable of harming your computer system or data files. These computer viruses behave in much the same way as biological viruses by contaminating any computer systems they come in contact with. These self-executing programs are generally very small and work at damaging the way your computer works or by damaging or completely removing key system files.

When computer viruses are a hot topic, more and more people find out about the destructive power of these programs. In this way a great many people find out about virus protection programs and rush out to get the newest protection programs or they ensure that their computer virus protection is up to date. Many magazine and news articles about computer viruses have the effect of sometimes panicking people into believing that their computers are at risk. Having a good anti-virus program and current updates is one of the best ways to protect your computer system against virus attacks.

This must also be coupled with good file habits such as scanning all downloaded files with the anti-virus program before opening them. It is always a good idea to take the time to ensure that the file you thought you were downloading is indeed the file you have. For instance, a file that labels itself as a movie file and is less than one megabyte in size is not a movie file. Movie files are generally nearly a thousand times that size and therefore, the file you have downloaded is most likely not a movie file and may in fact be a computer virus.

Computer viruses are a hot topic at the office when a virus attack manages to get past protection protocols put in place by the network administrators. All it takes is one person allowing some executable files they have been sent to open and start replicating itself through the network of computers to make life Hell for that company. Virus attacks can cripple office systems very quickly resulting in lost revenue and consumer confidence which can affect the way that stocks in that company are traded resulting in even further financial losses. That is why it is so important for larger businesses to have comprehensive computer virus protection programs in place.

These virus programs are much more detailed and powerful than the anti-virus programs that many consumers have protecting their computer systems. Because the fallout from a virus attack is much more financially damaging to a large corporation, the virus protection program needs to be much more robust and capable of protecting multiple systems within the corporation. Computer viruses are a hot topic among businesses simply because of the way that they can affect the company financially.

Is Free Antivirus Software Worth It?

If you are planning on hooking up your computer to a network or to the Internet, an anti virus protection program is an absolute must. Along with a firewall, these two programs are the only real line of defense you have against hackers, viruses and other problems that can plague Internet users.

The world of anti virus software is divided up into two main categories: programs that you pay for, such as BitDefender and Kaspersky and ones you can download for free. While having free anti virus software is significantly better than no protection at all, the time tested versions like BitDefender and Kaspersky are better in every respect. Let’s take a look at just a few of the ways in which store-bought virus protection is superior to free anti virus software.

When it comes to solid anti virus protection, the key lies in the support that backs the program up, and no one has better support than industry leaders like BitDefender and Kaspersky. They have huge staffs that work year round refining and updating their product so that users are always safe and sound from hackers and viruses. Although the free anti virus software that is available for download does an admirable job trying to keep the public safe, it simply doesn’t have the manpower or the resources behind it to provide the continually updated protection an avid Internet user needs. Again, the protection provided is better than nothing, but you should go with the store bought versions if you can.

Along with more regular updates, programs like BitDefender and Kaspersky can afford to provide around the clock tech support to help you if your computer should become infected. As hard as the free programs out there try, the best you can expect is an email response to your problem in a day or two, and that’s a best case outcome. Many free anti virus software programs don’t offer any tech support at all. It is up to you, the user, to figure out what to do. Even if you consider yourself a computer expert, chances are, at one time or another, you are going to run into a problem you need help with and if you go with one of the major free anti virus software programs, you won’t be able to get any help at all.

Finally, most free anti virus software programs are extremely slow when it comes to scanning your computer and fixing problems it finds. One of the major knocks against Norton Anti Virus, probably the most popular anti virus program on the market today, is that the system scans were too slow. Thankfully, this problem has been fixed Norton now performs better than it used to (depending upon the speed of the computer it it running on of course). Most of the free anti virus software programs out there, on the other hand, are not. In addition, many of these free programs are also resource hogs that eat up your free memory so that you can’t really do much else while it is running.

When you compare the two products side by side, it is easy to see that store bought anti virus programs are far superior to their free counterparts. That is not to say that traditional powerhouses like Norton and McAfee are inexpensive or without flaw, but if you are serious about keeping your new computer safe and sound, there really is no other way to go.

What are XP and Vista Rootkits?

With every new year comes a new batch of malicious computer viruses for us to all be aware of. One of the most common types of viruses are known as XP and Vista rootkits. These viruses allow a third party user to take control of your computer. They can either edit or embed themselves in your operating system and allow someone else to become the root user, or the administrator of your computer. This gives them the ability to look for personal information such as credit card numbers or it can allow them to haphazardly delete information you need. Let’s take a closer look at what rootkits are, how you may end up with one and how to get rid of one once you have it.

The origins of XP and Vista rootkits are somewhat unknown. It is thought that these programs came from the designers of the operating systems themselves. They were used as a way for tech support people to gain remote access over computers that needed help. Even today’s XP and Vista machines come with a program that, with administrative access, can give control of your entire computer to another person at a remote location. It was once these programs became hacked that rootkits started to cause problems.

Rootkits can be acquired in any number of ways. The most popular form of transmission is still via email. The virus can be attached to an email or embedded in an otherwise normal attachment. Windows rootkits are also commonly transmitted throughout the Internet and can be installed on computers that don’t use firewalls. Hackers can use programs that search online networks for computers that are vulnerable. This is why it is so important to always have up to date firewall and anti virus programs on your machine at all times.

One of the most common places that XP and Vista rootkits hide themselves is in firmware. Firmware is the software that peripherals that you attach to your computer use to operate. Once in a while, firmware updates will become available for items like your router or your video card or sound card. If these files are infected, it can be extremely difficult to remove the bug since most virus programs don’t bother scanning firmware. In the future, never download firmware updates for any of your peripherals from any third party sites. Either download the updates from the manufacturer’s website or from the website of your computer’s manufacturer.

Removing XP and Vista rootkits isn’t as difficult as it sounds, assuming your computer is prepared. You should always have up to date anti virus software installed and running at all times. Shutting down your anti virus programs, even for a moment, can open your machine up to an attack. The same goes for your firewall. In most cases, these programs should detect rootkits as they are installed so you can authorize your virus protection to fix the problem.

Be Aware of Phishing Scams

surf the web, purchase products over the web or use the many financial services offered by your credit card company, bank and even Paypal and Ebay, then you should be aware of Phishing scams and how they can affect you personally.

Phishing scams is when hackers or criminals masquerade as a legitimate entities in order to steal sensitive information such as credit card numbers, social security numbers, etc to commit fraud. Phishing scams are numerous on the web and can affect almost anyone. Here are some tips to easily spot phishing scams and what to do if you think your information has been compromised.

How to Spot Phishing Scams A vast majority of phishing scams come in the form of email. Emails are sent to possibly millions of people stating that they are from a legitimate entity such as American Express, Chase Bank, Ebay, Paypal, etc. The email itself looks very convincing (in fact, it is usually an exact copy of official emails sent). Within the email it will usually state that your account information is not up to date and not updating this information could jeopardize your account. It will usually give you a hyperlink to click on to update your account information which will usually ask you for your full name, address, social security number and account number. Once you have given all your sensitive information to this web site, the hacker or criminal organization can now use this info to make purchase online using your credit card information, open up loans using your info and literally steal money from your bank account.

Three ways to spot phishing scams are to make sure that the email is addressed directly to you. Inside the email itself, it should state your full name. If it says "Dear member" or "Dear customer" it probably is a phishing scam. Secondly, the email that you receive the message should be the one that you have given to the company. If you have five email address and use only one email address for all your finance related business, any emails you receive on your other email addresses are probably phishing scams. Thirdly, the vast majority of financial companies will never ask you for your account information or other sensitive info through an email.

An Easy Way to Thwart All Phishing Scams Whether you think an email is legitimate or not, never click on any hyperlink within the email, instead, simply open up a new browser window, type in the financial company's address and log into your account. If your account requires any kind of update, it will state it. Usually, most companies will send you a letter in the mail or call you directly if there is some kind of issue.

HOW TO DETERMINE FAKE MAIL OR FISHING MAIL

Find the link they are trying to get you to click, without clicking on the link highlight over it, and look in the lower left hand corner of the email window. It should show a URL. If the URL does not begin with:

http://www.[domain].com

...where [domain] is the domain of company in which the email is about. So in this example, paypal is the domain - so the URL must begin with http://www.paypal.com. If it has anything else after the http://. IT IS A SCAM! Do not even click it.

Some email programs will not show the URL in the lower left of the window, so you can either take a chance and click the link, hoping that it's not linking to a virus script or play it safe and install antivirus software. Most popular antivirus programs have anti-phishing capabilities built in to detect these sites for you and warn you in advance. If you want to see who we recommend for antivirus software,

Be careful when you receive any email that talks about your account or recent security issues. Also, these scams usually imitate large, popular sites such as Paypal, Ebay, some large banks, etc... If you ever fall for one of these scams, and someone gets ahold of your account information, you could have some major headaches down the road.

Guardian Jobs website hacked

The UK jobs website, Guardian Jobs, was hacked last night leaving a proportion of users data exposed. The Metropolitan Police areGuardian Jobs investigating and for anyone that has been affected has been emailed with details and advise.

The Guardian have confirmed to TNW that the US site, guardianjobs.com, has not been affected and is independent of the UK operation. The data is held on separate databases run by the third parties that operate the sites for the Guardian, Madgex and Indeed. In the UK, it’s run by Madgex and according to the Guardian, steps have been put in place to make sure a recurrence doesn’t happen.

We learned yesterday evening that the Guardian Jobs website has been targeted by a sophisticated and deliberate hack, which has breached the security of the data on the site. You have used the site to make one or more job applications and we believe your personal data, relating to those applications, may have been accessed.

The supplier who runs the site has identified the manner in which it was hacked and taken steps to prevent a recurrence.

Back in March, the Guardian Jobs UK passed the 2 million user figure mark, and with those users data compromised, it puts them at considerable risk of identity theft, including myself. The metropolitan police have recommended the following, for users who haven’t recieved their email as yet:

1) Contact your creditors, even if they have not been affected, so that they can monitor your accounts to ensure they remain protected.

2) Contact a credit reference agency: Callcredit, Equifax or Experian provide suggested steps to resolve the situation and prevent it happening again.

3) Contact CIFAS protective registration: If you think you have been a victim of identity theft you should consider subscribing to CIFAS. This places a notice on your credit file indicating that your name and address may be used to perpetrate identity fraud.

The security of websites such as the Guardian Jobs and third parties involved continues to be questioned. It’s increasingly frustrating to hear of these breaches that will undoubtably affect consumer confidence online, in an already economically fragile environment.

If you would like to find out more about this breach, the Guardian have a dedicated page to keep you updated,

Mobile Code Security

With the growth of distributed computer and telecommunications systems, there have been increasing demands to support the concept of "mobile code", sourced from remote, possibly untrusted, systems, but executed locally. The best known examples of this are WWW applets, but it also is manifest in dynamic email, and more recently, in supporting third party suppliers in the emerging Telecommunications Information Networking Architecture (TINA). Supporting mobile code introduces a number of serious security and safety issues that must be addressed. This paper will introduce some of these issues, and outline some of the proposed solution approaches, as utilised in languages such as Safe-TCL, Java, and Omniware.
Introduction
"Mobile Code" is code sourced from remote, possibly "untrusted" systems, but executed on your local system. Examples include: web applets, dynamic email, and TINA building blocks.

The concept of "mobile code" has been called by many names: mobile agents, mobile code, downloadable code, executable content, active capsules, remote code, and others. All these deal with the local execution of remotely sourced code.
Mobile Code Examples
Examples of mobile code include:

Web Applets
Mini-programs written in Java, which are automatically loaded & run on being named in an HTML document. A document can include a number of applets, and these may be sourced from a number of different servers, and run virtually without the user being aware of them.
Dynamic Email
One proposal for the provision of dynamic email suggested incorporating Safe-TCL scripts as components of MIME email. These scripts could be run either on mail delivery, or when the mail is read by the recipient.
TINA Building Blocks
The evolving "Telecommunications Information Networking Architecture" (see NDC95) includes support for 3rd party service providers who can supply TINA Building Blocks (objects), which can manipulate network resources in order to provide value added services to clients. An outline of some of the security and safety issues is given in Shah96.

All of these examples illustrate that the use of mobile code will raise of number of serious security and safety issues. This paper will outline some general approaches to, and specific examples of, "safe" systems. I finish by mentioning some flaws which have been found in existing systems, in order to derive some lessons for future designs.
Low-level Security Issues
The use of "mobile code" raises a number of obvious security issues:

* access control -- is the use of this code permitted
* user authentication -- to identify valid users
* data integrity -- to ensure the code is delivered intact
* non-repudiation -- of use of the code, for both the sender and the receiver, especially if its use is being charged
* data confidentiality -- to protect sensitive code
* auditing -- to trace uses of mobile code

Techniques for providing these security services are well known. Their provision is not a technical problem, but rather a political and economic one. It involves the use of cryptographic extensions to communications protocols. These are well described in the OSI Security Framework, the ISO 10181 and CCITT X.810-X.816 standards, in the IETF IP-SEC proposals, and the Secure Web protocols.

Clearly a system which supports "mobile code" will need to provide these services. Before too long, I believe we will see them. A more interesting question, though, is how to address the issue of how to safely execute the code once it is validly and correctly delivered to the end-user's system.
Mobile Code Safety
The prime focus of this paper is on the techniques which can be used to provide for the safe execution of imported code on the local system. This has to address threats due to rogue code being loaded and run. Of course in many ways, these problems are not new: they have been a key component of operating systems design on multi-user systems for many years. The traditional approach to addressing these problems has been to use heavy address space protection mechanisms, along with user access rights to the file system and other resources. The difference between the traditional problems, and those posed by mobile code, is one of volume and responsiveness. Mobile code is intended for quick, lightweight execution, which conflicts with the cost of heavy address space mechanisms in most current operating systems. Also, each mobile code unit can, in one sense, be thought of as running as its own unique user, to provide protection between the various mobile code units and the system. Traditional methods of adding new users cannot cope with this demand.

The types of attacks which need to be guarded against include:

* denial of service
* disclosure of confidential information
* damage or modification of data
* annoyance attacks

Some example scenarios which can be imagined include: a Video-on-Demand service which discretely scans local files for information; An online game which opens a covert connection to run programs locally; an Invisible program that captures system activity information.
Resource Access & Safety
Fundamentally, the issue of safe execution of code comes down to a concern with access to system resources. Any running program has to access system resources in order to perform its task. Traditionally, that access has been to all normal user resources. "Mobile Code" must have restricted access to resources for safety. However, it must be allowed some access in order to perform its required functions. Just which types of access, and how these are to be controlled, is a key research issue. The types of resources to which access is required include:

* file system
* network
* random memory
* output devices (entire display, various windows, speaker ...)
* input devices (keyboard, mic ...)
* process control (access to CPU cycles)
* user environment
* system calls

Language Support for Safety
When considering means of providing safe execution, if heavy address space protection mechanisms are not being used, then considerable reliance is going to be placed on the verified use of type-safe programming languages. These ensure that arrays stay in bounds, that pointers are always valid, and that code cannot violate variable typing (such as placing code in a string and then executing it). These features are needed to ensure that various code units do not interfere with each other, and with the system.

If type-safe languages are being used, we want assurance of the type-system's soundness and safety, want validation of type-checking implementations, and of course, all without compromising efficiency.

In addition, a range of usual sound programming proceedures need to be followed. The system should be designed in a modular fashion, separating interfaces from implementations in programs, and with appropriate layering of libraries and module groups, with particular care being taken at the interfaces between security boundaries.

One general approach to designing "safe" execution evironments is to remove general library routines which could compromise security, and replace them with more specific, safer ones, eg. replace a general file access routine with one that can write files only in a temporary directory.

Great care is needed with this approach to ensure that unforeseen interactions or implementation flaws do not negate the desired security. This has been an area where failures have occured on a number of occasions.
Granting Access to Resources
One of the key issues in providing for safe execution of "mobile code" is determining exactly which resources a particular code unit is to be granted access to. That is, there is a need for a security policy which determines what type access any "mobile code" unit has. This policy may be:

fixed for all "mobile code" units
very restrictive but easy, and the approach currently used to handle applet security in web browsers such as Netscape.
user verifies each security related access requests
relatively easy, but rapidly gets annoying, and eventually is self-defeating when users stop taking notice of the details of the requests. Whilst there is a place for querying the user, it should be used exceedingly sparingly.
negotiate for each "mobile code" unit
much harder, as some basis is needed for negotiation, perhaps based on various profiles, but ultimately this is likely to be the best approach.

In the longer term, some mechanisms are needed to permit negotiation of appropriate accesses. How this is expressed is, I believe, one of the key research issues. Initially this is likely to be based on a simple tabular approach, based on the various categories mentioned above. While adequate for the simplistic applets seen to date, this is unlikely to be sufficient for more complex "mobile code" applications. For these, some faily powerful language is going to be needed to express the required types of accesses, along with a means of reasoning about those requests. For example, consider a simple "mobile code" text-editor -- it should be able to change any textual file specified by the user, have access perhaps to a preferences file, but otherwise be denied access to all other files. How can this be expressed and reasoned with? This is an area that needs considerable additional work, but will be a key to the successful use of "mobile code".
Mobile Code Technologies
Having considered some of the issues raised by the need for "safe" execution of "mobile code", I will now summarise some approaches that have been tried. One method of categorising "mobile code" technologies, given in TW96, is based on the type of code distributed:

* Source Code
* Intermediate Code
* Platform-dependent Binary Code
* Just-in-time compilation

Source Code
The first approach is based on distributing the source for the "mobile code" unit used. This source will be parsed and executed by an interpreter on the user's system. The interpreter is responsible for vetting source to ensure it obeys the required language syntactic and semantic restrictions; and then for providing a safe execution "sand-box" environment. The safety of this approach relies on the correct specification and implementation of the interpreter.

The main advantages of the source code approach is the distribution of relatively small amounts of code; the fact that since the user has the full source, it is easier to vet the code; and that it is easier for the interpreter to contain the execution environment.

Disadvantages include the fact that it is slow, since the source must first be parsed; and that it is hard to expand the core functionality, since the interpreter's design limits this.
Programmable MUDs
One early example which included aspects of "mobile code" were some of the MUDs which were programmable (see Bro93) eg MUCK, MOO, UberMUD. These systems could execute source authored by arbitrary users anywhere in the world, manually transferred to the MUD system, and subsequently executed in the MUD interpreter environment. Safeguards were provided by the fact that the MUD interpreter had no other access to host system apart from the single MUD database file. However, any MUD program had full access (as the running user) to MUD data. One limitation was that users needed explicit permission to author code: once granted however, they were trusted not to abuse the privilege.

These systems are early illustrations of some of the concepts: the use of a "sand-box" interpreter, and restrictions on the source of code.
Safe-TCL
The most widespread and common example of the source code approach is Safe-TCL, a subset of the TCL language with restricted features for safety. TCL was designed by John Ousterhout as a simple, clean, interpreted, embeddable command language, with graphical toolkit (Tk) (see Ous94). Safe-TCL is restricted by having limited file system access, and is prevented from executing arbitrary system commands. Safe-TCL code is usually executed by the "untrusted interpreter" (that is the interpreter which executes code from an untrusted source). A key component of the Safe-TCL system is the provision of another "trusted interpreter" (which executes code from a trusted source). Trusted code can be used to extend the capabilities of the Safe-TCL system. Such extension code can be invoked by any code running on the "untrusted interpreter", but the extension code uses the "trusted interpreter". This provides a clean mechanism for extending the system.

Safe-TCL was designed by Nathaniel Borenstein and Marshall Rose as a means of augmenting email to include active messages, termed "Dynamic Email" (see Bor94). With the addition of new MIME types: application/safe-tcl and multipart/enabled-mail, Safe-TCL programs could be incorporated into email messages, and executed either on delivery or access by the recipient. The concepts in Safe-TCL were subsequently adopted by the Tcl group, and are now incorporated as standard in the latest Tcl/Tk releases.

More recently, Safe-TCL has been adapted for use on the web to execute "Tclets" -- Safe-TCL code downloaded by a web browser and executed by an interpreter on the user's system (see Tclet96). It is currently handled by a plug-in on common browsers such as Netscape (see Lev96). Safe-TCL has also been extensively used in the First Virtual Internet payment system.
JavaScript
JavaScript is a source-level scripting language, which is embedded in an HTML document. It is NOT Java! It is interpreted by the user's web browser, and allows control over most of the features of the web browsers. It has access to most of the content of its HTML document, and has full interaction with the displayed content. It can access Java methods (& vica versa), providing access to features not present as standard in JavaScript. Currently there is only a very coarse level of security management: it is either enabled or disabled. Its security features are not yet well documented.
Intermediate Code
A second approach to providing "mobile code" is to have the programs compiled to a platform-independent intermediate code, which is then distributed to the user's system. This intermediate code is executed by an interpreter on the user's system.

Advantages are that it is faster to interprete than source, since no textual parsing is required, and the intermediate code is semantically much closer to machine code. The interpreter provides a safe execution "sand-box", and again, the safety of the system depends on the interpreter. The code in general is quite small, and the user's system can vet the code to ensure it obeys the safety restrictions. Disadvantages of this approach are its moderate speed, since an interpreter is still being used, and the fact that less semantic information is available to assist in vetting the code than if source was available.
JAVA
Probably the best known intermediate code technology today is Java. It is Sun Microsystems' "executable content" technology, using an interpreted, dynamic, type-safe object-oriented language (see GM95). Its safety features include the use of runtime bytecode verification, late dynamic binding of modules, automatic memory management, and exception processing. Considerable effort has gone in to ensuring its safety in design and implementation. This safety is, however, dependent on the correct specification and implementation of both the verifier/interpreter AND the standard library implementation (esp. SecurityManager). Failures in these areas have led to some security flaws, as described later.
Telescript
Telescript is a technology for creating distributed applications using "mobile agents" (see Tar95). A key difference between Telescript and Java is that a Telescript "mobile agent" is a migrating process that is able to autonomously transfer its execution to a different system by asking to "go" elsewhere. Like Java, it is an interpreted, dynamic, type-safe object-oriented language, compiled to an intermediate code, with runtime type checking and late dynamic binding, automatic memory management, and exception processing. Additional features include object persistence and remote access, enabling objects to access each other over the network. Because of its migratory and remote access features, authentication and protection features are integral. Currently, Telescript is also supported via Netscape plugins for web applications, as well as using dedicated interpreters for other distributed applications.
Native Binary Code
The final category of code distribution uses native binary code, which is then executed on the user's system. This gives the maximum speed, but means that the code is platform dependent. Safe execution of binary code requires:

* restricted use of instruction set
* restricted address space access

Approaches to ensuring this can rely upon:

* tradional heavy address space protection, which is costly in terms of system performance and support;
* the verified use of a trusted compiler, which guarantees to generate safe code that will not violate the security restrictions;
* the use of "software fault isolation" technologies (see WLAG93) which augment the instruction stream, inserting additional checks to ensure safe execution (Ste92).

A combination of verified use of a trusted compiler, and the software fault isolation approach has created considerable interest, especially when used with a Just-in-time Compiler.
Just-in-time Compilation
Just-in-time Compilation (JIT) is an approach that combines the portability of intermediate or source code with the speed of binary code. The source or intermediate code is distributed, but is then compiled to binary on the user's system before being executed. If source is used, it is slower, but easier to check. If intermediate code is used, then it is faster. Another advantage is that the user can utilise their own trusted compiler to verify code, and insert the desired software fault isolation run-time checks.

This approach is being used with Java JIT compilers, and also in the Omniware system.
Omniware
Omniware is yet another technology for "mobile code" (see LSW95). Omniware code is written in C++, which is then compiled to an intermediate code for the OmniVM. This is distributed, and at run-time is translated to native code for execution. It relies on "software fault isolation" techniques to enforce safe execution of binaries. This adds special checking code which emulates a MMU in software, placing each module in its own protection domain. The run-time environment vets access to resources. The major advantages claimed for Omniware are that it uses a standard, well known language, C++, that it is fast, since binary code is actually being executed, and yet it is safe, due to the use of the "software fault isolation" techniques.
Theory vs Practice
There are a number of good proposals for providing safe execution of "mobile code". However, some flaws have been found in practice. Most of the recent effort has focused on Java (see below), although the researchers believe that other systems would be likely to have similar flaws if they were as closely scrutinised. By examining the flaws found, some lessons may be drawn to assist with future designs.
Java Implementation Flaws
A number of implementation flaws have been found in the Java system (see DFW96, Ban95, Yel95). These include:

* Problems with network security, mostly created using DNS spoofing to subvert the interpreter's view of the domain namespace, and subsequently to violate the restriction on opening connections only back to the source of the Java code.
* There were some early problems with buffer overflows in sprintf in the original JDKs. These have mostly been fixed, except in javap (where care is still needed).
* Some of the standard routines provide information about the layout of storage for objects. This is probably not a serious flaw, but more information is revealed than is perhaps necessary.
* In HotJava, the proxy variables were public, which meant that any Java program could change them, and thus redirect all requests from the user's browser.
* There are some problems with inter-applet security. Applets are supposed to be quarantined from each other. However, using the thread manager, an applet can discover which other applets have running threads, control attributes of these threads, and even discover the applets names (since these are encoded in the thread names).

All of these flaws can be corrected by changes to the standard Java run-time environment: many have already been made.
Java Language vs Bytecodes
More serious are some deficiencies in the design of the Java language itself, or more correctly, in differing semantics between the Java language, and the bytecodes of the Java Virtual Machine (JVM) to which the language is compiled. DFW96 have identified two significant flaws.

The first, and most serious, relates to superclass constructors. Whenever an object is created, a constructor is called for it. These constructors are required to call the constructor for the super (parent) class first. Unfortunately the Java language prohibits, but the bytecode verifier allows, the creation of a partially initialised class loader, which can then be used to thwart some of the security checks on object creation, and to violate the strong typing of objects. DFW96 have found by using this attack, they can get and set the value of any non-static variable, and call any method (including native methods with fewer security restrictions).

The second flaw identified relates to the Java package names. Again the bytecode verifier allows a leading "/" on package names, which is interpreted by the run-time system as an absolute pathname to some package. Since the package is on the local system, it is regarded as trusted code. If a user is running Java on a system that allows any other type of network file access (eg FTP server with an incoming directory), then that can be used to place code on the system which can then be executed by the user's Java interpreter.

Also identified were some problems with object initialisation, where object constructors are working with partially initialised objects.

All of these suggest that some further work is needed on the design of the Java language, and particularly on its relation to the JVM bytecodes.
Security Failure Lessons
Experience with systems (esp. Java) have highlighted some dangers, showing that failures can occur in both the implementation and the specification of the system. Correct specification does not prevent poor implementation, weakening its security. Great care is needed. Ideally it should be possible to formally verify the language design, and then validate its implementation. In practise, this is unlikely to be possible for some time. Some of the methods and procedures used in the IT Security Evaluation community may, however, assist in the creation of more reliable systems.
Conclusions
"Mobile code" is here with increasing demands for its use. Safe execution of "mobile code" implies a need for controlled access to resources, access which ideally should be negotiated for each "mobile code" unit. The means for achieving this is a subject for considerable additional research.

Approaches taken so far to providing "mobile code" include the distribution of: source, intermediate code, or binary code, and the use of Just-In-Time compilers.

Experience with these systems has shown that safe and secure systems need both correct specification and implementation. There is still considerable research and development needed in these systems. However I believe the goal of safe and secure "mobile code" execution is reasonable and achievable.