When you study computer and information technology, you will gain skills that can help solve problems in a variety of industries, such as business, manufacturing, law enforcement or healthcare. As more data and information become accessible from individual computers and across networks, the need for information technology experts will continue to grow. You can learn how to plan, analyze, design, build, maintain and manage projects. Professors and projects will expose you to software development, systems integration, data management and computer networks.Information technology (IT) is the acquisition, processing, storage and dissemination of vocal, pictorial, textual and numerical information by a microelectronics-based combination of computing and telecommunications.[1] The term in its modern sense first appeared in a 1958 article published in the Harvard Business Review, in which authors Leavitt and Whisler commented that "the new technology does not yet have a single established name. We shall call it information technology IT spans wide variety of areas that include but are not limited to things such as processes, computer software, computer hardware, programming languages, and data constructs. In short, anything that renders data, information or perceived knowledge in any visual format whatsoever, via any multimedia distribution mechanism, is considered part of the domain space known as Information Technology (IT).
IT professionals perform a variety of functions (IT Disciplines/Competencies) that range from installing applications to designing complex computer networks and information databases. A few of the duties that IT professionals perform may include data management, networking, engineering computer hardware, database and software design, as well as management and administration of entire systems. Information technology is starting to spread farther than the conventional personal computer and network technology, and more into integrations of other technologies such as the use of cell phones, televisions, automobiles, and more, which is increasing the demand for such jobs.IT spans wide variety of areas that include but are not limited to things such as processes, computer software, computer hardware, programming languages, and data constructs. In short, anything that renders data, information or perceived knowledge in any visual format whatsoever, via any multimedia distribution mechanism, is considered part of the domain space known as Information Technology (IT).
Learning and Teaching Information Technology
Computer Skills in Context
There is clear and widespread agreement among the public and educators that all students need to be proficient computer users or "computer literate." However, while districts are spending a great deal of money on technology, there seems to be only a vague notion of what computer literacy really means. Can the student who operates a computer well enough to play a game, send e-mail or surf the Web be considered computer literate? Will a student who uses computers in school only for running tutorials or an integrated learning system have the skills necessary to survive in our society? Will the ability to do basic word processing be sufficient for students entering the workplace or post-secondary education?
Clearly not. In too many schools, teachers and students still use computers only as the equivalent of expensive flash cards, electronic worksheets, or as little more than a typewriter. The productivity side of computer use in the general content area curriculum is neglected or grossly underdeveloped (Moursund, 1995).
Recent publications by educational associations are advocating for a more meaningful use of technology in schools (ISTE, 2000). Educational technologists are clearly describing what students should know and be able to do with technology. They are advocating integrating computer skills into the content areas, proclaiming that computer skills should not be taught in isolation and that separate "computer classes" do not really help students learn to apply computer skills in meaningful ways. There is increasing recognition that the end result of computer literacy is not knowing how to operate computers, but to use technology as a tool for organization, communication, research, and problem solving. This is an important shift in approach and emphasis.
Moving from teaching isolated technology skills to an integrated approach is an important step that takes a great deal of planning and effort. Fortunately, we have a model for doing so. Over the past 25 years, library media professionals have worked hard to move from teaching isolated "library skills" to teaching integrated "information skills." They found that information skills can be integrated effectively when the skills (1) directly relate to the content area curriculum and to classroom assignments, and (2) are tied together in a logical and systematic information process model.
Schools seeking to move from isolated information technology skills instruction will also need to focus on both of these requirements. Successful integrated information skills programs are designed around collaborative projects jointly planned and taught by teachers and library media professionals. Information technology skills instruction can and should be imbedded in such a curriculum. Library media specialists, computer teachers, and classroom teachers need to work together to develop units and lessons that will include both technology skills, information skills, and content-area curriculum outcomes.
A meaningful, unified information technology literacy curriculum must be more than a "laundry list" of isolated skills, such as knowing the parts of the computer, writing drafts and final products with a word processor, and searching for information using the World Wide Web.
While these specific skills are important for students to learn, the "laundry list" approach does not provide an adequate model for students to transfer and apply skills from situation to situation. These curricula address the "how" of computer use, but rarely the "when" or "why." Students may learn isolated skills and tools, but they would still lack an understanding of how those various skills fit together to solve problems and complete tasks. Students need to be able to use computers and other technologies flexibly, creatively and purposefully. All learners should be able to recognize what they need to accomplish, determine whether a computer will help them to do so, and then be able to use the computer as part of the process of accomplishing their task. Individual computer skills take on a new meaning when they are integrated within this type of information problem-solving process, and students develop true "information technology literacy" because they have genuinely applied various information technology skills as part of the learning process.
The curriculum outlined on pages 2-3 of this ERIC Digest, "Technology Skills for Information Problem Solving," demonstrates how technology literacy skills can fit within an information literacy skills context (American Association of School Librarians, 1998). The baseline information literacy context is the Big6 process (see sidebar and Eisenberg & Berkowitz, 1988, 1992, 1999, 2000). The various technology skills are adapted from the International Society for Technology in Education's National Educational Technology Standards for Students (2000) and the Mankato Schools Information Literacy Curriculum Guideline. Students might reasonably be expected to authentically demonstrate these basic computer skills before graduation.
Some technology literacy competencies that may be relevant in some situations include: (1) knowing the basic operation, terminology, and maintenance of equipment, (2) knowing how to use computer-assisted instructional programs, (3) having knowledge of the impact of technology on careers, society, and culture (as a direct instructional objective), and (4) computer programming.
Defining and describing technology skills is only a first step in assuring all our children become proficient information and technology users. A teacher-supported scope and sequence of skills, well designed projects, and effective assessments are also critical. Equally essential is collaboration among classroom teachers, teacher librarians, and technology teachers in order to present students with a unified and integrated approach to ensure that all children master the skills they will need to thrive in an information rich future
reference:
1(Eisenberg & Lowe, 1999)http://www.libraryinstruction.com/info-tech.html
2 Wikipedia..
computer and medicine
Tuesday, February 1, 2011
Thursday, January 27, 2011
anti virus
From Wikipedia, the free encyclopedia
Jump to: navigation, search
"Antivirus" redirects here. For antiviral medication, see Antiviral drug.
Antivirus software
SymantecEndpointProtection.jpg
Symantec Endpoint Protection, an example of antivirus software
Antivirus or anti-virus software is used to prevent, detect, and remove computer viruses, worms, and trojan horses. It may also prevent and remove adware, spyware, and other forms of malware. This page talks about the software used for the prevention and removal of such threats, rather than computer security implemented by software methods.
A variety of strategies are typically employed. Signature-based detection involves searching for known patterns of data within executable code. However, it is possible for a computer to be infected with new malware for which no signature is yet known. To counter such so-called zero-day threats, heuristics can be used. One type of heuristic approach, generic signatures, can identify new viruses or variants of existing viruses by looking for known malicious code, or slight variations of such code, in files. Some antivirus software can also predict what a file will do by running it in a sandbox and analyzing what it does to see if it performs any malicious actions.
No matter how useful antivirus software can be, it can sometimes have drawbacks. Antivirus software can impair a computer's performance. Inexperienced users may also have trouble understanding the prompts and decisions that antivirus software presents them with. An incorrect decision may lead to a security breach. If the antivirus software employs heuristic detection, success depends on achieving the right balance between false positives and false negatives. False positives can be as destructive as false negatives. Finally, antivirus software generally runs at the highly trusted kernel level of the operating system, creating a potential avenue of attack.[1]
Contents
[hide]
* 1 History
* 2 Identification methods
o 2.1 Signature based detection
o 2.2 Heuristics
o 2.3 Rootkit detection
* 3 Issues of concern
o 3.1 Unexpected renewal costs
o 3.2 Rogue security applications
o 3.3 Problems caused by false positives
o 3.4 System and interoperability related issues
o 3.5 Effectiveness
o 3.6 New viruses
o 3.7 Rootkits
* 4 Other methods
o 4.1 Cloud antivirus
o 4.2 Network firewall
o 4.3 Online scanning
o 4.4 Specialist tools
* 5 Popularity
* 6 See also
* 7 References
* 8 External links
[edit] History
An example of free antivirus software: ClamTk 3.08.
See also: Timeline of notable computer viruses and worms
Most of the computer viruses written in the early and mid 1980s were limited to self-reproduction and had no specific damage routine built into the code.[2] That changed when more and more programmers became acquainted with virus programming and created viruses that manipulated or even destroyed data on infected computers.
There are competing claims for the innovator of the first antivirus product. Possibly the first publicly documented removal of a computer virus in the wild was performed by Bernd Fix in 1987.[3][4]
Fred Cohen, who published one of the first academic papers on computer viruses in 1984,[5] began to develop strategies for antivirus software in 1988[6] that were picked up and continued by later antivirus software developers.
Also in 1988 a mailing list named VIRUS-L[7] was started on the BITNET/EARN network where new viruses and the possibilities of detecting and eliminating viruses were discussed. Some members of this mailing list like John McAfee or Eugene Kaspersky later founded software companies that developed and sold commercial antivirus software.
Before internet connectivity was widespread, viruses were typically spread by infected floppy disks. Antivirus software came into use, but was updated relatively infrequently. During this time, virus checkers essentially had to check executable files and the boot sectors of floppy disks and hard disks. However, as internet usage became common, viruses began to spread online.[8]
Over the years it has become necessary for antivirus software to check an increasing variety of files, rather than just executables, for several reasons:
* Powerful macros used in word processor applications, such as Microsoft Word, presented a risk. Virus writers could use the macros to write viruses embedded within documents. This meant that computers could now also be at risk from infection by opening documents with hidden attached macros.[9]
* Later email programs, in particular Microsoft's Outlook Express and Outlook, were vulnerable to viruses embedded in the email body itself. A user's computer could be infected by just opening or previewing a message.[10]
As always-on broadband connections became the norm, and more and more viruses were released, it became essential to update virus checkers more and more frequently. Even then, a new zero-day virus could become widespread before antivirus companies released an update to protect against it.
[edit] Identification methods
Malwarebytes' Anti-Malware version 1.46 - a proprietary freeware antimalware product
There are several methods which antivirus software can use to identify malware.
Signature based detection is the most common method. To identify viruses and other malware, antivirus software compares the contents of a file to a dictionary of virus signatures. Because viruses can embed themselves in existing files, the entire file is searched, not just as a whole, but also in pieces.[11]
Heuristic-based detection, like malicious activity detection, can be used to identify unknown viruses.
File emulation is another heuristic approach. File emulation involves executing a program in a virtual environment and logging what actions the program performs. Depending on the actions logged, the antivirus software can determine if the program is malicious or not and then carry out the appropriate disinfection actions.[12]
[edit] Signature based detection
Traditionally, antivirus software heavily relied upon signatures to identify malware. This can be very effective, but cannot defend against malware unless samples have already been obtained and signatures created. Because of this, signature-based approaches are not effective against new, unknown viruses.
As new viruses are being created each day, the signature-based detection approach requires frequent updates of the virus signature dictionary. To assist the antivirus software companies, the software may allow the user to upload new viruses or variants to the company, allowing the virus to be analyzed and the signature added to the dictionary.[11]
Although the signature-based approach can effectively contain virus outbreaks, virus authors have tried to stay a step ahead of such software by writing "oligomorphic", "polymorphic" and, more recently, "metamorphic" viruses, which encrypt parts of themselves or otherwise modify themselves as a method of disguise, so as to not match virus signatures in the dictionary.[13]
[edit] Heuristics
Some more sophisticated antivirus software uses heuristic analysis to identify new malware or variants of known malware.
Many viruses start as a single infection and through either mutation or refinements by other attackers, can grow into dozens of slightly different strains, called variants. Generic detection refers to the detection and removal of multiple threats using a single virus definition.[14]
For example, the Vundo trojan has several family members, depending on the antivirus vendor's classification. Symantec classifies members of the Vundo family into two distinct categories, Trojan.Vundo and Trojan.Vundo.B.[15][16]
While it may be advantageous to identify a specific virus, it can be quicker to detect a virus family through a generic signature or through an inexact match to an existing signature. Virus researchers find common areas that all viruses in a family share uniquely and can thus create a single generic signature. These signatures often contain non-contiguous code, using wildcard characters where differences lie. These wildcards allow the scanner to detect viruses even if they are padded with extra, meaningless code.[17] A detection that uses this method is said to be "heuristic detection."
[edit] Rootkit detection
Main article: Rootkit
Anti-virus software can also scan for rootkits; a rootkit is a type of malware that is designed to gain administrative-level control over a computer system without being detected. Rootkits can change how the operating system functions and in some cases can tamper with the anti-virus program and render it ineffective. Rootkits are also difficult to remove, in some cases requiring a complete re-installation of the operating system.[18][19]
[edit] Issues of concern
[edit] Unexpected renewal costs
Some commercial antivirus software end-user license agreements include a clause that the subscription will be automatically renewed, and the purchaser's credit card automatically billed, at the renewal time without explicit approval. For example, McAfee requires users to unsubscribe at least 60 days before the expiration of the present subscription[20] while BitDefender sends notifications to unsubscribe 30 days before the renewal.[21] Norton Antivirus also renews subscriptions automatically by default.[22]
[edit] Rogue security applications
Main article: Scareware
Some apparent antivirus programs are actually malware masquerading as legitimate software, such as WinFixer and MS Antivirus.[23]
[edit] Problems caused by false positives
A "false positive" is when antivirus software identifies a non-malicious file as a virus. When this happens, it can cause serious problems. For example, if an antivirus program is configured to immediately delete or quarantine infected files, a false positive in a essential file can render the operating system or some applications unusable.[24] In May 2007, a faulty virus signature issued by Symantec mistakenly removed essential operating system files, leaving thousands of PCs unable to boot.[25] Also in May 2007 the executable file required by Pegasus Mail was falsely detected by Norton AntiVirus as being a Trojan and it was automatically removed, preventing Pegasus Mail from running.[26] Norton anti-virus has falsely identified three releases of Pegasus Mail as malware, and would delete the Pegasus Mail installer file when this happens.[27] In response to this Pegasus Mail stated:
“ On the basis that Norton/Symantec has done this for every one of the last three releases of Pegasus Mail, we can only condemn this product as too flawed to use, and recommend in the strongest terms that our users cease using it in favour of alternative, less buggy anti-virus packages.[27] ”
In April 2010 McAfee VirusScan detected svchost.exe, a normal Windows binary, as a virus on machines running Windows XP with Service Pack 3, causing a reboot loop and loss of all network access.[28][29]
In December 2010, a faulty update on the AVG anti-virus suite damaged 64-bit versions of Windows 7, rendering it unable to boot, due to an endless boot loop created.[30]
When Microsoft Windows becomes damaged by faulty anti-virus products, fixing the damage to Microsoft Windows incurs technical support costs and businesses can be forced to close whilst remedial action is undertaken.[31][32]
[edit] System and interoperability related issues
Running multiple antivirus programs concurrently can degrade performance and create conflicts.[33] However, using a concept called multiscanning, several companies (including G Data[34] and Microsoft[35]) have created applications which can run multiple engines concurrently.
It is sometimes necessary to temporarily disable virus protection when installing major updates such as Windows Service Packs or updating graphics card drivers.[36] Active antivirus protection may partially or completely prevent the installation of a major update.
Support issues also exist around antivirus application interoperability with common solutions like SSL VPN remote access and network access control products.[37] These technology solutions often have policy assessment applications which require that an up to date antivirus is installed and running. If the antivirus application is not recognized by the policy assessment, whether because the antivirus application has been updated or because it is not part of the policy assessment library, the user will be unable to connect.
[edit] Effectiveness
Studies in December 2007 showed that the effectiveness of antivirus software had decreased in the previous year, particularly against unknown or zero day attacks. The computer magazine c't found that detection rates for these threats had dropped from 40-50% in 2006 to 20-30% in 2007. At that time, the only exception was the NOD32 antivirus, which managed a detection rate of 68 percent.[38]
The problem is magnified by the changing intent of virus authors. Some years ago it was obvious when a virus infection was present. The viruses of the day, written by amateurs, exhibited destructive behavior or pop-ups. Modern viruses are often written by professionals, financed by criminal organizations.[39]
Independent testing on all the major virus scanners consistently shows that none provide 100% virus detection. The best ones provided as high as 99.6% detection, while the lowest provided only 81.8% in tests conducted in February 2010. All virus scanners produce false positive results as well, identifying benign files as malware.[40]
Although methodologies may differ, some notable independent quality testing agencies include AV-Comparatives, ICSA Labs, West Coast Labs, VB100 and other members of the Anti-Malware Testing Standards Organization.[41]
[edit] New viruses
Most popular anti-virus programs are not very effective against new viruses, even those that use non-signature-based methods that should detect new viruses. The reason for this is that the virus designers test their new viruses on the major anti-virus applications to make sure that they are not detected before releasing them into the wild.[42]
Some new viruses, particularly ransomware, use polymorphic code to avoid detection by virus scanners. Jerome Segura, a security analyst with ParetoLogic, explained:[43]
“ It's something that they miss a lot of the time because this type of [ransomware virus] comes from sites that use a polymorphism, which means they basically randomize the file they send you and it gets by well-known antivirus products very easily. I've seen people firsthand getting infected, having all the pop-ups and yet they have antivirus software running and it's not detecting anything. It actually can be pretty hard to get rid of, as well, and you're never really sure if it's really gone. When we see something like that usually we advise to reinstall the operating system or reinstall backups.[43] ”
A proof of concept malware has shown how new viruses could use the Graphics Processing Unit (GPU) to avoid detection from anti-virus software. The potential success of this involves bypassing the CPU in order to make it much harder for security researchers to analyse the inner workings of such malware.[44]
[edit] Rootkits
The detection of rootkits are a major challenge for anti-virus programs. Rootkits are extremely difficult to detect and if undetected, rootkits have full administrative access to the computer and are invisible to users, so that they will not be shown in the list of running processes in the task manager. Rootkits can modify the inner workings of the operating system[45] and tamper with antivirus programs.[18]
[edit] Other methods
A command-line virus scanner, Clam AV 0.95.2, running a virus signature definition update, scanning a file and identifying a Trojan
Installed antivirus software running on an individual computer is only one method of guarding against viruses. Other methods are also used, including cloud-based antivirus, firewalls and on-line scanners.
[edit] Cloud antivirus
Cloud antivirus is a technology that uses lightweight agent software on the protected computer, while offloading the majority of data analysis to the provider's infrastructure.[46]
One approach to implementing cloud antivirus involves scanning suspicious files using multiple antivirus engines. This approach was proposed by an early implementation of the cloud antivirus concept called CloudAV. CloudAV was designed to send programs or documents to a network cloud where multiple antivirus and behavioral detection programs are used simultaneously in order to improve detection rates. Parallel scanning of files using potentially incompatible antivirus scanners is achieved by spawning a virtual machine per detection engine and therefore eliminating any possible issues. CloudAV can also perform "retrospective detection," whereby the cloud detection engine rescans all files in its file access history when a new threat is identified thus improving new threat detection speed. Finally, CloudAV is a solution for effective virus scanning on devices that lack the computing power to perform the scans themselves.[47]
[edit] Network firewall
Network firewalls prevent unknown programs and processes from accessing the system. However, they are not antivirus systems and make no attempt to identify or remove anything. They may protect against infection from outside the protected computer or network, and limit the activity of any malicious software which is present by blocking incoming or outgoing requests on certain TCP/IP ports. A firewall is designed to deal with broader system threats that come from network connections into the system and is not an alternative to a virus protection system.
[edit] Online scanning
Some antivirus vendors maintain websites with free online scanning capability of the entire computer, critical areas only, local disks, folders or files.
[edit] Specialist tools
Using rkhunter to scan for rootkits on a Ubuntu Linux computer.
Virus removal tools are available to help remove stubborn infections or certain types of infection. Examples include Trend Micro's Rootkit Buster[48] and rkhunter for the detection of rootkits, Avira's AntiVir Removal Tool,[49] and AVG's various virus removal tools.[50]
A rescue disk that is bootable, such as a CD or USB storage device, can be used to run antivirus software outside of the installed operating system, in order to remove infections while they are dormant. A bootable antivirus disk can be useful when, for example, the installed operating system is no longer bootable or has malware that is resisting all attempts to be removed by the installed antivirus software. Examples of some of these bootable disks include the Avira AntiVir Rescue System[51] and AVG Rescue CD.[52] The AVG Rescue CD software can also be installed onto a USB storage device, that is bootable on newer computers.[53]
[edit] Popularity
Main article: List of antivirus software
A survey by Symantec in 2009 found that a third of small to medium sized business did not use antivirus protection at that time, whereas more than 80% of home users had some kind of antivirus installed.[54]
[edit] See also
Monitor padlock.svg Computer security portal
* EICAR, the European Institute for Computer Antivirus Research
* Linux malware
* List of antivirus software
* List of computer viruses
* List of trojan horses
* Quarantine technology
* Sandbox (computer security)
* Timeline of notable computer viruses and worms
* Virus hoax
Jump to: navigation, search
"Antivirus" redirects here. For antiviral medication, see Antiviral drug.
Antivirus software
SymantecEndpointProtection.jpg
Symantec Endpoint Protection, an example of antivirus software
Antivirus or anti-virus software is used to prevent, detect, and remove computer viruses, worms, and trojan horses. It may also prevent and remove adware, spyware, and other forms of malware. This page talks about the software used for the prevention and removal of such threats, rather than computer security implemented by software methods.
A variety of strategies are typically employed. Signature-based detection involves searching for known patterns of data within executable code. However, it is possible for a computer to be infected with new malware for which no signature is yet known. To counter such so-called zero-day threats, heuristics can be used. One type of heuristic approach, generic signatures, can identify new viruses or variants of existing viruses by looking for known malicious code, or slight variations of such code, in files. Some antivirus software can also predict what a file will do by running it in a sandbox and analyzing what it does to see if it performs any malicious actions.
No matter how useful antivirus software can be, it can sometimes have drawbacks. Antivirus software can impair a computer's performance. Inexperienced users may also have trouble understanding the prompts and decisions that antivirus software presents them with. An incorrect decision may lead to a security breach. If the antivirus software employs heuristic detection, success depends on achieving the right balance between false positives and false negatives. False positives can be as destructive as false negatives. Finally, antivirus software generally runs at the highly trusted kernel level of the operating system, creating a potential avenue of attack.[1]
Contents
[hide]
* 1 History
* 2 Identification methods
o 2.1 Signature based detection
o 2.2 Heuristics
o 2.3 Rootkit detection
* 3 Issues of concern
o 3.1 Unexpected renewal costs
o 3.2 Rogue security applications
o 3.3 Problems caused by false positives
o 3.4 System and interoperability related issues
o 3.5 Effectiveness
o 3.6 New viruses
o 3.7 Rootkits
* 4 Other methods
o 4.1 Cloud antivirus
o 4.2 Network firewall
o 4.3 Online scanning
o 4.4 Specialist tools
* 5 Popularity
* 6 See also
* 7 References
* 8 External links
[edit] History
An example of free antivirus software: ClamTk 3.08.
See also: Timeline of notable computer viruses and worms
Most of the computer viruses written in the early and mid 1980s were limited to self-reproduction and had no specific damage routine built into the code.[2] That changed when more and more programmers became acquainted with virus programming and created viruses that manipulated or even destroyed data on infected computers.
There are competing claims for the innovator of the first antivirus product. Possibly the first publicly documented removal of a computer virus in the wild was performed by Bernd Fix in 1987.[3][4]
Fred Cohen, who published one of the first academic papers on computer viruses in 1984,[5] began to develop strategies for antivirus software in 1988[6] that were picked up and continued by later antivirus software developers.
Also in 1988 a mailing list named VIRUS-L[7] was started on the BITNET/EARN network where new viruses and the possibilities of detecting and eliminating viruses were discussed. Some members of this mailing list like John McAfee or Eugene Kaspersky later founded software companies that developed and sold commercial antivirus software.
Before internet connectivity was widespread, viruses were typically spread by infected floppy disks. Antivirus software came into use, but was updated relatively infrequently. During this time, virus checkers essentially had to check executable files and the boot sectors of floppy disks and hard disks. However, as internet usage became common, viruses began to spread online.[8]
Over the years it has become necessary for antivirus software to check an increasing variety of files, rather than just executables, for several reasons:
* Powerful macros used in word processor applications, such as Microsoft Word, presented a risk. Virus writers could use the macros to write viruses embedded within documents. This meant that computers could now also be at risk from infection by opening documents with hidden attached macros.[9]
* Later email programs, in particular Microsoft's Outlook Express and Outlook, were vulnerable to viruses embedded in the email body itself. A user's computer could be infected by just opening or previewing a message.[10]
As always-on broadband connections became the norm, and more and more viruses were released, it became essential to update virus checkers more and more frequently. Even then, a new zero-day virus could become widespread before antivirus companies released an update to protect against it.
[edit] Identification methods
Malwarebytes' Anti-Malware version 1.46 - a proprietary freeware antimalware product
There are several methods which antivirus software can use to identify malware.
Signature based detection is the most common method. To identify viruses and other malware, antivirus software compares the contents of a file to a dictionary of virus signatures. Because viruses can embed themselves in existing files, the entire file is searched, not just as a whole, but also in pieces.[11]
Heuristic-based detection, like malicious activity detection, can be used to identify unknown viruses.
File emulation is another heuristic approach. File emulation involves executing a program in a virtual environment and logging what actions the program performs. Depending on the actions logged, the antivirus software can determine if the program is malicious or not and then carry out the appropriate disinfection actions.[12]
[edit] Signature based detection
Traditionally, antivirus software heavily relied upon signatures to identify malware. This can be very effective, but cannot defend against malware unless samples have already been obtained and signatures created. Because of this, signature-based approaches are not effective against new, unknown viruses.
As new viruses are being created each day, the signature-based detection approach requires frequent updates of the virus signature dictionary. To assist the antivirus software companies, the software may allow the user to upload new viruses or variants to the company, allowing the virus to be analyzed and the signature added to the dictionary.[11]
Although the signature-based approach can effectively contain virus outbreaks, virus authors have tried to stay a step ahead of such software by writing "oligomorphic", "polymorphic" and, more recently, "metamorphic" viruses, which encrypt parts of themselves or otherwise modify themselves as a method of disguise, so as to not match virus signatures in the dictionary.[13]
[edit] Heuristics
Some more sophisticated antivirus software uses heuristic analysis to identify new malware or variants of known malware.
Many viruses start as a single infection and through either mutation or refinements by other attackers, can grow into dozens of slightly different strains, called variants. Generic detection refers to the detection and removal of multiple threats using a single virus definition.[14]
For example, the Vundo trojan has several family members, depending on the antivirus vendor's classification. Symantec classifies members of the Vundo family into two distinct categories, Trojan.Vundo and Trojan.Vundo.B.[15][16]
While it may be advantageous to identify a specific virus, it can be quicker to detect a virus family through a generic signature or through an inexact match to an existing signature. Virus researchers find common areas that all viruses in a family share uniquely and can thus create a single generic signature. These signatures often contain non-contiguous code, using wildcard characters where differences lie. These wildcards allow the scanner to detect viruses even if they are padded with extra, meaningless code.[17] A detection that uses this method is said to be "heuristic detection."
[edit] Rootkit detection
Main article: Rootkit
Anti-virus software can also scan for rootkits; a rootkit is a type of malware that is designed to gain administrative-level control over a computer system without being detected. Rootkits can change how the operating system functions and in some cases can tamper with the anti-virus program and render it ineffective. Rootkits are also difficult to remove, in some cases requiring a complete re-installation of the operating system.[18][19]
[edit] Issues of concern
[edit] Unexpected renewal costs
Some commercial antivirus software end-user license agreements include a clause that the subscription will be automatically renewed, and the purchaser's credit card automatically billed, at the renewal time without explicit approval. For example, McAfee requires users to unsubscribe at least 60 days before the expiration of the present subscription[20] while BitDefender sends notifications to unsubscribe 30 days before the renewal.[21] Norton Antivirus also renews subscriptions automatically by default.[22]
[edit] Rogue security applications
Main article: Scareware
Some apparent antivirus programs are actually malware masquerading as legitimate software, such as WinFixer and MS Antivirus.[23]
[edit] Problems caused by false positives
A "false positive" is when antivirus software identifies a non-malicious file as a virus. When this happens, it can cause serious problems. For example, if an antivirus program is configured to immediately delete or quarantine infected files, a false positive in a essential file can render the operating system or some applications unusable.[24] In May 2007, a faulty virus signature issued by Symantec mistakenly removed essential operating system files, leaving thousands of PCs unable to boot.[25] Also in May 2007 the executable file required by Pegasus Mail was falsely detected by Norton AntiVirus as being a Trojan and it was automatically removed, preventing Pegasus Mail from running.[26] Norton anti-virus has falsely identified three releases of Pegasus Mail as malware, and would delete the Pegasus Mail installer file when this happens.[27] In response to this Pegasus Mail stated:
“ On the basis that Norton/Symantec has done this for every one of the last three releases of Pegasus Mail, we can only condemn this product as too flawed to use, and recommend in the strongest terms that our users cease using it in favour of alternative, less buggy anti-virus packages.[27] ”
In April 2010 McAfee VirusScan detected svchost.exe, a normal Windows binary, as a virus on machines running Windows XP with Service Pack 3, causing a reboot loop and loss of all network access.[28][29]
In December 2010, a faulty update on the AVG anti-virus suite damaged 64-bit versions of Windows 7, rendering it unable to boot, due to an endless boot loop created.[30]
When Microsoft Windows becomes damaged by faulty anti-virus products, fixing the damage to Microsoft Windows incurs technical support costs and businesses can be forced to close whilst remedial action is undertaken.[31][32]
[edit] System and interoperability related issues
Running multiple antivirus programs concurrently can degrade performance and create conflicts.[33] However, using a concept called multiscanning, several companies (including G Data[34] and Microsoft[35]) have created applications which can run multiple engines concurrently.
It is sometimes necessary to temporarily disable virus protection when installing major updates such as Windows Service Packs or updating graphics card drivers.[36] Active antivirus protection may partially or completely prevent the installation of a major update.
Support issues also exist around antivirus application interoperability with common solutions like SSL VPN remote access and network access control products.[37] These technology solutions often have policy assessment applications which require that an up to date antivirus is installed and running. If the antivirus application is not recognized by the policy assessment, whether because the antivirus application has been updated or because it is not part of the policy assessment library, the user will be unable to connect.
[edit] Effectiveness
Studies in December 2007 showed that the effectiveness of antivirus software had decreased in the previous year, particularly against unknown or zero day attacks. The computer magazine c't found that detection rates for these threats had dropped from 40-50% in 2006 to 20-30% in 2007. At that time, the only exception was the NOD32 antivirus, which managed a detection rate of 68 percent.[38]
The problem is magnified by the changing intent of virus authors. Some years ago it was obvious when a virus infection was present. The viruses of the day, written by amateurs, exhibited destructive behavior or pop-ups. Modern viruses are often written by professionals, financed by criminal organizations.[39]
Independent testing on all the major virus scanners consistently shows that none provide 100% virus detection. The best ones provided as high as 99.6% detection, while the lowest provided only 81.8% in tests conducted in February 2010. All virus scanners produce false positive results as well, identifying benign files as malware.[40]
Although methodologies may differ, some notable independent quality testing agencies include AV-Comparatives, ICSA Labs, West Coast Labs, VB100 and other members of the Anti-Malware Testing Standards Organization.[41]
[edit] New viruses
Most popular anti-virus programs are not very effective against new viruses, even those that use non-signature-based methods that should detect new viruses. The reason for this is that the virus designers test their new viruses on the major anti-virus applications to make sure that they are not detected before releasing them into the wild.[42]
Some new viruses, particularly ransomware, use polymorphic code to avoid detection by virus scanners. Jerome Segura, a security analyst with ParetoLogic, explained:[43]
“ It's something that they miss a lot of the time because this type of [ransomware virus] comes from sites that use a polymorphism, which means they basically randomize the file they send you and it gets by well-known antivirus products very easily. I've seen people firsthand getting infected, having all the pop-ups and yet they have antivirus software running and it's not detecting anything. It actually can be pretty hard to get rid of, as well, and you're never really sure if it's really gone. When we see something like that usually we advise to reinstall the operating system or reinstall backups.[43] ”
A proof of concept malware has shown how new viruses could use the Graphics Processing Unit (GPU) to avoid detection from anti-virus software. The potential success of this involves bypassing the CPU in order to make it much harder for security researchers to analyse the inner workings of such malware.[44]
[edit] Rootkits
The detection of rootkits are a major challenge for anti-virus programs. Rootkits are extremely difficult to detect and if undetected, rootkits have full administrative access to the computer and are invisible to users, so that they will not be shown in the list of running processes in the task manager. Rootkits can modify the inner workings of the operating system[45] and tamper with antivirus programs.[18]
[edit] Other methods
A command-line virus scanner, Clam AV 0.95.2, running a virus signature definition update, scanning a file and identifying a Trojan
Installed antivirus software running on an individual computer is only one method of guarding against viruses. Other methods are also used, including cloud-based antivirus, firewalls and on-line scanners.
[edit] Cloud antivirus
Cloud antivirus is a technology that uses lightweight agent software on the protected computer, while offloading the majority of data analysis to the provider's infrastructure.[46]
One approach to implementing cloud antivirus involves scanning suspicious files using multiple antivirus engines. This approach was proposed by an early implementation of the cloud antivirus concept called CloudAV. CloudAV was designed to send programs or documents to a network cloud where multiple antivirus and behavioral detection programs are used simultaneously in order to improve detection rates. Parallel scanning of files using potentially incompatible antivirus scanners is achieved by spawning a virtual machine per detection engine and therefore eliminating any possible issues. CloudAV can also perform "retrospective detection," whereby the cloud detection engine rescans all files in its file access history when a new threat is identified thus improving new threat detection speed. Finally, CloudAV is a solution for effective virus scanning on devices that lack the computing power to perform the scans themselves.[47]
[edit] Network firewall
Network firewalls prevent unknown programs and processes from accessing the system. However, they are not antivirus systems and make no attempt to identify or remove anything. They may protect against infection from outside the protected computer or network, and limit the activity of any malicious software which is present by blocking incoming or outgoing requests on certain TCP/IP ports. A firewall is designed to deal with broader system threats that come from network connections into the system and is not an alternative to a virus protection system.
[edit] Online scanning
Some antivirus vendors maintain websites with free online scanning capability of the entire computer, critical areas only, local disks, folders or files.
[edit] Specialist tools
Using rkhunter to scan for rootkits on a Ubuntu Linux computer.
Virus removal tools are available to help remove stubborn infections or certain types of infection. Examples include Trend Micro's Rootkit Buster[48] and rkhunter for the detection of rootkits, Avira's AntiVir Removal Tool,[49] and AVG's various virus removal tools.[50]
A rescue disk that is bootable, such as a CD or USB storage device, can be used to run antivirus software outside of the installed operating system, in order to remove infections while they are dormant. A bootable antivirus disk can be useful when, for example, the installed operating system is no longer bootable or has malware that is resisting all attempts to be removed by the installed antivirus software. Examples of some of these bootable disks include the Avira AntiVir Rescue System[51] and AVG Rescue CD.[52] The AVG Rescue CD software can also be installed onto a USB storage device, that is bootable on newer computers.[53]
[edit] Popularity
Main article: List of antivirus software
A survey by Symantec in 2009 found that a third of small to medium sized business did not use antivirus protection at that time, whereas more than 80% of home users had some kind of antivirus installed.[54]
[edit] See also
Monitor padlock.svg Computer security portal
* EICAR, the European Institute for Computer Antivirus Research
* Linux malware
* List of antivirus software
* List of computer viruses
* List of trojan horses
* Quarantine technology
* Sandbox (computer security)
* Timeline of notable computer viruses and worms
* Virus hoax
malware
Malware, short for malicious software, is a software designed to secretly access a computer system without the owner's informed consent. The expression is a general term used by computer professionals to mean a variety of forms of hostile, intrusive, or annoying software or program code.[1]
Software is considered to be malware based on the perceived intent of the creator rather than any particular features. Malware includes computer viruses, worms, trojan horses, spyware, dishonest adware, scareware, crimeware, most rootkits, and other malicious and unwanted software or program. In law, malware is sometimes known as a computer contaminant, for instance in the legal codes of several U. S. states, including California and West Virginia.[2][3]
Preliminary results from Symantec published in 2008 suggested that "the release rate of malicious code and other unwanted programs may be exceeding that of legitimate software applications."[4] According to F-Secure, "As much malware [was] produced in 2007 as in the previous 20 years altogether."[5] Malware's most common pathway from criminals to users is through the Internet: primarily by e-mail and the World Wide Web.[6]
The prevalence of malware as a vehicle for organized Internet crime, along with the general inability of traditional anti-malware protection platforms (products) to protect against the continuous stream of unique and newly produced malware, has seen the adoption of a new mindset for businesses operating on the Internet: the acknowledgment that some sizable percentage of Internet customers will always be infected for some reason or another, and that they need to continue doing business with infected customers. The result is a greater emphasis on back-office systems designed to spot fraudulent activities associated with advanced malware operating on customers' computers.[7]
On March 29, 2010, Symantec Corporation named Shaoxing, China, as the world's malware capital.[8]
Malware is not the same as defective software, that is, software that has a legitimate purpose but contains harmful bugs. Sometimes, malware is disguised as genuine software, and may come from an official site. Therefore, some security programs, such as McAfee may call malware "potentially unwanted programs" or "PUP". Though a computer virus is malware that can reproduce itself, the term is often used erroneously to refer to the entire category. Malware is sometimes called scumware.
Contents
[hide]
* 1 Purposes
* 2 Infectious malware: viruses and worms
o 2.1 Capsule history of viruses and worms
* 3 Concealment: Trojan horses, rootkits, and backdoors
o 3.1 Trojan horses
o 3.2 Rootkits
o 3.3 Backdoors
* 4 Malware for profit: spyware, botnets, keystroke loggers, and dialers
* 5 Data-stealing malware
o 5.1 Characteristics of data-stealing malware
o 5.2 Examples of data-stealing malware
o 5.3 Data-stealing malware incidents
* 6 Controversy about assignment to spyware
* 7 Vulnerability to malware
o 7.1 Eliminating over-privileged code
* 8 Anti-malware programs
* 9 Academic research on malware: a brief overview
* 10 Grayware
* 11 Web and spam
o 11.1 Wikis and blogs
o 11.2 Targeted SMTP threats
o 11.3 HTTP and FTP
* 12 See also
* 13 References
* 14 External links
[edit] Purposes
Many early infectious programs, including the first Internet Worm and a number of MS-DOS viruses, were written as experiments or pranks. They were generally intended to be harmless or merely annoying, rather than to cause serious damage to computer systems. In some cases, the perpetrator did not realize how much harm his or her creations would do. Young programmers learning about viruses and their techniques wrote them simply for practice, or to see how far they could spread. As late as 1999, widespread viruses such as the Melissa virus and the David virus appear to have been written chiefly as pranks. The first mobile phone virus, Cabir, appeared in 2004.
Hostile intent related to vandalism can be found in programs designed to cause harm or data loss. Many DOS viruses, and the Windows ExploreZip worm, were designed to destroy files on a hard disk, or to corrupt the file system by writing invalid data to them. Network-borne worms such as the 2001 Code Red worm or the Ramen worm fall into the same category. Designed to vandalize web pages, worms may seem like the online equivalent to graffiti tagging, with the author's alias or affinity group appearing everywhere the worm goes.[citation needed]
Since the rise of widespread broadband Internet access, malicious software has been designed for a profit, for examples forced advertising. For instance, since 2003, the majority of widespread viruses and worms have been designed to take control of users' computers for black-market exploitation.[9] Infected "zombie computers" are used to send email spam, to host contraband data such as child pornography [10], or to engage in distributed denial-of-service attacks as a form of extortion.[11]
Another strictly for-profit category of malware has emerged in spyware -- programs designed to monitor users' web browsing, display unsolicited advertisements, or redirect affiliate marketing revenues to the spyware creator. Spyware programs do not spread like viruses; they are, in general, installed by exploiting security holes or are packaged with user-installed software, such as peer-to-peer applications.
[edit] Infectious malware: viruses and worms
Main articles: Computer virus and Computer worm
The best-known types of malware, viruses and worms, are known for the manner in which they spread, rather than any other particular behavior. The term computer virus is used for a program that has infected some executable software and, when run, causes the virus to spread to other executables. Viruses may also contain a payload that performs other actions, often malicious. On the other hand, a worm is a program that actively transmits itself over a network to infect other computers. It too may carry a payload.
These definitions lead to the observation that a virus requires user intervention to spread, whereas a worm spreads itself automatically. Using this distinction, infections transmitted by email or Microsoft Word documents, which rely on the recipient opening a file or email to infect the system, would be classified as viruses rather than worms.
Some writers in the trade and popular press misunderstand this distinction and use the terms interchangeably.
[edit] Capsule history of viruses and worms
Before Internet access became widespread, viruses spread on personal computers by infecting the executable boot sectors of floppy disks. By inserting a copy of itself into the machine code instructions in these executables, a virus causes itself to be run whenever a program is run or the disk is booted. Early computer viruses were written for the Apple II and Macintosh, but they became more widespread with the dominance of the IBM PC and MS-DOS system. Executable-infecting viruses are dependent on users exchanging software or boot-able floppies, so they spread rapidly in computer hobbyist circles.
The first worms, network-borne infectious programs, originated not on personal computers, but on multitasking Unix systems. The first well-known worm was the Internet Worm of 1988, which infected SunOS and VAX BSD systems. Unlike a virus, this worm did not insert itself into other programs. Instead, it exploited security holes (vulnerabilities) in network server programs and started itself running as a separate process. This same behaviour is used by today's worms as well.
With the rise of the Microsoft Windows platform in the 1990s, and the flexible macros of its applications, it became possible to write infectious code in the macro language of Microsoft Word and similar programs. These macro viruses infect documents and templates rather than applications (executables), but rely on the fact that macros in a Word document are a form of executable code.
Today, worms are most commonly written for the Windows OS, although a few like Mare-D[12] and the Lion worm[13] are also written for Linux and Unix systems. Worms today work in the same basic way as 1988's Internet Worm: they scan the network and leverage vulnerable computers to replicate. Because they need no human intervention, worms can spread with incredible speed. The SQL Slammer infected thousands of computers in a few minutes.[14]
[edit] Concealment: Trojan horses, rootkits, and backdoors
Main articles: Trojan horse (computing), Rootkit, and Backdoor (computing)
[edit] Trojan horses
For a malicious program to accomplish its goals, it must be able to run without being shut down, or deleted by the user or administrator of the computer system on which it is running. Concealment can also help get the malware installed in the first place. When a malicious program is disguised as something innocuous or desirable, users may be tempted to install it without knowing what it does. This is the technique of the Trojan horse or trojan.
In broad terms, a Trojan horse is any program that invites the user to run it, concealing a harmful or malicious payload. The payload may take effect immediately and can lead to many undesirable effects, such as deleting the user's files or further installing malicious or undesirable software. Trojan horses known as droppers are used to start off a worm outbreak, by injecting the worm into users' local networks.
One of the most common ways that spyware is distributed is as a Trojan horse, bundled with a piece of desirable software that the user downloads from the Internet. When the user installs the software, the spyware is installed alongside. Spyware authors who attempt to act in a legal fashion may include an end-user license agreement that states the behavior of the spyware in loose terms, which the users are unlikely to read or understand.
[edit] Rootkits
Once a malicious program is installed on a system, it is essential that it stays concealed, to avoid detection and disinfection. The same is true when a human attacker breaks into a computer directly. Techniques known as rootkits allow this concealment, by modifying the host's operating system so that the malware is hidden from the user. Rootkits can prevent a malicious process from being visible in the system's list of processes, or keep its files from being read. Originally, a rootkit was a set of tools installed by a human attacker on a Unix system, allowing the attacker to gain administrator (root) access. Today, the term is used more generally for concealment routines in a malicious program.
Some malicious programs contain routines to defend against removal, not merely to hide themselves, but to repel attempts to remove them. An early example of this behavior is recorded in the Jargon File tale of a pair of programs infesting a Xerox CP-V time sharing system:
Each ghost-job would detect the fact that the other had been killed, and would start a new copy of the recently slain program within a few milliseconds. The only way to kill both ghosts was to kill them simultaneously (very difficult) or to deliberately crash the system.[15]
Similar techniques are used by some modern malware, wherein the malware starts a number of processes that monitor and restore one another as needed. In the event a user running Microsoft Windows is infected with such malware, if they wish to manually stop it, they could use Task Manager's 'processes' tab to find the main process (the one that spawned the "resurrector process(es)"), and use the 'end process tree' function, which would kill not only the main process, but the "resurrector(s)" as well, since they were started by the main process. Some malware programs use other techniques, such as naming the infected file similar to a legitimate or trust-able file (expl0rer.exe VS explorer.exe).
[edit] Backdoors
A backdoor is a method of bypassing normal authentication procedures. Once a system has been compromised (by one of the above methods, or in some other way), one or more backdoors may be installed in order to allow easier access in the future. Backdoors may also be installed prior to malicious software, to allow attackers entry.
The idea has often been suggested that computer manufacturers preinstall backdoors on their systems to provide technical support for customers, but this has never been reliably verified. Crackers typically use backdoors to secure remote access to a computer, while attempting to remain hidden from casual inspection. To install backdoors crackers may use Trojan horses, worms, or other methods.
[edit] Malware for profit: spyware, botnets, keystroke loggers, and dialers
Main articles: Spyware, Botnet, Keystroke logging, Web threats, and Dialer
During the 1980s and 1990s, it was usually taken for granted that malicious programs were created as a form of vandalism or prank. More recently, the greater share of malware programs have been written with a profit motive (financial or otherwise) in mind. This can be taken as the malware authors' choice to monetize their control over infected systems: to turn that control into a source of revenue.
Spyware programs are commercially produced for the purpose of gathering information about computer users, showing them pop-up ads, or altering web-browser behavior for the financial benefit of the spyware creator. For instance, some spyware programs redirect search engine results to paid advertisements. Others, often called "stealware" by the media, overwrite affiliate marketing codes so that revenue is redirected to the spyware creator rather than the intended recipient.
Spyware programs are sometimes installed as Trojan horses of one sort or another. They differ in that their creators present themselves openly as businesses, for instance by selling advertising space on the pop-ups created by the malware. Most such programs present the user with an end-user license agreement that purportedly protects the creator from prosecution under computer contaminant laws. However, spyware EULAs have not yet been upheld in court.
Another way that financially motivated malware creators can profit from their infections is to directly use the infected computers to do work for the creator. The infected computers are used as proxies to send out spam messages. A computer left in this state is often known as a zombie computer. The advantage to spammers of using infected computers is they provide anonymity, protecting the spammer from prosecution. Spammers have also used infected PCs to target anti-spam organizations with distributed denial-of-service attacks.
In order to coordinate the activity of many infected computers, attackers have used coordinating systems known as botnets. In a botnet, the malware or malbot logs in to an Internet Relay Chat channel or other chat system. The attacker can then give instructions to all the infected systems simultaneously. Botnets can also be used to push upgraded malware to the infected systems, keeping them resistant to antivirus software or other security measures.
It is possible for a malware creator to profit by stealing sensitive information from a victim. Some malware programs install a key logger, which intercepts the user's keystrokes when entering a password, credit card number, or other information that may be exploited. This is then transmitted to the malware creator automatically, enabling credit card fraud and other theft. Similarly, malware may copy the CD key or password for online games, allowing the creator to steal accounts or virtual items.
Another way of stealing money from the infected PC owner is to take control of a dial-up modem and dial an expensive toll call. Dialer (or porn dialer) software dials up a premium-rate telephone number such as a U.S. "900 number" and leave the line open, charging the toll to the infected user.
[edit] Data-stealing malware
Data-stealing malware is a web threat that divests victims of personal and proprietary information with the intent of monetizing stolen data through direct use or underground distribution. Content security threats that fall under this umbrella include keyloggers, screen scrapers, spyware, adware, backdoors, and bots. The term does not refer to activities such as spam, phishing, DNS poisoning, SEO abuse, etc. However, when these threats result in file download or direct installation, as most hybrid attacks do, files that act as agents to proxy information will fall into the data-stealing malware category.
[edit] Characteristics of data-stealing malware
Does not leave traces of the event
* The malware is typically stored in a cache that is routinely flushed
* The malware may be installed via a drive-by-download process
* The website hosting the malware as well as the malware is generally temporary or rogue
Frequently changes and extends its functions
* It is difficult for antivirus software to detect final payload attributes due to the combination(s) of malware components
* The malware uses multiple file encryption levels
Thwarts Intrusion Detection Systems (IDS) after successful installation
* There are no perceivable network anomalies
* The malware hides in web traffic
* The malware is stealthier in terms of traffic and resource use
Thwarts disk encryption
* Data is stolen during decryption and display
* The malware can record keystrokes, passwords, and screenshots
Thwarts Data Loss Prevention (DLP)
* Leakage protection hinges on metadata tagging, not everything is tagged
* Miscreants can use encryption to port data
[edit] Examples of data-stealing malware
* Bancos, an info stealer that waits for the user to access banking websites then spoofs pages of the bank website to steal sensitive information.
* Gator, spyware that covertly monitors web-surfing habits, uploads data to a server for analysis then serves targeted pop-up ads.
* LegMir, spyware that steals personal information such as account names and passwords related to online games.
* Qhost, a Trojan that modifies the Hosts file to point to a different DNS server when banking sites are accessed then opens a spoofed login page to steal login credentials for those financial institutions.
[edit] Data-stealing malware incidents
* Albert Gonzalez (not to be confused with the U.S. Attorney General Alberto Gonzalez) is accused of masterminding a ring to use malware to steal and sell more than 170 million credit card numbers in 2006 and 2007—the largest computer fraud in history. Among the firms targeted were BJ's Wholesale Club, TJX, DSW Shoe, OfficeMax, Barnes & Noble, Boston Market, Sports Authority and Forever 21.[16]
* A Trojan horse program stole more than 1.6 million records belonging to several hundred thousand people from Monster Worldwide Inc’s job search service. The data was used by cybercriminals to craft phishing emails targeted at Monster.com users to plant additional malware on users’ PCs.[17]
* Customers of Hannaford Bros. Co, a supermarket chain based in Maine, were victims of a data security breach involving the potential compromise of 4.2 million debit and credit cards. The company was hit by several class-action law suits.[18]
* The Torpig Trojan has compromised and stolen login credentials from approximately 250,000 online bank accounts as well as a similar number of credit and debit cards. Other information such as email, and FTP accounts from numerous websites, have also been compromised and stolen.[19]
[edit] Controversy about assignment to spyware
There is a group of software (Alexa toolbar, Google toolbar, Eclipse data usage collector, etc) that send data to a central server about which pages have been visited or which features of the software have been used. However differently from "classic" malware these tools document activities and only send data with the user's approval. The user may opt in to share the data in exchange to the additional features and services, or (in case of Eclipse) as the form of voluntary support for the project. Some security tools report such loggers as malware while others do not. The status of the group is questionable. Some tools like PDFCreator are more on the boundary than others because opting out has been made more complex than it could be (during the installation, the user needs to uncheck two check boxes rather than one). However also PDFCreator is only sometimes mentioned as malware and is still subject of discussions.
[edit] Vulnerability to malware
Main article: Vulnerability (computing)
In this context, as throughout, it should be borne in mind that the “system” under attack may be of various types, e.g. a single computer and operating system, a network or an application.
Various factors make a system more vulnerable to malware:
* Homogeneity: e.g. when all computers in a network run the same OS, upon exploiting one, one can exploit them all.
* Weight of numbers: simply because the vast majority of existing malware is written to attack Windows systems, then Windows systems, ipso facto, are more vulnerable to succumbing to malware (regardless of the security strengths or weaknesses of Windows itself).
* Defects: malware leveraging defects in the OS design.
* Unconfirmed code: code from a floppy disk, CD-ROM or USB device may be executed without the user’s agreement.
* Over-privileged users: some systems allow all users to modify their internal structures.
* Over-privileged code: some systems allow code executed by a user to access all rights of that user.
An oft-cited cause of vulnerability of networks is homogeneity or software monoculture.[20] For example, Microsoft Windows or Apple Mac have such a large share of the market that concentrating on either could enable a cracker to subvert a large number of systems, but any total monoculture is a problem. Instead, introducing inhomogeneity (diversity), purely for the sake of robustness, could increase short-term costs for training and maintenance. However, having a few diverse nodes would deter total shutdown of the network, and allow those nodes to help with recovery of the infected nodes. Such separate, functional redundancy would avoid the cost of a total shutdown, would avoid homogeneity as the problem of "all eggs in one basket".
Most systems contain bugs, or loopholes, which may be exploited by malware. A typical example is the buffer-overrun weakness, in which an interface designed to store data, in a small area of memory, allows the caller to supply more data than will fit. This extra data then overwrites the interface's own executable structure (past the end of the buffer and other data). In this manner, malware can force the system to execute malicious code, by replacing legitimate code with its own payload of instructions (or data values) copied into live memory, outside the buffer area.
Originally, PCs had to be booted from floppy disks, and until recently it was common for this to be the default boot device. This meant that a corrupt floppy disk could subvert the computer during booting, and the same applies to CDs. Although that is now less common, it is still possible to forget that one has changed the default, and rare that a BIOS makes one confirm a boot from removable media.
In some systems, non-administrator users are over-privileged by design, in the sense that they are allowed to modify internal structures of the system. In some environments, users are over-privileged because they have been inappropriately granted administrator or equivalent status. This is primarily a configuration decision, but on Microsoft Windows systems the default configuration is to over-privilege the user. This situation exists due to decisions made by Microsoft to prioritize compatibility with older systems above security configuration in newer systems[citation needed] and because typical applications were developed without the under-privileged users in mind. As privilege escalation exploits have increased this priority is shifting for the release of Microsoft Windows Vista. As a result, many existing applications that require excess privilege (over-privileged code) may have compatibility problems with Vista. However, Vista's User Account Control feature attempts to remedy applications not designed for under-privileged users, acting as a crutch to resolve the privileged access problem inherent in legacy applications.
Malware, running as over-privileged code, can use this privilege to subvert the system. Almost all currently popular operating systems, and also many scripting applications allow code too many privileges, usually in the sense that when a user executes code, the system allows that code all rights of that user. This makes users vulnerable to malware in the form of e-mail attachments, which may or may not be disguised.
Given this state of affairs, users are warned only to open attachments they trust, and to be wary of code received from untrusted sources. It is also common for operating systems to be designed so that device drivers need escalated privileges, while they are supplied by more and more hardware manufacturers.
[edit] Eliminating over-privileged code
Over-privileged code dates from the time when most programs were either delivered with a computer or written in-house, and repairing it would at a stroke render most antivirus software almost redundant. It would, however, have appreciable consequences for the user interface and system management.
The system would have to maintain privilege profiles, and know which to apply for each user and program. In the case of newly installed software, an administrator would need to set up default profiles for the new code.
Eliminating vulnerability to rogue device drivers is probably harder than for arbitrary rogue executables. Two techniques, used in VMS, that can help are memory mapping only the registers of the device in question and a system interface associating the driver with interrupts from the device.
Other approaches are:
* Various forms of virtualization, allowing the code unlimited access only to virtual resources
* Various forms of sandbox or jail
* The security functions of Java, in java.security
Such approaches, however, if not fully integrated with the operating system, would reduplicate effort and not be universally applied, both of which would be detrimental to security.
[edit] Anti-malware programs
Main article: Antivirus software
As malware attacks become more frequent, attention has begun to shift from viruses and spyware protection, to malware protection, and programs have been developed to specifically combat them.
Anti-malware programs can combat malware in two ways:
1. They can provide real time protection against the installation of malware software on a computer. This type of spyware protection works the same way as that of antivirus protection in that the anti-malware software scans all incoming network data for malware software and blocks any threats it comes across.
2. Anti-malware software programs can be used solely for detection and removal of malware software that has already been installed onto a computer. This type of malware protection is normally much easier to use and more popular.[citation needed] This type of anti-malware software scans the contents of the Windows registry, operating system files, and installed programs on a computer and will provide a list of any threats found, allowing the user to choose which files to delete or keep, or to compare this list to a list of known malware components, removing files that match.
Real-time protection from malware works identically to real-time antivirus protection: the software scans disk files at download time, and blocks the activity of components known to represent malware. In some cases, it may also intercept attempts to install start-up items or to modify browser settings. Because many malware components are installed as a result of browser exploits or user error, using security software (some of which are anti-malware, though many are not) to "sandbox" browsers (essentially babysit the user and their browser) can also be effective in helping to restrict any damage done.
[edit] Academic research on malware: a brief overview
The notion of a self-reproducing computer program can be traced back to when presented lectures that encompassed the theory and organization of complicated automata.[21] Neumann showed that in theory a program could reproduce itself. This constituted a plausibility result in computability theory. Fred Cohen experimented with computer viruses and confirmed Neumann's postulate. He also investigated other properties of malware (detectability, self-obfuscating programs that used rudimentary encryption that he called "evolutionary", and so on). His 1988 doctoral dissertation was on the subject of computer viruses.[22] Cohen's faculty advisor, Leonard Adleman (the A in RSA) presented a rigorous proof that, in the general case, algorithmically determining whether a virus is or is not present is Turing undecidable.[23] This problem must not be mistaken for that of determining, within a broad class of programs, that a virus is not present; this problem differs in that it does not require the ability to recognize all viruses. Adleman's proof is perhaps the deepest result in malware computability theory to date and it relies on Cantor's diagonal argument as well as the halting problem. Ironically, it was later shown by Young and Yung that Adleman's work in cryptography is ideal in constructing a virus that is highly resistant to reverse-engineering by presenting the notion of a cryptovirus.[24] A cryptovirus is a virus that contains and uses a public key and randomly generated symmetric cipher initialization vector (IV) and session key (SK). In the cryptoviral extortion attack, the virus hybrid encrypts plaintext data on the victim's machine using the randomly generated IV and SK. The IV+SK are then encrypted using the virus writer's public key. In theory the victim must negotiate with the virus writer to get the IV+SK back in order to decrypt the ciphertext (assuming there are no backups). Analysis of the virus reveals the public key, not the IV and SK needed for decryption, or the private key needed to recover the IV and SK. This result was the first to show that computational complexity theory can be used to devise malware that is robust against reverse-engineering.
Another growing area of computer virus research is to mathematically model the infection behavior of worms using models such as Lotka–Volterra equations, which has been applied in the study of biological virus. Various virus propagation scenarios have been studied by researchers such as propagation of computer virus, fighting virus with virus like predator codes,[25][26] effectiveness of patching etc.
[edit] Grayware
Grayware[27] (or greyware) is a general term sometimes used as a classification for applications that behave in a manner that is annoying or undesirable, and yet less serious or troublesome than malware.[28] Grayware encompasses spyware, adware, dialers, joke programs, remote access tools, and any other unwelcome files and programs apart from viruses that are designed to harm the performance of computers on your network. The term has been in use since at least as early as September 2004.[29]
Grayware refers to applications or files that are not classified as viruses or trojan horse programs, but can still negatively affect the performance of the computers on your network and introduce significant security risks to your organization.[30] Often grayware performs a variety of undesired actions such as irritating users with pop-up windows, tracking user habits and unnecessarily exposing computer vulnerabilities to attack.
* Spyware is software that installs components on a computer for the purpose of recording Web surfing habits (primarily for marketing purposes). Spyware sends this information to its author or to other interested parties when the computer is online. Spyware often downloads with items identified as 'free downloads' and does not notify the user of its existence or ask for permission to install the components. The information spyware components gather can include user keystrokes, which means that private information such as login names, passwords, and credit card numbers are vulnerable to theft.
* Adware is software that displays advertising banners on Web browsers such as Internet Explorer and Mozilla Firefox. While not categorized as malware, many users consider adware invasive. Adware programs often create unwanted effects on a system, such as annoying popup ads and the general degradation in either network connection or system performance. Adware programs are typically installed as separate programs that are bundled with certain free software. Many users inadvertently agree to installing adware by accepting the End User License Agreement (EULA) on the free software. Adware are also often installed in tandem with spyware programs. Both programs feed off each other's functionalities: spyware programs profile users' Internet behavior, while adware programs display targeted ads that correspond to the gathered user prof Web and spam
If an intruder can gain access to a website, it can be hijacked with a single HTML element.[31]
The World Wide Web is a criminals' preferred pathway for spreading malware. Today's web threats use combinations of malware to create infection chains. About one in ten Web pages may contain malicious code.[32]
[edit] Wikis and blogs
Attackers may use wikis and blogs to advertise links that lead to malware sites.[33]
Wiki and blog servers can also be attacked directly. Just in 2010, Network Solutions has been hacked[34][35] and some sites hosting in there became a path to malware and spam.
[edit] Targeted SMTP threats
Targeted SMTP threats also represent an emerging attack vector through which malware is propagated. As users adapt to widespread spam attacks, cybercriminals distribute crimeware to target one specific organization or industry, often for financial gain.[36]
[edit] HTTP and FTP
Infections via "drive-by" download are spread through the Web over HTTP and FTP when resources containing spurious keywords are indexed by legitimate search engines, as well as when JavaScript is surreptitiously added to legitimate websites and advertising networks.[37]
[edit] See also
Computer-aj aj ashton 01.svg Computing portal
Monitor padlock.svg Computer security portal
* Category:Web security exploits
* Computer crime
* Computer insecurity
* Cyber spying
* Firewall (computing)
* Industrial espionage
* It risk
* Malvertising
* Privacy-invasive software
* Security in Web applications
* Social engineering (security)
* Spy softwar
Software is considered to be malware based on the perceived intent of the creator rather than any particular features. Malware includes computer viruses, worms, trojan horses, spyware, dishonest adware, scareware, crimeware, most rootkits, and other malicious and unwanted software or program. In law, malware is sometimes known as a computer contaminant, for instance in the legal codes of several U. S. states, including California and West Virginia.[2][3]
Preliminary results from Symantec published in 2008 suggested that "the release rate of malicious code and other unwanted programs may be exceeding that of legitimate software applications."[4] According to F-Secure, "As much malware [was] produced in 2007 as in the previous 20 years altogether."[5] Malware's most common pathway from criminals to users is through the Internet: primarily by e-mail and the World Wide Web.[6]
The prevalence of malware as a vehicle for organized Internet crime, along with the general inability of traditional anti-malware protection platforms (products) to protect against the continuous stream of unique and newly produced malware, has seen the adoption of a new mindset for businesses operating on the Internet: the acknowledgment that some sizable percentage of Internet customers will always be infected for some reason or another, and that they need to continue doing business with infected customers. The result is a greater emphasis on back-office systems designed to spot fraudulent activities associated with advanced malware operating on customers' computers.[7]
On March 29, 2010, Symantec Corporation named Shaoxing, China, as the world's malware capital.[8]
Malware is not the same as defective software, that is, software that has a legitimate purpose but contains harmful bugs. Sometimes, malware is disguised as genuine software, and may come from an official site. Therefore, some security programs, such as McAfee may call malware "potentially unwanted programs" or "PUP". Though a computer virus is malware that can reproduce itself, the term is often used erroneously to refer to the entire category. Malware is sometimes called scumware.
Contents
[hide]
* 1 Purposes
* 2 Infectious malware: viruses and worms
o 2.1 Capsule history of viruses and worms
* 3 Concealment: Trojan horses, rootkits, and backdoors
o 3.1 Trojan horses
o 3.2 Rootkits
o 3.3 Backdoors
* 4 Malware for profit: spyware, botnets, keystroke loggers, and dialers
* 5 Data-stealing malware
o 5.1 Characteristics of data-stealing malware
o 5.2 Examples of data-stealing malware
o 5.3 Data-stealing malware incidents
* 6 Controversy about assignment to spyware
* 7 Vulnerability to malware
o 7.1 Eliminating over-privileged code
* 8 Anti-malware programs
* 9 Academic research on malware: a brief overview
* 10 Grayware
* 11 Web and spam
o 11.1 Wikis and blogs
o 11.2 Targeted SMTP threats
o 11.3 HTTP and FTP
* 12 See also
* 13 References
* 14 External links
[edit] Purposes
Many early infectious programs, including the first Internet Worm and a number of MS-DOS viruses, were written as experiments or pranks. They were generally intended to be harmless or merely annoying, rather than to cause serious damage to computer systems. In some cases, the perpetrator did not realize how much harm his or her creations would do. Young programmers learning about viruses and their techniques wrote them simply for practice, or to see how far they could spread. As late as 1999, widespread viruses such as the Melissa virus and the David virus appear to have been written chiefly as pranks. The first mobile phone virus, Cabir, appeared in 2004.
Hostile intent related to vandalism can be found in programs designed to cause harm or data loss. Many DOS viruses, and the Windows ExploreZip worm, were designed to destroy files on a hard disk, or to corrupt the file system by writing invalid data to them. Network-borne worms such as the 2001 Code Red worm or the Ramen worm fall into the same category. Designed to vandalize web pages, worms may seem like the online equivalent to graffiti tagging, with the author's alias or affinity group appearing everywhere the worm goes.[citation needed]
Since the rise of widespread broadband Internet access, malicious software has been designed for a profit, for examples forced advertising. For instance, since 2003, the majority of widespread viruses and worms have been designed to take control of users' computers for black-market exploitation.[9] Infected "zombie computers" are used to send email spam, to host contraband data such as child pornography [10], or to engage in distributed denial-of-service attacks as a form of extortion.[11]
Another strictly for-profit category of malware has emerged in spyware -- programs designed to monitor users' web browsing, display unsolicited advertisements, or redirect affiliate marketing revenues to the spyware creator. Spyware programs do not spread like viruses; they are, in general, installed by exploiting security holes or are packaged with user-installed software, such as peer-to-peer applications.
[edit] Infectious malware: viruses and worms
Main articles: Computer virus and Computer worm
The best-known types of malware, viruses and worms, are known for the manner in which they spread, rather than any other particular behavior. The term computer virus is used for a program that has infected some executable software and, when run, causes the virus to spread to other executables. Viruses may also contain a payload that performs other actions, often malicious. On the other hand, a worm is a program that actively transmits itself over a network to infect other computers. It too may carry a payload.
These definitions lead to the observation that a virus requires user intervention to spread, whereas a worm spreads itself automatically. Using this distinction, infections transmitted by email or Microsoft Word documents, which rely on the recipient opening a file or email to infect the system, would be classified as viruses rather than worms.
Some writers in the trade and popular press misunderstand this distinction and use the terms interchangeably.
[edit] Capsule history of viruses and worms
Before Internet access became widespread, viruses spread on personal computers by infecting the executable boot sectors of floppy disks. By inserting a copy of itself into the machine code instructions in these executables, a virus causes itself to be run whenever a program is run or the disk is booted. Early computer viruses were written for the Apple II and Macintosh, but they became more widespread with the dominance of the IBM PC and MS-DOS system. Executable-infecting viruses are dependent on users exchanging software or boot-able floppies, so they spread rapidly in computer hobbyist circles.
The first worms, network-borne infectious programs, originated not on personal computers, but on multitasking Unix systems. The first well-known worm was the Internet Worm of 1988, which infected SunOS and VAX BSD systems. Unlike a virus, this worm did not insert itself into other programs. Instead, it exploited security holes (vulnerabilities) in network server programs and started itself running as a separate process. This same behaviour is used by today's worms as well.
With the rise of the Microsoft Windows platform in the 1990s, and the flexible macros of its applications, it became possible to write infectious code in the macro language of Microsoft Word and similar programs. These macro viruses infect documents and templates rather than applications (executables), but rely on the fact that macros in a Word document are a form of executable code.
Today, worms are most commonly written for the Windows OS, although a few like Mare-D[12] and the Lion worm[13] are also written for Linux and Unix systems. Worms today work in the same basic way as 1988's Internet Worm: they scan the network and leverage vulnerable computers to replicate. Because they need no human intervention, worms can spread with incredible speed. The SQL Slammer infected thousands of computers in a few minutes.[14]
[edit] Concealment: Trojan horses, rootkits, and backdoors
Main articles: Trojan horse (computing), Rootkit, and Backdoor (computing)
[edit] Trojan horses
For a malicious program to accomplish its goals, it must be able to run without being shut down, or deleted by the user or administrator of the computer system on which it is running. Concealment can also help get the malware installed in the first place. When a malicious program is disguised as something innocuous or desirable, users may be tempted to install it without knowing what it does. This is the technique of the Trojan horse or trojan.
In broad terms, a Trojan horse is any program that invites the user to run it, concealing a harmful or malicious payload. The payload may take effect immediately and can lead to many undesirable effects, such as deleting the user's files or further installing malicious or undesirable software. Trojan horses known as droppers are used to start off a worm outbreak, by injecting the worm into users' local networks.
One of the most common ways that spyware is distributed is as a Trojan horse, bundled with a piece of desirable software that the user downloads from the Internet. When the user installs the software, the spyware is installed alongside. Spyware authors who attempt to act in a legal fashion may include an end-user license agreement that states the behavior of the spyware in loose terms, which the users are unlikely to read or understand.
[edit] Rootkits
Once a malicious program is installed on a system, it is essential that it stays concealed, to avoid detection and disinfection. The same is true when a human attacker breaks into a computer directly. Techniques known as rootkits allow this concealment, by modifying the host's operating system so that the malware is hidden from the user. Rootkits can prevent a malicious process from being visible in the system's list of processes, or keep its files from being read. Originally, a rootkit was a set of tools installed by a human attacker on a Unix system, allowing the attacker to gain administrator (root) access. Today, the term is used more generally for concealment routines in a malicious program.
Some malicious programs contain routines to defend against removal, not merely to hide themselves, but to repel attempts to remove them. An early example of this behavior is recorded in the Jargon File tale of a pair of programs infesting a Xerox CP-V time sharing system:
Each ghost-job would detect the fact that the other had been killed, and would start a new copy of the recently slain program within a few milliseconds. The only way to kill both ghosts was to kill them simultaneously (very difficult) or to deliberately crash the system.[15]
Similar techniques are used by some modern malware, wherein the malware starts a number of processes that monitor and restore one another as needed. In the event a user running Microsoft Windows is infected with such malware, if they wish to manually stop it, they could use Task Manager's 'processes' tab to find the main process (the one that spawned the "resurrector process(es)"), and use the 'end process tree' function, which would kill not only the main process, but the "resurrector(s)" as well, since they were started by the main process. Some malware programs use other techniques, such as naming the infected file similar to a legitimate or trust-able file (expl0rer.exe VS explorer.exe).
[edit] Backdoors
A backdoor is a method of bypassing normal authentication procedures. Once a system has been compromised (by one of the above methods, or in some other way), one or more backdoors may be installed in order to allow easier access in the future. Backdoors may also be installed prior to malicious software, to allow attackers entry.
The idea has often been suggested that computer manufacturers preinstall backdoors on their systems to provide technical support for customers, but this has never been reliably verified. Crackers typically use backdoors to secure remote access to a computer, while attempting to remain hidden from casual inspection. To install backdoors crackers may use Trojan horses, worms, or other methods.
[edit] Malware for profit: spyware, botnets, keystroke loggers, and dialers
Main articles: Spyware, Botnet, Keystroke logging, Web threats, and Dialer
During the 1980s and 1990s, it was usually taken for granted that malicious programs were created as a form of vandalism or prank. More recently, the greater share of malware programs have been written with a profit motive (financial or otherwise) in mind. This can be taken as the malware authors' choice to monetize their control over infected systems: to turn that control into a source of revenue.
Spyware programs are commercially produced for the purpose of gathering information about computer users, showing them pop-up ads, or altering web-browser behavior for the financial benefit of the spyware creator. For instance, some spyware programs redirect search engine results to paid advertisements. Others, often called "stealware" by the media, overwrite affiliate marketing codes so that revenue is redirected to the spyware creator rather than the intended recipient.
Spyware programs are sometimes installed as Trojan horses of one sort or another. They differ in that their creators present themselves openly as businesses, for instance by selling advertising space on the pop-ups created by the malware. Most such programs present the user with an end-user license agreement that purportedly protects the creator from prosecution under computer contaminant laws. However, spyware EULAs have not yet been upheld in court.
Another way that financially motivated malware creators can profit from their infections is to directly use the infected computers to do work for the creator. The infected computers are used as proxies to send out spam messages. A computer left in this state is often known as a zombie computer. The advantage to spammers of using infected computers is they provide anonymity, protecting the spammer from prosecution. Spammers have also used infected PCs to target anti-spam organizations with distributed denial-of-service attacks.
In order to coordinate the activity of many infected computers, attackers have used coordinating systems known as botnets. In a botnet, the malware or malbot logs in to an Internet Relay Chat channel or other chat system. The attacker can then give instructions to all the infected systems simultaneously. Botnets can also be used to push upgraded malware to the infected systems, keeping them resistant to antivirus software or other security measures.
It is possible for a malware creator to profit by stealing sensitive information from a victim. Some malware programs install a key logger, which intercepts the user's keystrokes when entering a password, credit card number, or other information that may be exploited. This is then transmitted to the malware creator automatically, enabling credit card fraud and other theft. Similarly, malware may copy the CD key or password for online games, allowing the creator to steal accounts or virtual items.
Another way of stealing money from the infected PC owner is to take control of a dial-up modem and dial an expensive toll call. Dialer (or porn dialer) software dials up a premium-rate telephone number such as a U.S. "900 number" and leave the line open, charging the toll to the infected user.
[edit] Data-stealing malware
Data-stealing malware is a web threat that divests victims of personal and proprietary information with the intent of monetizing stolen data through direct use or underground distribution. Content security threats that fall under this umbrella include keyloggers, screen scrapers, spyware, adware, backdoors, and bots. The term does not refer to activities such as spam, phishing, DNS poisoning, SEO abuse, etc. However, when these threats result in file download or direct installation, as most hybrid attacks do, files that act as agents to proxy information will fall into the data-stealing malware category.
[edit] Characteristics of data-stealing malware
Does not leave traces of the event
* The malware is typically stored in a cache that is routinely flushed
* The malware may be installed via a drive-by-download process
* The website hosting the malware as well as the malware is generally temporary or rogue
Frequently changes and extends its functions
* It is difficult for antivirus software to detect final payload attributes due to the combination(s) of malware components
* The malware uses multiple file encryption levels
Thwarts Intrusion Detection Systems (IDS) after successful installation
* There are no perceivable network anomalies
* The malware hides in web traffic
* The malware is stealthier in terms of traffic and resource use
Thwarts disk encryption
* Data is stolen during decryption and display
* The malware can record keystrokes, passwords, and screenshots
Thwarts Data Loss Prevention (DLP)
* Leakage protection hinges on metadata tagging, not everything is tagged
* Miscreants can use encryption to port data
[edit] Examples of data-stealing malware
* Bancos, an info stealer that waits for the user to access banking websites then spoofs pages of the bank website to steal sensitive information.
* Gator, spyware that covertly monitors web-surfing habits, uploads data to a server for analysis then serves targeted pop-up ads.
* LegMir, spyware that steals personal information such as account names and passwords related to online games.
* Qhost, a Trojan that modifies the Hosts file to point to a different DNS server when banking sites are accessed then opens a spoofed login page to steal login credentials for those financial institutions.
[edit] Data-stealing malware incidents
* Albert Gonzalez (not to be confused with the U.S. Attorney General Alberto Gonzalez) is accused of masterminding a ring to use malware to steal and sell more than 170 million credit card numbers in 2006 and 2007—the largest computer fraud in history. Among the firms targeted were BJ's Wholesale Club, TJX, DSW Shoe, OfficeMax, Barnes & Noble, Boston Market, Sports Authority and Forever 21.[16]
* A Trojan horse program stole more than 1.6 million records belonging to several hundred thousand people from Monster Worldwide Inc’s job search service. The data was used by cybercriminals to craft phishing emails targeted at Monster.com users to plant additional malware on users’ PCs.[17]
* Customers of Hannaford Bros. Co, a supermarket chain based in Maine, were victims of a data security breach involving the potential compromise of 4.2 million debit and credit cards. The company was hit by several class-action law suits.[18]
* The Torpig Trojan has compromised and stolen login credentials from approximately 250,000 online bank accounts as well as a similar number of credit and debit cards. Other information such as email, and FTP accounts from numerous websites, have also been compromised and stolen.[19]
[edit] Controversy about assignment to spyware
There is a group of software (Alexa toolbar, Google toolbar, Eclipse data usage collector, etc) that send data to a central server about which pages have been visited or which features of the software have been used. However differently from "classic" malware these tools document activities and only send data with the user's approval. The user may opt in to share the data in exchange to the additional features and services, or (in case of Eclipse) as the form of voluntary support for the project. Some security tools report such loggers as malware while others do not. The status of the group is questionable. Some tools like PDFCreator are more on the boundary than others because opting out has been made more complex than it could be (during the installation, the user needs to uncheck two check boxes rather than one). However also PDFCreator is only sometimes mentioned as malware and is still subject of discussions.
[edit] Vulnerability to malware
Main article: Vulnerability (computing)
In this context, as throughout, it should be borne in mind that the “system” under attack may be of various types, e.g. a single computer and operating system, a network or an application.
Various factors make a system more vulnerable to malware:
* Homogeneity: e.g. when all computers in a network run the same OS, upon exploiting one, one can exploit them all.
* Weight of numbers: simply because the vast majority of existing malware is written to attack Windows systems, then Windows systems, ipso facto, are more vulnerable to succumbing to malware (regardless of the security strengths or weaknesses of Windows itself).
* Defects: malware leveraging defects in the OS design.
* Unconfirmed code: code from a floppy disk, CD-ROM or USB device may be executed without the user’s agreement.
* Over-privileged users: some systems allow all users to modify their internal structures.
* Over-privileged code: some systems allow code executed by a user to access all rights of that user.
An oft-cited cause of vulnerability of networks is homogeneity or software monoculture.[20] For example, Microsoft Windows or Apple Mac have such a large share of the market that concentrating on either could enable a cracker to subvert a large number of systems, but any total monoculture is a problem. Instead, introducing inhomogeneity (diversity), purely for the sake of robustness, could increase short-term costs for training and maintenance. However, having a few diverse nodes would deter total shutdown of the network, and allow those nodes to help with recovery of the infected nodes. Such separate, functional redundancy would avoid the cost of a total shutdown, would avoid homogeneity as the problem of "all eggs in one basket".
Most systems contain bugs, or loopholes, which may be exploited by malware. A typical example is the buffer-overrun weakness, in which an interface designed to store data, in a small area of memory, allows the caller to supply more data than will fit. This extra data then overwrites the interface's own executable structure (past the end of the buffer and other data). In this manner, malware can force the system to execute malicious code, by replacing legitimate code with its own payload of instructions (or data values) copied into live memory, outside the buffer area.
Originally, PCs had to be booted from floppy disks, and until recently it was common for this to be the default boot device. This meant that a corrupt floppy disk could subvert the computer during booting, and the same applies to CDs. Although that is now less common, it is still possible to forget that one has changed the default, and rare that a BIOS makes one confirm a boot from removable media.
In some systems, non-administrator users are over-privileged by design, in the sense that they are allowed to modify internal structures of the system. In some environments, users are over-privileged because they have been inappropriately granted administrator or equivalent status. This is primarily a configuration decision, but on Microsoft Windows systems the default configuration is to over-privilege the user. This situation exists due to decisions made by Microsoft to prioritize compatibility with older systems above security configuration in newer systems[citation needed] and because typical applications were developed without the under-privileged users in mind. As privilege escalation exploits have increased this priority is shifting for the release of Microsoft Windows Vista. As a result, many existing applications that require excess privilege (over-privileged code) may have compatibility problems with Vista. However, Vista's User Account Control feature attempts to remedy applications not designed for under-privileged users, acting as a crutch to resolve the privileged access problem inherent in legacy applications.
Malware, running as over-privileged code, can use this privilege to subvert the system. Almost all currently popular operating systems, and also many scripting applications allow code too many privileges, usually in the sense that when a user executes code, the system allows that code all rights of that user. This makes users vulnerable to malware in the form of e-mail attachments, which may or may not be disguised.
Given this state of affairs, users are warned only to open attachments they trust, and to be wary of code received from untrusted sources. It is also common for operating systems to be designed so that device drivers need escalated privileges, while they are supplied by more and more hardware manufacturers.
[edit] Eliminating over-privileged code
Over-privileged code dates from the time when most programs were either delivered with a computer or written in-house, and repairing it would at a stroke render most antivirus software almost redundant. It would, however, have appreciable consequences for the user interface and system management.
The system would have to maintain privilege profiles, and know which to apply for each user and program. In the case of newly installed software, an administrator would need to set up default profiles for the new code.
Eliminating vulnerability to rogue device drivers is probably harder than for arbitrary rogue executables. Two techniques, used in VMS, that can help are memory mapping only the registers of the device in question and a system interface associating the driver with interrupts from the device.
Other approaches are:
* Various forms of virtualization, allowing the code unlimited access only to virtual resources
* Various forms of sandbox or jail
* The security functions of Java, in java.security
Such approaches, however, if not fully integrated with the operating system, would reduplicate effort and not be universally applied, both of which would be detrimental to security.
[edit] Anti-malware programs
Main article: Antivirus software
As malware attacks become more frequent, attention has begun to shift from viruses and spyware protection, to malware protection, and programs have been developed to specifically combat them.
Anti-malware programs can combat malware in two ways:
1. They can provide real time protection against the installation of malware software on a computer. This type of spyware protection works the same way as that of antivirus protection in that the anti-malware software scans all incoming network data for malware software and blocks any threats it comes across.
2. Anti-malware software programs can be used solely for detection and removal of malware software that has already been installed onto a computer. This type of malware protection is normally much easier to use and more popular.[citation needed] This type of anti-malware software scans the contents of the Windows registry, operating system files, and installed programs on a computer and will provide a list of any threats found, allowing the user to choose which files to delete or keep, or to compare this list to a list of known malware components, removing files that match.
Real-time protection from malware works identically to real-time antivirus protection: the software scans disk files at download time, and blocks the activity of components known to represent malware. In some cases, it may also intercept attempts to install start-up items or to modify browser settings. Because many malware components are installed as a result of browser exploits or user error, using security software (some of which are anti-malware, though many are not) to "sandbox" browsers (essentially babysit the user and their browser) can also be effective in helping to restrict any damage done.
[edit] Academic research on malware: a brief overview
The notion of a self-reproducing computer program can be traced back to when presented lectures that encompassed the theory and organization of complicated automata.[21] Neumann showed that in theory a program could reproduce itself. This constituted a plausibility result in computability theory. Fred Cohen experimented with computer viruses and confirmed Neumann's postulate. He also investigated other properties of malware (detectability, self-obfuscating programs that used rudimentary encryption that he called "evolutionary", and so on). His 1988 doctoral dissertation was on the subject of computer viruses.[22] Cohen's faculty advisor, Leonard Adleman (the A in RSA) presented a rigorous proof that, in the general case, algorithmically determining whether a virus is or is not present is Turing undecidable.[23] This problem must not be mistaken for that of determining, within a broad class of programs, that a virus is not present; this problem differs in that it does not require the ability to recognize all viruses. Adleman's proof is perhaps the deepest result in malware computability theory to date and it relies on Cantor's diagonal argument as well as the halting problem. Ironically, it was later shown by Young and Yung that Adleman's work in cryptography is ideal in constructing a virus that is highly resistant to reverse-engineering by presenting the notion of a cryptovirus.[24] A cryptovirus is a virus that contains and uses a public key and randomly generated symmetric cipher initialization vector (IV) and session key (SK). In the cryptoviral extortion attack, the virus hybrid encrypts plaintext data on the victim's machine using the randomly generated IV and SK. The IV+SK are then encrypted using the virus writer's public key. In theory the victim must negotiate with the virus writer to get the IV+SK back in order to decrypt the ciphertext (assuming there are no backups). Analysis of the virus reveals the public key, not the IV and SK needed for decryption, or the private key needed to recover the IV and SK. This result was the first to show that computational complexity theory can be used to devise malware that is robust against reverse-engineering.
Another growing area of computer virus research is to mathematically model the infection behavior of worms using models such as Lotka–Volterra equations, which has been applied in the study of biological virus. Various virus propagation scenarios have been studied by researchers such as propagation of computer virus, fighting virus with virus like predator codes,[25][26] effectiveness of patching etc.
[edit] Grayware
Grayware[27] (or greyware) is a general term sometimes used as a classification for applications that behave in a manner that is annoying or undesirable, and yet less serious or troublesome than malware.[28] Grayware encompasses spyware, adware, dialers, joke programs, remote access tools, and any other unwelcome files and programs apart from viruses that are designed to harm the performance of computers on your network. The term has been in use since at least as early as September 2004.[29]
Grayware refers to applications or files that are not classified as viruses or trojan horse programs, but can still negatively affect the performance of the computers on your network and introduce significant security risks to your organization.[30] Often grayware performs a variety of undesired actions such as irritating users with pop-up windows, tracking user habits and unnecessarily exposing computer vulnerabilities to attack.
* Spyware is software that installs components on a computer for the purpose of recording Web surfing habits (primarily for marketing purposes). Spyware sends this information to its author or to other interested parties when the computer is online. Spyware often downloads with items identified as 'free downloads' and does not notify the user of its existence or ask for permission to install the components. The information spyware components gather can include user keystrokes, which means that private information such as login names, passwords, and credit card numbers are vulnerable to theft.
* Adware is software that displays advertising banners on Web browsers such as Internet Explorer and Mozilla Firefox. While not categorized as malware, many users consider adware invasive. Adware programs often create unwanted effects on a system, such as annoying popup ads and the general degradation in either network connection or system performance. Adware programs are typically installed as separate programs that are bundled with certain free software. Many users inadvertently agree to installing adware by accepting the End User License Agreement (EULA) on the free software. Adware are also often installed in tandem with spyware programs. Both programs feed off each other's functionalities: spyware programs profile users' Internet behavior, while adware programs display targeted ads that correspond to the gathered user prof Web and spam
If an intruder can gain access to a website, it can be hijacked with a single HTML element.[31]
The World Wide Web is a criminals' preferred pathway for spreading malware. Today's web threats use combinations of malware to create infection chains. About one in ten Web pages may contain malicious code.[32]
[edit] Wikis and blogs
Attackers may use wikis and blogs to advertise links that lead to malware sites.[33]
Wiki and blog servers can also be attacked directly. Just in 2010, Network Solutions has been hacked[34][35] and some sites hosting in there became a path to malware and spam.
[edit] Targeted SMTP threats
Targeted SMTP threats also represent an emerging attack vector through which malware is propagated. As users adapt to widespread spam attacks, cybercriminals distribute crimeware to target one specific organization or industry, often for financial gain.[36]
[edit] HTTP and FTP
Infections via "drive-by" download are spread through the Web over HTTP and FTP when resources containing spurious keywords are indexed by legitimate search engines, as well as when JavaScript is surreptitiously added to legitimate websites and advertising networks.[37]
[edit] See also
Computer-aj aj ashton 01.svg Computing portal
Monitor padlock.svg Computer security portal
* Category:Web security exploits
* Computer crime
* Computer insecurity
* Cyber spying
* Firewall (computing)
* Industrial espionage
* It risk
* Malvertising
* Privacy-invasive software
* Security in Web applications
* Social engineering (security)
* Spy softwar
computer virus
A computer virus is a computer program that can copy itself[1] and infect a computer. The term "virus" is also commonly but erroneously used to refer to other types of malware, including but not limited to adware and spyware programs that do not have the reproductive ability. A true virus can spread from one computer to another (in some form of executable code) when its host is taken to the target computer; for instance because a user sent it over a network or the Internet, or carried it on a removable medium such as a floppy disk, CD, DVD, or USB drive.[2]
Viruses can increase their chances of spreading to other computers by infecting files on a network file system or a file system that is accessed by another computer.[3][4]
As stated above, the term "computer virus" is sometimes used as a catch-all phrase to include all types of malware, even those that do not have the reproductive ability. Malware includes computer viruses, computer worms, Trojan horses, most rootkits, spyware, dishonest adware and other malicious and unwanted software, including true viruses. Viruses are sometimes confused with worms and Trojan horses, which are technically different. A worm can exploit security vulnerabilities to spread itself automatically to other computers through networks, while a Trojan horse is a program that appears harmless but hides malicious functions. Worms and Trojan horses, like viruses, may harm a computer system's data or performance. Some viruses and other malware have symptoms noticeable to the computer user, but many are surreptitious or simply do nothing to call attention to themselves. Some viruses do nothing beyond reproducing themselves.
Contents
[hide]
* 1 History
o 1.1 Academic work
o 1.2 Science Fiction
o 1.3 Virus programs
* 2 Infection strategies
o 2.1 Nonresident viruses
o 2.2 Resident viruses
* 3 Vectors and hosts
* 4 Methods to avoid detection
o 4.1 Avoiding bait files and other undesirable hosts
o 4.2 Stealth
+ 4.2.1 Self-modification
+ 4.2.2 Encryption with a variable key
+ 4.2.3 Polymorphic code
+ 4.2.4 Metamorphic code
* 5 Vulnerability and countermeasures
o 5.1 The vulnerability of operating systems to viruses
o 5.2 The role of software development
o 5.3 Anti-virus software and other preventive measures
o 5.4 Recovery methods
+ 5.4.1 Virus removal
+ 5.4.2 Operating system reinstallation
* 6 See also
* 7 References
* 8 Further reading
* 9 External links
History
Academic work
The first academic work on the theory of computer viruses (although the term "computer virus" was not invented at that time) was done by John von Neumann in 1949 who held lectures at the University of Illinois about the "Theory and Organization of Complicated Automata". The work of von Neumann was later published as the "Theory of self-reproducing automata".[5] In his essay von Neumann postulated that a computer program could reproduce.
In 1972 Veith Risak published his article "Selbstreproduzierende Automaten mit minimaler Informationsübertragung" (Self-reproducing automata with minimal information exchange).[6] The article describes a fully functional virus written in assembler language for a SIEMENS 4004/35 computer system.
In 1980 Jürgen Kraus wrote his diplom thesis "Selbstreproduktion bei Programmen" (Self-reproduction of programs) at the University of Dortmund.[7] In his work Kraus postulated that computer programs can behave in a way similar to biological viruses.
In 1984 Fred Cohen from the University of Southern California wrote his paper "Computer Viruses - Theory and Experiments".[8] It was the first paper to explicitly call a self-reproducing program a "virus"; a term introduced by his mentor Leonard Adleman.
An article that describes "useful virus functionalities" was published by J. B. Gunn under the title "Use of virus functions to provide a virtual APL interpreter under user control" in 1984.[9]
Science Fiction
The Terminal Man, a science fiction novel by Michael Crichton (1972), told (as a sideline story) of a computer with telephone modem dialing capability, which had been programmed to randomly dial phone numbers until it hit a modem that is answered by another computer. It then attempted to program the answering computer with its own program, so that the second computer would also begin dialing random numbers, in search of yet another computer to program. The program is assumed to spread exponentially through susceptible computers.
The actual term 'virus' was first used in David Gerrold's 1972 novel, When HARLIE Was One. In that novel, a sentient computer named HARLIE writes viral software to retrieve damaging personal information from other computers to blackmail the man who wants to turn him off.
Virus programs
The Creeper virus was first detected on ARPANET, the forerunner of the Internet, in the early 1970s.[10] Creeper was an experimental self-replicating program written by Bob Thomas at BBN Technologies in 1971.[11] Creeper used the ARPANET to infect DEC PDP-10 computers running the TENEX operating system.[12] Creeper gained access via the ARPANET and copied itself to the remote system where the message, "I'm the creeper, catch me if you can!" was displayed. The Reaper program was created to delete Creeper.[13]
A program called "Elk Cloner" was the first computer virus to appear "in the wild" — that is, outside the single computer or lab where it was created.[14] Written in 1981 by Richard Skrenta, it attached itself to the Apple DOS 3.3 operating system and spread via floppy disk.[14][15] This virus, created as a practical joke when Skrenta was still in high school, was injected in a game on a floppy disk. On its 50th use the Elk Cloner virus would be activated, infecting the computer and displaying a short poem beginning "Elk Cloner: The program with a personality."
The first PC virus in the wild was a boot sector virus dubbed (c)Brain,[16] created in 1986 by the Farooq Alvi Brothers in Lahore, Pakistan, reportedly to deter piracy of the software they had written.[17]
Before computer networks became widespread, most viruses spread on removable media, particularly floppy disks. In the early days of the personal computer, many users regularly exchanged information and programs on floppies. Some viruses spread by infecting programs stored on these disks, while others installed themselves into the disk boot sector, ensuring that they would be run when the user booted the computer from the disk, usually inadvertently. PCs of the era would attempt to boot first from a floppy if one had been left in the drive. Until floppy disks fell out of use, this was the most successful infection strategy and boot sector viruses were the most common in the wild for many years.[1]
Traditional computer viruses emerged in the 1980s, driven by the spread of personal computers and the resultant increase in BBS, modem use, and software sharing. Bulletin board-driven software sharing contributed directly to the spread of Trojan horse programs, and viruses were written to infect popularly traded software. Shareware and bootleg software were equally common vectors for viruses on BBS's.[citation needed]
Macro viruses have become common since the mid-1990s. Most of these viruses are written in the scripting languages for Microsoft programs such as Word and Excel and spread throughout Microsoft Office by infecting documents and spreadsheets. Since Word and Excel were also available for Mac OS, most could also spread to Macintosh computers. Although most of these viruses did not have the ability to send infected e-mail, those viruses which did take advantage of the Microsoft Outlook COM interface.[citation needed]
Some old versions of Microsoft Word allow macros to replicate themselves with additional blank lines. If two macro viruses simultaneously infect a document, the combination of the two, if also self-replicating, can appear as a "mating" of the two and would likely be detected as a virus unique from the "parents".[18]
A virus may also send a web address link as an instant message to all the contacts on an infected machine. If the recipient, thinking the link is from a friend (a trusted source) follows the link to the website, the virus hosted at the site may be able to infect this new computer and continue propagating.
Viruses that spread using cross-site scripting were first reported in 2002,[19] and were academically demonstrated in 2005.[20] There have been multiple instances of the cross-site scripting viruses in the wild, exploiting websites such as MySpace and Yahoo.
Infection strategies
In order to replicate itself, a virus must be permitted to execute code and write to memory. For this reason, many viruses attach themselves to executable files that may be part of legitimate programs. If a user attempts to launch an infected program, the virus' code may be executed simultaneously. Viruses can be divided into two types based on their behavior when they are executed. Nonresident viruses immediately search for other hosts that can be infected, infect those targets, and finally transfer control to the application program they infected. Resident viruses do not search for hosts when they are started. Instead, a resident virus loads itself into memory on execution and transfers control to the host program. The virus stays active in the background and infects new hosts when those files are accessed by other programs or the operating system itself.
Nonresident viruses
Nonresident viruses can be thought of as consisting of a finder module and a replication module. The finder module is responsible for finding new files to infect. For each new executable file the finder module encounters, it calls the replication module to infect that file.
Resident viruses
Resident viruses contain a replication module that is similar to the one that is employed by nonresident viruses. This module, however, is not called by a finder module. The virus loads the replication module into memory when it is executed instead and ensures that this module is executed each time the operating system is called to perform a certain operation. The replication module can be called, for example, each time the operating system executes a file. In this case the virus infects every suitable program that is executed on the computer.
Resident viruses are sometimes subdivided into a category of fast infectors and a category of slow infectors. Fast infectors are designed to infect as many files as possible. A fast infector, for instance, can infect every potential host file that is accessed. This poses a special problem when using anti-virus software, since a virus scanner will access every potential host file on a computer when it performs a system-wide scan. If the virus scanner fails to notice that such a virus is present in memory the virus can "piggy-back" on the virus scanner and in this way infect all files that are scanned. Fast infectors rely on their fast infection rate to spread. The disadvantage of this method is that infecting many files may make detection more likely, because the virus may slow down a computer or perform many suspicious actions that can be noticed by anti-virus software. Slow infectors, on the other hand, are designed to infect hosts infrequently. Some slow infectors, for instance, only infect files when they are copied. Slow infectors are designed to avoid detection by limiting their actions: they are less likely to slow down a computer noticeably and will, at most, infrequently trigger anti-virus software that detects suspicious behavior by programs. The slow infector approach, however, does not seem very successful.
Vectors and hosts
Viruses have targeted various types of transmission media or hosts. This list is not exhaustive:
* Binary executable files (such as COM files and EXE files in MS-DOS, Portable Executable files in Microsoft Windows, the Mach-O format in OSX, and ELF files in Linux)
* Volume Boot Records of floppy disks and hard disk partitions
* The master boot record (MBR) of a hard disk
* General-purpose script files (such as batch files in MS-DOS and Microsoft Windows, VBScript files, and shell script files on Unix-like platforms).
* Application-specific script files (such as Telix-scripts)
* System specific autorun script files (such as Autorun.inf file needed by Windows to automatically run software stored on USB Memory Storage Devices).
* Documents that can contain macros (such as Microsoft Word documents, Microsoft Excel spreadsheets, AmiPro documents, and Microsoft Access database files)
* Cross-site scripting vulnerabilities in web applications (see XSS Worm)
* Arbitrary computer files. An exploitable buffer overflow, format string, race condition or other exploitable bug in a program which reads the file could be used to trigger the execution of code hidden within it. Most bugs of this type can be made more difficult to exploit in computer architectures with protection features such as an execute disable bit and/or address space layout randomization.
PDFs, like HTML, may link to malicious code. PDFs can also be infected with malicious code.
In operating systems that use file extensions to determine program associations (such as Microsoft Windows), the extensions may be hidden from the user by default. This makes it possible to create a file that is of a different type than it appears to the user. For example, an executable may be created named "picture.png.exe", in which the user sees only "picture.png" and therefore assumes that this file is an image and most likely is safe, yet when opened runs the executable on the client machine.
An additional method is to generate the virus code from parts of existing operating system files by using the CRC16/CRC32 data. The initial code can be quite small (tens of bytes) and unpack a fairly large virus. This is analogous to a biological "prion" in the way it works but is vulnerable to signature based detection. This attack has not yet been seen "in the wild".
Methods to avoid detection
In order to avoid detection by users, some viruses employ different kinds of deception. Some old viruses, especially on the MS-DOS platform, make sure that the "last modified" date of a host file stays the same when the file is infected by the virus. This approach does not fool anti-virus software, however, especially those which maintain and date Cyclic redundancy checks on file changes.
Some viruses can infect files without increasing their sizes or damaging the files. They accomplish this by overwriting unused areas of executable files. These are called cavity viruses. For example, the CIH virus, or Chernobyl Virus, infects Portable Executable files. Because those files have many empty gaps, the virus, which was 1 KB in length, did not add to the size of the file.
Some viruses try to avoid detection by killing the tasks associated with antivirus software before it can detect them.
As computers and operating systems grow larger and more complex, old hiding techniques need to be updated or replaced. Defending a computer against viruses may demand that a file system migrate towards detailed and explicit permission for every kind of file access.
Avoiding bait files and other undesirable hosts
A virus needs to infect hosts in order to spread further. In some cases, it might be a bad idea to infect a host program. For example, many anti-virus programs perform an integrity check of their own code. Infecting such programs will therefore increase the likelihood that the virus is detected. For this reason, some viruses are programmed not to infect programs that are known to be part of anti-virus software. Another type of host that viruses sometimes avoid are bait files. Bait files (or goat files) are files that are specially created by anti-virus software, or by anti-virus professionals themselves, to be infected by a virus. These files can be created for various reasons, all of which are related to the detection of the virus:
* Anti-virus professionals can use bait files to take a sample of a virus (i.e. a copy of a program file that is infected by the virus). It is more practical to store and exchange a small, infected bait file, than to exchange a large application program that has been infected by the virus.
* Anti-virus professionals can use bait files to study the behavior of a virus and evaluate detection methods. This is especially useful when the virus is polymorphic. In this case, the virus can be made to infect a large number of bait files. The infected files can be used to test whether a virus scanner detects all versions of the virus.
* Some anti-virus software employs bait files that are accessed regularly. When these files are modified, the anti-virus software warns the user that a virus is probably active on the system.
Since bait files are used to detect the virus, or to make detection possible, a virus can benefit from not infecting them. Viruses typically do this by avoiding suspicious programs, such as small program files or programs that contain certain patterns of 'garbage instructions'.
A related strategy to make baiting difficult is sparse infection. Sometimes, sparse infectors do not infect a host file that would be a suitable candidate for infection in other circumstances. For example, a virus can decide on a random basis whether to infect a file or not, or a virus can only infect host files on particular days of the week.
Stealth
Some viruses try to trick antivirus software by intercepting its requests to the operating system. A virus can hide itself by intercepting the antivirus software’s request to read the file and passing the request to the virus, instead of the OS. The virus can then return an uninfected version of the file to the antivirus software, so that it seems that the file is "clean". Modern antivirus software employs various techniques to counter stealth mechanisms of viruses. The only completely reliable method to avoid stealth is to boot from a medium that is known to be clean.
Self-modification
Most modern antivirus programs try to find virus-patterns inside ordinary programs by scanning them for so-called virus signatures. A signature is a characteristic byte-pattern that is part of a certain virus or family of viruses. If a virus scanner finds such a pattern in a file, it notifies the user that the file is infected. The user can then delete, or (in some cases) "clean" or "heal" the infected file. Some viruses employ techniques that make detection by means of signatures difficult but probably not impossible. These viruses modify their code on each infection. That is, each infected file contains a different variant of the virus.
Encryption with a variable key
A more advanced method is the use of simple encryption to encipher the virus. In this case, the virus consists of a small decrypting module and an encrypted copy of the virus code. If the virus is encrypted with a different key for each infected file, the only part of the virus that remains constant is the decrypting module, which would (for example) be appended to the end. In this case, a virus scanner cannot directly detect the virus using signatures, but it can still detect the decrypting module, which still makes indirect detection of the virus possible. Since these would be symmetric keys, stored on the infected host, it is in fact entirely possible to decrypt the final virus, but this is probably not required, since self-modifying code is such a rarity that it may be reason for virus scanners to at least flag the file as suspicious.
An old, but compact, encryption involves XORing each byte in a virus with a constant, so that the exclusive-or operation had only to be repeated for decryption. It is suspicious for a code to modify itself, so the code to do the encryption/decryption may be part of the signature in many virus definitions.
Polymorphic code
Polymorphic code was the first technique that posed a serious threat to virus scanners. Just like regular encrypted viruses, a polymorphic virus infects files with an encrypted copy of itself, which is decoded by a decryption module. In the case of polymorphic viruses, however, this decryption module is also modified on each infection. A well-written polymorphic virus therefore has no parts which remain identical between infections, making it very difficult to detect directly using signatures. Antivirus software can detect it by decrypting the viruses using an emulator, or by statistical pattern analysis of the encrypted virus body. To enable polymorphic code, the virus has to have a polymorphic engine (also called mutating engine or mutation engine) somewhere in its encrypted body. See Polymorphic code for technical detail on how such engines operate.[21]
Some viruses employ polymorphic code in a way that constrains the mutation rate of the virus significantly. For example, a virus can be programmed to mutate only slightly over time, or it can be programmed to refrain from mutating when it infects a file on a computer that already contains copies of the virus. The advantage of using such slow polymorphic code is that it makes it more difficult for antivirus professionals to obtain representative samples of the virus, because bait files that are infected in one run will typically contain identical or similar samples of the virus. This will make it more likely that the detection by the virus scanner will be unreliable, and that some instances of the virus may be able to avoid detection.
Metamorphic code
To avoid being detected by emulation, some viruses rewrite themselves completely each time they are to infect new executables. Viruses that utilize this technique are said to be metamorphic. To enable metamorphism, a metamorphic engine is needed. A metamorphic virus is usually very large and complex. For example, W32/Simile consisted of over 14000 lines of Assembly language code, 90% of which is part of the metamorphic engine.[22][23]
Vulnerability and countermeasures
The vulnerability of operating systems to viruses
Just as genetic diversity in a population decreases the chance of a single disease wiping out a population, the diversity of software systems on a network similarly limits the destructive potential of viruses. This became a particular concern in the 1990s, when Microsoft gained market dominance in desktop operating systems and office suites. The users of Microsoft software (especially networking software such as Microsoft Outlook and Internet Explorer) are especially vulnerable to the spread of viruses. Microsoft software is targeted by virus writers due to their desktop dominance, and is often criticized for including many errors and holes for virus writers to exploit. Integrated and non-integrated Microsoft applications (such as Microsoft Office) and applications with scripting languages with access to the file system (for example Visual Basic Script (VBS), and applications with networking features) are also particularly vulnerable.
Although Windows is by far the most popular target operating system for virus writers, viruses also exist on other platforms. Any operating system that allows third-party programs to run can theoretically run viruses. Some operating systems are more secure than others. Unix-based operating systems (and NTFS-aware applications on Windows NT based platforms) only allow their users to run executables within their own protected memory space.
An Internet based experiment revealed that there were cases when people willingly pressed a particular button to download a virus. Security analyst Didier Stevens ran a half year advertising campaign on Google AdWords which said "Is your PC virus-free? Get it infected here!". The result was 409 clicks.[24][25]
As of 2006[update], there are relatively few security exploits targeting Mac OS X (with a Unix-based file system and kernel).[26] The number of viruses for the older Apple operating systems, known as Mac OS Classic, varies greatly from source to source, with Apple stating that there are only four known viruses, and independent sources stating there are as many as 63 viruses. Many Mac OS Classic viruses targeted the HyperCard authoring environment. The difference in virus vulnerability between Macs and Windows is a chief selling point, one that Apple uses in their Get a Mac advertising.[27] In January 2009, Symantec announced the discovery of a trojan that targets Macs.[28] This discovery did not gain much coverage until April 2009.[28]
While Linux, and Unix in general, has always natively blocked normal users from having access to make changes to the operating system environment, Windows users are generally not. This difference has continued partly due to the widespread use of administrator accounts in contemporary versions like XP. In 1997, when a virus for Linux was released – known as "Bliss" – leading antivirus vendors issued warnings that Unix-like systems could fall prey to viruses just like Windows.[29] The Bliss virus may be considered characteristic of viruses – as opposed to worms – on Unix systems. Bliss requires that the user run it explicitly, and it can only infect programs that the user has the access to modify. Unlike Windows users, most Unix users do not log in as an administrator user except to install or configure software; as a result, even if a user ran the virus, it could not harm their operating system. The Bliss virus never became widespread, and remains chiefly a research curiosity. Its creator later posted the source code to Usenet, allowing researchers to see how it worked.[30]
The role of software development
Because software is often designed with security features to prevent unauthorized use of system resources, many viruses must exploit software bugs in a system or application to spread. Software development strategies that produce large numbers of bugs will generally also produce potential exploits.
Anti-virus software and other preventive measures
Many users install anti-virus software that can detect and eliminate known viruses after the computer downloads or runs the executable. There are two common methods that an anti-virus software application uses to detect viruses. The first, and by far the most common method of virus detection is using a list of virus signature definitions. This works by examining the content of the computer's memory (its RAM, and boot sectors) and the files stored on fixed or removable drives (hard drives, floppy drives), and comparing those files against a database of known virus "signatures". The disadvantage of this detection method is that users are only protected from viruses that pre-date their last virus definition update. The second method is to use a heuristic algorithm to find viruses based on common behaviors. This method has the ability to detect novel viruses that anti-virus security firms have yet to create a signature for.
Some anti-virus programs are able to scan opened files in addition to sent and received e-mails "on the fly" in a similar manner. This practice is known as "on-access scanning". Anti-virus software does not change the underlying capability of host software to transmit viruses. Users must update their software regularly to patch security holes. Anti-virus software also needs to be regularly updated in order to recognize the latest threats.
One may also minimize the damage done by viruses by making regular backups of data (and the operating systems) on different media, that are either kept unconnected to the system (most of the time), read-only or not accessible for other reasons, such as using different file systems. This way, if data is lost through a virus, one can start again using the backup (which should preferably be recent).
If a backup session on optical media like CD and DVD is closed, it becomes read-only and can no longer be affected by a virus (so long as a virus or infected file was not copied onto the CD/DVD). Likewise, an operating system on a bootable CD can be used to start the computer if the installed operating systems become unusable. Backups on removable media must be carefully inspected before restoration. The Gammima virus, for example, propagates via removable flash drives.[31][32]
Recovery methods
Once a computer has been compromised by a virus, it is usually unsafe to continue using the same computer without completely reinstalling the operating system. However, there are a number of recovery options that exist after a computer has a virus. These actions depend on severity of the type of virus.
Virus removal
One possibility on Windows Me, Windows XP, Windows Vista and Windows 7 is a tool known as System Restore, which restores the registry and critical system files to a previous checkpoint. Often a virus will cause a system to hang, and a subsequent hard reboot will render a system restore point from the same day corrupt. Restore points from previous days should work provided the virus is not designed to corrupt the restore files or also exists in previous restore points.[33] Some viruses, however, disable System Restore and other important tools such as Task Manager and Command Prompt. An example of a virus that does this is CiaDoor. However, many such viruses can be removed by rebooting the computer, entering Windows safe mode, and then using system tools.
Administrators have the option to disable such tools from limited users for various reasons (for example, to reduce potential damage from and the spread of viruses). A virus can modify the registry to do the same even if the Administrator is controlling the computer; it blocks all users including the administrator from accessing the tools. The message "Task Manager has been disabled by your administrator" may be displayed, even to the administrator.[citation needed]
Users running a Microsoft operating system can access Microsoft's website to run a free scan, provided they have their 20-digit registration number. Many websites run by anti-virus software companies provide free online virus scanning, with limited cleaning facilities (the purpose of the sites is to sell anti-virus products). Some websites allow a single suspicious file to be checked by many antivirus programs in one operation.
Operating system reinstallation
Reinstalling the operating system is another approach to virus removal. It involves either reformatting the computer's hard drive and installing the OS and all programs from original media, or restoring the entire partition with a clean backup image. User data can be restored by booting from a Live CD, or putting the hard drive into another computer and booting from its operating system with great care not to infect the second computer by executing any infected programs on the original drive; and once the system has been restored precautions must be taken to avoid reinfection from a restored executable file.
These methods are simple to do, may be faster than disinfecting a computer, and are guaranteed to remove any malware. If the operating system and programs must be reinstalled from scratch, the time and effort to reinstall, reconfigure, and restore user preferences must be taken into account. Restoring from an image is much faster, totally safe, and restores the exact configuration to the state it was in when the image was made, with no further trouble.
See also
* Adware
* Antivirus software
* Computer insecurity
* Computer worm
* Crimeware
* Cryptovirology
* Linux malware
* List of computer virus hoaxes
Monitor padlock.svg Computer security portal
* List of computer viruses
* List of computer viruses (all)
* Malware
* Mobile viruses
* Multipartite virus
* Spam
* Spyware
* Trojan horse (computing)
* Virus hoax
from Wikipedia, the free encyclopedia
Viruses can increase their chances of spreading to other computers by infecting files on a network file system or a file system that is accessed by another computer.[3][4]
As stated above, the term "computer virus" is sometimes used as a catch-all phrase to include all types of malware, even those that do not have the reproductive ability. Malware includes computer viruses, computer worms, Trojan horses, most rootkits, spyware, dishonest adware and other malicious and unwanted software, including true viruses. Viruses are sometimes confused with worms and Trojan horses, which are technically different. A worm can exploit security vulnerabilities to spread itself automatically to other computers through networks, while a Trojan horse is a program that appears harmless but hides malicious functions. Worms and Trojan horses, like viruses, may harm a computer system's data or performance. Some viruses and other malware have symptoms noticeable to the computer user, but many are surreptitious or simply do nothing to call attention to themselves. Some viruses do nothing beyond reproducing themselves.
Contents
[hide]
* 1 History
o 1.1 Academic work
o 1.2 Science Fiction
o 1.3 Virus programs
* 2 Infection strategies
o 2.1 Nonresident viruses
o 2.2 Resident viruses
* 3 Vectors and hosts
* 4 Methods to avoid detection
o 4.1 Avoiding bait files and other undesirable hosts
o 4.2 Stealth
+ 4.2.1 Self-modification
+ 4.2.2 Encryption with a variable key
+ 4.2.3 Polymorphic code
+ 4.2.4 Metamorphic code
* 5 Vulnerability and countermeasures
o 5.1 The vulnerability of operating systems to viruses
o 5.2 The role of software development
o 5.3 Anti-virus software and other preventive measures
o 5.4 Recovery methods
+ 5.4.1 Virus removal
+ 5.4.2 Operating system reinstallation
* 6 See also
* 7 References
* 8 Further reading
* 9 External links
History
Academic work
The first academic work on the theory of computer viruses (although the term "computer virus" was not invented at that time) was done by John von Neumann in 1949 who held lectures at the University of Illinois about the "Theory and Organization of Complicated Automata". The work of von Neumann was later published as the "Theory of self-reproducing automata".[5] In his essay von Neumann postulated that a computer program could reproduce.
In 1972 Veith Risak published his article "Selbstreproduzierende Automaten mit minimaler Informationsübertragung" (Self-reproducing automata with minimal information exchange).[6] The article describes a fully functional virus written in assembler language for a SIEMENS 4004/35 computer system.
In 1980 Jürgen Kraus wrote his diplom thesis "Selbstreproduktion bei Programmen" (Self-reproduction of programs) at the University of Dortmund.[7] In his work Kraus postulated that computer programs can behave in a way similar to biological viruses.
In 1984 Fred Cohen from the University of Southern California wrote his paper "Computer Viruses - Theory and Experiments".[8] It was the first paper to explicitly call a self-reproducing program a "virus"; a term introduced by his mentor Leonard Adleman.
An article that describes "useful virus functionalities" was published by J. B. Gunn under the title "Use of virus functions to provide a virtual APL interpreter under user control" in 1984.[9]
Science Fiction
The Terminal Man, a science fiction novel by Michael Crichton (1972), told (as a sideline story) of a computer with telephone modem dialing capability, which had been programmed to randomly dial phone numbers until it hit a modem that is answered by another computer. It then attempted to program the answering computer with its own program, so that the second computer would also begin dialing random numbers, in search of yet another computer to program. The program is assumed to spread exponentially through susceptible computers.
The actual term 'virus' was first used in David Gerrold's 1972 novel, When HARLIE Was One. In that novel, a sentient computer named HARLIE writes viral software to retrieve damaging personal information from other computers to blackmail the man who wants to turn him off.
Virus programs
The Creeper virus was first detected on ARPANET, the forerunner of the Internet, in the early 1970s.[10] Creeper was an experimental self-replicating program written by Bob Thomas at BBN Technologies in 1971.[11] Creeper used the ARPANET to infect DEC PDP-10 computers running the TENEX operating system.[12] Creeper gained access via the ARPANET and copied itself to the remote system where the message, "I'm the creeper, catch me if you can!" was displayed. The Reaper program was created to delete Creeper.[13]
A program called "Elk Cloner" was the first computer virus to appear "in the wild" — that is, outside the single computer or lab where it was created.[14] Written in 1981 by Richard Skrenta, it attached itself to the Apple DOS 3.3 operating system and spread via floppy disk.[14][15] This virus, created as a practical joke when Skrenta was still in high school, was injected in a game on a floppy disk. On its 50th use the Elk Cloner virus would be activated, infecting the computer and displaying a short poem beginning "Elk Cloner: The program with a personality."
The first PC virus in the wild was a boot sector virus dubbed (c)Brain,[16] created in 1986 by the Farooq Alvi Brothers in Lahore, Pakistan, reportedly to deter piracy of the software they had written.[17]
Before computer networks became widespread, most viruses spread on removable media, particularly floppy disks. In the early days of the personal computer, many users regularly exchanged information and programs on floppies. Some viruses spread by infecting programs stored on these disks, while others installed themselves into the disk boot sector, ensuring that they would be run when the user booted the computer from the disk, usually inadvertently. PCs of the era would attempt to boot first from a floppy if one had been left in the drive. Until floppy disks fell out of use, this was the most successful infection strategy and boot sector viruses were the most common in the wild for many years.[1]
Traditional computer viruses emerged in the 1980s, driven by the spread of personal computers and the resultant increase in BBS, modem use, and software sharing. Bulletin board-driven software sharing contributed directly to the spread of Trojan horse programs, and viruses were written to infect popularly traded software. Shareware and bootleg software were equally common vectors for viruses on BBS's.[citation needed]
Macro viruses have become common since the mid-1990s. Most of these viruses are written in the scripting languages for Microsoft programs such as Word and Excel and spread throughout Microsoft Office by infecting documents and spreadsheets. Since Word and Excel were also available for Mac OS, most could also spread to Macintosh computers. Although most of these viruses did not have the ability to send infected e-mail, those viruses which did take advantage of the Microsoft Outlook COM interface.[citation needed]
Some old versions of Microsoft Word allow macros to replicate themselves with additional blank lines. If two macro viruses simultaneously infect a document, the combination of the two, if also self-replicating, can appear as a "mating" of the two and would likely be detected as a virus unique from the "parents".[18]
A virus may also send a web address link as an instant message to all the contacts on an infected machine. If the recipient, thinking the link is from a friend (a trusted source) follows the link to the website, the virus hosted at the site may be able to infect this new computer and continue propagating.
Viruses that spread using cross-site scripting were first reported in 2002,[19] and were academically demonstrated in 2005.[20] There have been multiple instances of the cross-site scripting viruses in the wild, exploiting websites such as MySpace and Yahoo.
Infection strategies
In order to replicate itself, a virus must be permitted to execute code and write to memory. For this reason, many viruses attach themselves to executable files that may be part of legitimate programs. If a user attempts to launch an infected program, the virus' code may be executed simultaneously. Viruses can be divided into two types based on their behavior when they are executed. Nonresident viruses immediately search for other hosts that can be infected, infect those targets, and finally transfer control to the application program they infected. Resident viruses do not search for hosts when they are started. Instead, a resident virus loads itself into memory on execution and transfers control to the host program. The virus stays active in the background and infects new hosts when those files are accessed by other programs or the operating system itself.
Nonresident viruses
Nonresident viruses can be thought of as consisting of a finder module and a replication module. The finder module is responsible for finding new files to infect. For each new executable file the finder module encounters, it calls the replication module to infect that file.
Resident viruses
Resident viruses contain a replication module that is similar to the one that is employed by nonresident viruses. This module, however, is not called by a finder module. The virus loads the replication module into memory when it is executed instead and ensures that this module is executed each time the operating system is called to perform a certain operation. The replication module can be called, for example, each time the operating system executes a file. In this case the virus infects every suitable program that is executed on the computer.
Resident viruses are sometimes subdivided into a category of fast infectors and a category of slow infectors. Fast infectors are designed to infect as many files as possible. A fast infector, for instance, can infect every potential host file that is accessed. This poses a special problem when using anti-virus software, since a virus scanner will access every potential host file on a computer when it performs a system-wide scan. If the virus scanner fails to notice that such a virus is present in memory the virus can "piggy-back" on the virus scanner and in this way infect all files that are scanned. Fast infectors rely on their fast infection rate to spread. The disadvantage of this method is that infecting many files may make detection more likely, because the virus may slow down a computer or perform many suspicious actions that can be noticed by anti-virus software. Slow infectors, on the other hand, are designed to infect hosts infrequently. Some slow infectors, for instance, only infect files when they are copied. Slow infectors are designed to avoid detection by limiting their actions: they are less likely to slow down a computer noticeably and will, at most, infrequently trigger anti-virus software that detects suspicious behavior by programs. The slow infector approach, however, does not seem very successful.
Vectors and hosts
Viruses have targeted various types of transmission media or hosts. This list is not exhaustive:
* Binary executable files (such as COM files and EXE files in MS-DOS, Portable Executable files in Microsoft Windows, the Mach-O format in OSX, and ELF files in Linux)
* Volume Boot Records of floppy disks and hard disk partitions
* The master boot record (MBR) of a hard disk
* General-purpose script files (such as batch files in MS-DOS and Microsoft Windows, VBScript files, and shell script files on Unix-like platforms).
* Application-specific script files (such as Telix-scripts)
* System specific autorun script files (such as Autorun.inf file needed by Windows to automatically run software stored on USB Memory Storage Devices).
* Documents that can contain macros (such as Microsoft Word documents, Microsoft Excel spreadsheets, AmiPro documents, and Microsoft Access database files)
* Cross-site scripting vulnerabilities in web applications (see XSS Worm)
* Arbitrary computer files. An exploitable buffer overflow, format string, race condition or other exploitable bug in a program which reads the file could be used to trigger the execution of code hidden within it. Most bugs of this type can be made more difficult to exploit in computer architectures with protection features such as an execute disable bit and/or address space layout randomization.
PDFs, like HTML, may link to malicious code. PDFs can also be infected with malicious code.
In operating systems that use file extensions to determine program associations (such as Microsoft Windows), the extensions may be hidden from the user by default. This makes it possible to create a file that is of a different type than it appears to the user. For example, an executable may be created named "picture.png.exe", in which the user sees only "picture.png" and therefore assumes that this file is an image and most likely is safe, yet when opened runs the executable on the client machine.
An additional method is to generate the virus code from parts of existing operating system files by using the CRC16/CRC32 data. The initial code can be quite small (tens of bytes) and unpack a fairly large virus. This is analogous to a biological "prion" in the way it works but is vulnerable to signature based detection. This attack has not yet been seen "in the wild".
Methods to avoid detection
In order to avoid detection by users, some viruses employ different kinds of deception. Some old viruses, especially on the MS-DOS platform, make sure that the "last modified" date of a host file stays the same when the file is infected by the virus. This approach does not fool anti-virus software, however, especially those which maintain and date Cyclic redundancy checks on file changes.
Some viruses can infect files without increasing their sizes or damaging the files. They accomplish this by overwriting unused areas of executable files. These are called cavity viruses. For example, the CIH virus, or Chernobyl Virus, infects Portable Executable files. Because those files have many empty gaps, the virus, which was 1 KB in length, did not add to the size of the file.
Some viruses try to avoid detection by killing the tasks associated with antivirus software before it can detect them.
As computers and operating systems grow larger and more complex, old hiding techniques need to be updated or replaced. Defending a computer against viruses may demand that a file system migrate towards detailed and explicit permission for every kind of file access.
Avoiding bait files and other undesirable hosts
A virus needs to infect hosts in order to spread further. In some cases, it might be a bad idea to infect a host program. For example, many anti-virus programs perform an integrity check of their own code. Infecting such programs will therefore increase the likelihood that the virus is detected. For this reason, some viruses are programmed not to infect programs that are known to be part of anti-virus software. Another type of host that viruses sometimes avoid are bait files. Bait files (or goat files) are files that are specially created by anti-virus software, or by anti-virus professionals themselves, to be infected by a virus. These files can be created for various reasons, all of which are related to the detection of the virus:
* Anti-virus professionals can use bait files to take a sample of a virus (i.e. a copy of a program file that is infected by the virus). It is more practical to store and exchange a small, infected bait file, than to exchange a large application program that has been infected by the virus.
* Anti-virus professionals can use bait files to study the behavior of a virus and evaluate detection methods. This is especially useful when the virus is polymorphic. In this case, the virus can be made to infect a large number of bait files. The infected files can be used to test whether a virus scanner detects all versions of the virus.
* Some anti-virus software employs bait files that are accessed regularly. When these files are modified, the anti-virus software warns the user that a virus is probably active on the system.
Since bait files are used to detect the virus, or to make detection possible, a virus can benefit from not infecting them. Viruses typically do this by avoiding suspicious programs, such as small program files or programs that contain certain patterns of 'garbage instructions'.
A related strategy to make baiting difficult is sparse infection. Sometimes, sparse infectors do not infect a host file that would be a suitable candidate for infection in other circumstances. For example, a virus can decide on a random basis whether to infect a file or not, or a virus can only infect host files on particular days of the week.
Stealth
Some viruses try to trick antivirus software by intercepting its requests to the operating system. A virus can hide itself by intercepting the antivirus software’s request to read the file and passing the request to the virus, instead of the OS. The virus can then return an uninfected version of the file to the antivirus software, so that it seems that the file is "clean". Modern antivirus software employs various techniques to counter stealth mechanisms of viruses. The only completely reliable method to avoid stealth is to boot from a medium that is known to be clean.
Self-modification
Most modern antivirus programs try to find virus-patterns inside ordinary programs by scanning them for so-called virus signatures. A signature is a characteristic byte-pattern that is part of a certain virus or family of viruses. If a virus scanner finds such a pattern in a file, it notifies the user that the file is infected. The user can then delete, or (in some cases) "clean" or "heal" the infected file. Some viruses employ techniques that make detection by means of signatures difficult but probably not impossible. These viruses modify their code on each infection. That is, each infected file contains a different variant of the virus.
Encryption with a variable key
A more advanced method is the use of simple encryption to encipher the virus. In this case, the virus consists of a small decrypting module and an encrypted copy of the virus code. If the virus is encrypted with a different key for each infected file, the only part of the virus that remains constant is the decrypting module, which would (for example) be appended to the end. In this case, a virus scanner cannot directly detect the virus using signatures, but it can still detect the decrypting module, which still makes indirect detection of the virus possible. Since these would be symmetric keys, stored on the infected host, it is in fact entirely possible to decrypt the final virus, but this is probably not required, since self-modifying code is such a rarity that it may be reason for virus scanners to at least flag the file as suspicious.
An old, but compact, encryption involves XORing each byte in a virus with a constant, so that the exclusive-or operation had only to be repeated for decryption. It is suspicious for a code to modify itself, so the code to do the encryption/decryption may be part of the signature in many virus definitions.
Polymorphic code
Polymorphic code was the first technique that posed a serious threat to virus scanners. Just like regular encrypted viruses, a polymorphic virus infects files with an encrypted copy of itself, which is decoded by a decryption module. In the case of polymorphic viruses, however, this decryption module is also modified on each infection. A well-written polymorphic virus therefore has no parts which remain identical between infections, making it very difficult to detect directly using signatures. Antivirus software can detect it by decrypting the viruses using an emulator, or by statistical pattern analysis of the encrypted virus body. To enable polymorphic code, the virus has to have a polymorphic engine (also called mutating engine or mutation engine) somewhere in its encrypted body. See Polymorphic code for technical detail on how such engines operate.[21]
Some viruses employ polymorphic code in a way that constrains the mutation rate of the virus significantly. For example, a virus can be programmed to mutate only slightly over time, or it can be programmed to refrain from mutating when it infects a file on a computer that already contains copies of the virus. The advantage of using such slow polymorphic code is that it makes it more difficult for antivirus professionals to obtain representative samples of the virus, because bait files that are infected in one run will typically contain identical or similar samples of the virus. This will make it more likely that the detection by the virus scanner will be unreliable, and that some instances of the virus may be able to avoid detection.
Metamorphic code
To avoid being detected by emulation, some viruses rewrite themselves completely each time they are to infect new executables. Viruses that utilize this technique are said to be metamorphic. To enable metamorphism, a metamorphic engine is needed. A metamorphic virus is usually very large and complex. For example, W32/Simile consisted of over 14000 lines of Assembly language code, 90% of which is part of the metamorphic engine.[22][23]
Vulnerability and countermeasures
The vulnerability of operating systems to viruses
Just as genetic diversity in a population decreases the chance of a single disease wiping out a population, the diversity of software systems on a network similarly limits the destructive potential of viruses. This became a particular concern in the 1990s, when Microsoft gained market dominance in desktop operating systems and office suites. The users of Microsoft software (especially networking software such as Microsoft Outlook and Internet Explorer) are especially vulnerable to the spread of viruses. Microsoft software is targeted by virus writers due to their desktop dominance, and is often criticized for including many errors and holes for virus writers to exploit. Integrated and non-integrated Microsoft applications (such as Microsoft Office) and applications with scripting languages with access to the file system (for example Visual Basic Script (VBS), and applications with networking features) are also particularly vulnerable.
Although Windows is by far the most popular target operating system for virus writers, viruses also exist on other platforms. Any operating system that allows third-party programs to run can theoretically run viruses. Some operating systems are more secure than others. Unix-based operating systems (and NTFS-aware applications on Windows NT based platforms) only allow their users to run executables within their own protected memory space.
An Internet based experiment revealed that there were cases when people willingly pressed a particular button to download a virus. Security analyst Didier Stevens ran a half year advertising campaign on Google AdWords which said "Is your PC virus-free? Get it infected here!". The result was 409 clicks.[24][25]
As of 2006[update], there are relatively few security exploits targeting Mac OS X (with a Unix-based file system and kernel).[26] The number of viruses for the older Apple operating systems, known as Mac OS Classic, varies greatly from source to source, with Apple stating that there are only four known viruses, and independent sources stating there are as many as 63 viruses. Many Mac OS Classic viruses targeted the HyperCard authoring environment. The difference in virus vulnerability between Macs and Windows is a chief selling point, one that Apple uses in their Get a Mac advertising.[27] In January 2009, Symantec announced the discovery of a trojan that targets Macs.[28] This discovery did not gain much coverage until April 2009.[28]
While Linux, and Unix in general, has always natively blocked normal users from having access to make changes to the operating system environment, Windows users are generally not. This difference has continued partly due to the widespread use of administrator accounts in contemporary versions like XP. In 1997, when a virus for Linux was released – known as "Bliss" – leading antivirus vendors issued warnings that Unix-like systems could fall prey to viruses just like Windows.[29] The Bliss virus may be considered characteristic of viruses – as opposed to worms – on Unix systems. Bliss requires that the user run it explicitly, and it can only infect programs that the user has the access to modify. Unlike Windows users, most Unix users do not log in as an administrator user except to install or configure software; as a result, even if a user ran the virus, it could not harm their operating system. The Bliss virus never became widespread, and remains chiefly a research curiosity. Its creator later posted the source code to Usenet, allowing researchers to see how it worked.[30]
The role of software development
Because software is often designed with security features to prevent unauthorized use of system resources, many viruses must exploit software bugs in a system or application to spread. Software development strategies that produce large numbers of bugs will generally also produce potential exploits.
Anti-virus software and other preventive measures
Many users install anti-virus software that can detect and eliminate known viruses after the computer downloads or runs the executable. There are two common methods that an anti-virus software application uses to detect viruses. The first, and by far the most common method of virus detection is using a list of virus signature definitions. This works by examining the content of the computer's memory (its RAM, and boot sectors) and the files stored on fixed or removable drives (hard drives, floppy drives), and comparing those files against a database of known virus "signatures". The disadvantage of this detection method is that users are only protected from viruses that pre-date their last virus definition update. The second method is to use a heuristic algorithm to find viruses based on common behaviors. This method has the ability to detect novel viruses that anti-virus security firms have yet to create a signature for.
Some anti-virus programs are able to scan opened files in addition to sent and received e-mails "on the fly" in a similar manner. This practice is known as "on-access scanning". Anti-virus software does not change the underlying capability of host software to transmit viruses. Users must update their software regularly to patch security holes. Anti-virus software also needs to be regularly updated in order to recognize the latest threats.
One may also minimize the damage done by viruses by making regular backups of data (and the operating systems) on different media, that are either kept unconnected to the system (most of the time), read-only or not accessible for other reasons, such as using different file systems. This way, if data is lost through a virus, one can start again using the backup (which should preferably be recent).
If a backup session on optical media like CD and DVD is closed, it becomes read-only and can no longer be affected by a virus (so long as a virus or infected file was not copied onto the CD/DVD). Likewise, an operating system on a bootable CD can be used to start the computer if the installed operating systems become unusable. Backups on removable media must be carefully inspected before restoration. The Gammima virus, for example, propagates via removable flash drives.[31][32]
Recovery methods
Once a computer has been compromised by a virus, it is usually unsafe to continue using the same computer without completely reinstalling the operating system. However, there are a number of recovery options that exist after a computer has a virus. These actions depend on severity of the type of virus.
Virus removal
One possibility on Windows Me, Windows XP, Windows Vista and Windows 7 is a tool known as System Restore, which restores the registry and critical system files to a previous checkpoint. Often a virus will cause a system to hang, and a subsequent hard reboot will render a system restore point from the same day corrupt. Restore points from previous days should work provided the virus is not designed to corrupt the restore files or also exists in previous restore points.[33] Some viruses, however, disable System Restore and other important tools such as Task Manager and Command Prompt. An example of a virus that does this is CiaDoor. However, many such viruses can be removed by rebooting the computer, entering Windows safe mode, and then using system tools.
Administrators have the option to disable such tools from limited users for various reasons (for example, to reduce potential damage from and the spread of viruses). A virus can modify the registry to do the same even if the Administrator is controlling the computer; it blocks all users including the administrator from accessing the tools. The message "Task Manager has been disabled by your administrator" may be displayed, even to the administrator.[citation needed]
Users running a Microsoft operating system can access Microsoft's website to run a free scan, provided they have their 20-digit registration number. Many websites run by anti-virus software companies provide free online virus scanning, with limited cleaning facilities (the purpose of the sites is to sell anti-virus products). Some websites allow a single suspicious file to be checked by many antivirus programs in one operation.
Operating system reinstallation
Reinstalling the operating system is another approach to virus removal. It involves either reformatting the computer's hard drive and installing the OS and all programs from original media, or restoring the entire partition with a clean backup image. User data can be restored by booting from a Live CD, or putting the hard drive into another computer and booting from its operating system with great care not to infect the second computer by executing any infected programs on the original drive; and once the system has been restored precautions must be taken to avoid reinfection from a restored executable file.
These methods are simple to do, may be faster than disinfecting a computer, and are guaranteed to remove any malware. If the operating system and programs must be reinstalled from scratch, the time and effort to reinstall, reconfigure, and restore user preferences must be taken into account. Restoring from an image is much faster, totally safe, and restores the exact configuration to the state it was in when the image was made, with no further trouble.
See also
* Adware
* Antivirus software
* Computer insecurity
* Computer worm
* Crimeware
* Cryptovirology
* Linux malware
* List of computer virus hoaxes
Monitor padlock.svg Computer security portal
* List of computer viruses
* List of computer viruses (all)
* Malware
* Mobile viruses
* Multipartite virus
* Spam
* Spyware
* Trojan horse (computing)
* Virus hoax
from Wikipedia, the free encyclopedia
Monday, January 10, 2011
home computers
Home computer
From Wikipedia, the free encyclopedia
Jump to: navigation, search
This article is primarily about a certain class of Personal computers from the late 1970s to mid-1980s, see Domotics or Home servers for home computers used in home automation.
Children playing Paperboy on an Amstrad CPC 464 in the 1980s
Most home computers, such as this Tandy Color Computer 3, featured a version of the BASIC programming language. The sometimes-sprawling nature of the well-outfitted home computer system is very much in evidence.
Home computers were a class of personal computers entering the market in 1977, and becoming increasingly common during the 1980s.[1] They were marketed to consumers as affordable, accessible personal computers and more capable than video game consoles. These computers typically cost much less than business, scientific or engineering-oriented desktop personal computers of the time, and were generally less powerful in terms of memory and expandability. However, a home computer often had better graphics and sound than contemporary business personal computers. Usually they were bought for education, game play, and personal productivity use such as word processing.
Advertisements for early home computers were rife with possibilities for their use in the home, from cataloging recipes to personal finance to home automation,[2][3][4] but these were seldom realized in practice. For example, using a typical 1980s home computer as a home automation appliance would require the computer to be kept powered on at all times and dedicated to this task. Personal finance and database use required tedious data entry. If no packaged software was available for a particular application, the home computer user was required to learn computer programming; a significant time commitment many weren't willing to make. Still, for many the home computer offered the first opportunity to learn to program.[5]
Today the line between 'business' and 'home' computer market segments has blurred or vanished completely, since both categories of computers now typically use the same processor architectures, peripherals, operating systems, and applications. Often the only difference may be the sales outlet through which they are purchased. Another change from the home computer era is that the once-common endeavour of writing one's own software programs has almost vanished from home computer use.[6]
A RadioShack TRS-80 released in 1977.
The Commodore PET released in 1977. This model featured a built in Datassette drive.
Contents
[hide]
* 1 Background
* 2 Technology
* 3 Radio frequency interference
* 4 The Home Computer "Revolution"
* 5 Use today
* 6 Notable home computers
o 6.1 1970s
o 6.2 1980s
* 7 See also
* 8 References
* 9 External links
[edit] Background
Computers became affordable for the general public due to the mass production of the microprocessor. Early microcomputers had front-mounted switches and blinkenlights to control and indicate internal system status, and were often sold in kit form. These kits would contain an empty printed circuit board which the buyer would fill with the integrated circuits, other individual electronic components, wires and connectors, and then hand-solder all the connections.[7] In contrast, home computers were designed to be used by the average consumer, not necessarily an electronics hobbyist.
While two early home computers (Sinclair ZX80, and Acorn Atom) could be bought either in kit form or assembled, most home computers were only sold pre-assembled. They were enclosed in plastic or metal cases similar in appearance to typewriter or hi-fi equipment enclosures, which were more familiar and attractive to consumers and lower cost than the metal card-cage enclosures used by the Altair and similar computers. A keyboard was usually built into the same case as the motherboard. Ports for plug-in peripheral devices such as a video display, cassette tape recorders, joysticks, and (later) disk drives either were built-in or available as add-on cards. Usually the manufacturer would sell peripheral devices designed to be compatible with their computers as extra cost accessories. Often peripherals were not interchangeable between brands of home computer, or even between successive models of the same brand.
To save the cost of a dedicated monitor, the home computer often would connect either directly or through an RF modulator to the family TV set which served as both video display and sound system.[8]
Almost universally, home computers had a version of a BASIC interpreter combined with a line editor in permanent read-only memory with which one could type in BASIC programs and execute them immediately. In direct mode, the BASIC interpreter was also used as the user interface, and given tasks such as loading, saving, managing, and running files.[9] One exception was the Jupiter Ace, which had a Forth interpreter built in. A programming language was seen as a requirement for any computer of the era due to the dearth of commercially-available productivity software as well as the widely varying applications users had in mind for the new devices.
After the success of systems like the RadioShack TRS-80, the Commodore PET and the Apple II in 1977, large numbers of new machines of all types began to appear during the late 1970s and early 1980s. Some home computers sold many units over several years, such as the BBC Micro, Sinclair ZX Spectrum, Atari 800XL and Commodore 64, and attracted third-party software development. By 1982, an estimated 621,000 home computers were in use in the United States, at an average sales price of $530.[10]
Low-end home computers competed with video game consoles. The markets weren't entirely distinct, as both could be used for games. A common marketing tactic was to show a computer system and console playing games side by side, then emphasising the computer's greater ability by showing it running user-created programs, education software, word processing, spreadsheet and other applications while the game console showed a blank screen or continued playing the same repetitive game. Books were available for most models of computer with titles along the lines of "64 Amazing BASIC Games for the Commodore 64". These books would include type in program listings and sometimes an mail-in offer to obtain the programs on disk or cassette and were a popular and low-cost means of both learning to program and software distribution. Some video game consoles offered "programming packs", consisting of a version of BASIC in a ROM cartridge. For the ColecoVision console Coleco even announced an expansion module which would convert it into a full-fledged computer system. This never materialised, but a standalone computer, the Coleco Adam was eventually released.[11] During the peak years of the home computer market, scores of models were produced, usually with little or no thought given to compatibility between different manufacturers or even within product lines of one manufacturer.[12] The concept of a computer platform did not exist, except for the Japanese MSX standard.[13]
Soon after its August 1981 introduction, the IBM Personal Computer would eventually become the standard platform used in business. This was largely due to the system's open architecture, which encouraged production of third-party clones of the design. The Visicalc-running Apple II would be quickly displaced for office use,[14] but Apple Computer's 1984 release of the Apple Macintosh introduced a new model for interacting with the computer to the market, which IBM-compatible computers would eventually also adopt.[15] Throughout the 1980s, PCs spread through businesses like wildfire, leading, by the end of the decade, to sub-$1000 IBM PC XT-class white box machines, usually built in Asia and sold by US companies like PCs Limited.
The declining cost of the IBM-compatibles on the one hand, and the greatly increased graphics, sound, and storage abilities of fourth generation video game consoles such as the Sega Genesis and Super Nintendo Entertainment System on the other, combined to cause the market segment for home computers to vanish by the early 1990s in the US. In Europe, the home computer remained a distinct presence for a few years more, with the Amiga and Atari ST lines being the dominant players, but today a computer bought for home use anywhere will be very similar to those used in offices - made by the same manufacturers, with compatible peripherals, operating systems, and application software.
[edit] Technology
A Commodore 64c system, showing the basic layout of a typical home computer system of the era. Pictured are the CPU/keyboard unit, floppy disk drive, and dedicated color monitor. Many systems also had a dot matrix printer for producing paper output.
Eastern Bloc computers were often significantly different in appearance from western computers. Pictured is a KC 85/3 with its keyboard placed on top, by VEB Mikroelektronik Mühlhausen released in 1986 and based on an East German Zilog Z80 clone.
The Soviet Elektronika BK0010-01 home computer was based on the К1801ВМ1 (Soviet LSI-11-compatible CPU) and shared architectural similarities with PDP-11.
Many home computers were superficially similar. Most had a keyboard integrated into the case; sometimes a cheap-to-make membrane or chiclet keyboard in the early days, although full-travel keyboards quickly became universal due to overwhelming consumer preference. Most systems could use an RF modulator to display 20–40 column text output on a home television. Indeed, the use of a television set as a display almost defines the pre-PC home computer. Although dedicated composite or "green screen" computer displays were available for this market segment and offered sharper text display and sometimes increased graphics resolution, a monitor was often a later purchase made only after users had bought a floppy disk drive, printer, modem, and the other pieces of a full system. This "peripherals sold separately" approach is another defining characteristic of the home computer era. Many first time computer buyers brought a base C-64 system home and hooked it up to their TV only to find they needed to buy a disk drive or Datassette before they could make use of it as anything but a game machine.
In the early part of the 1980s, the dominant microprocessors used in home computers were the 8-bit MOS Technology 6502 (Apple, Commodore, Atari) and Zilog Z80 (TRS-80). A notable exception was the TI-99 series, announced in 1979 with a 16-bit TMS9900 CPU.[16]
Processor clock rates were typically 1–2 MHz for 6502 based CPU's and 2–4 MHz for Z80 based systems (yielding roughly equal performance), but this aspect was not emphasized by users or manufacturers, as the systems' limited RAM capacity, graphics abilities and storage options had more of an effect on performance than CPU speed. Clock rate was considered a technical detail of interest only to users needing accurate timing for their own programs. To economize on component cost, often the same crystal used to produce color television compatible signals was also divided down and used for the processor clock. This meant processors rarely operated at their full rated speed, and had the side-effect that European and North American versions of the same home computer operated at slightly different speeds and different video resolution due to different television standards.
Initially, many home computers used the then-ubiquitous compact audio cassettes as a storage mechanism. A rough analogy to how this worked would be to place a recorder on the phone line as a file was uploaded by modem to "save" it, and playing the recording back through the modem to "load". Most cassette implementations were notoriously slow and unreliable, but floppy disk drives as found on more costly business-oriented microcomputers were expensive and used disks eight inches wide at the beginning of the home computer era. Costs declined toward the end of the 1980s as sales of microcomputers increased and mass production of 5.25" drive mechanisms enabled economy of scale. The 5.25" floppy disk drives would remain the standard throughout the 8-bit era. Though external 3.5" drives were made available for most systems toward the latter part of the 1980s, most software sold for 8-bit home computers remained on 5.25" disks; 3.5" drives were used for data storage. Standardization of disk formats was not common; sometimes even different models from the same manufacturer used different disk formats.
Various copy protection schemes were developed for floppy disks; most were broken in short order. Many users would only tolerate copy protection for games, as wear and tear on disks was a significant issue in an entirely floppy-based system. The ability to make a "working backup" disk of vital application software was seen as important. Copy programs that advertised their ability to copy or even remove common protection schemes were a common category of utility software in this pre-DMCA era.
In contrast to modern computers, home computers most often had their operating system (OS) stored in ROM chips. This made startup times very fast - no more than a few seconds - but made OS upgrades difficult or impossible without buying a new unit. Usually only the most severe bugs were fixed by issuing new ROMs to replace the old ones at the user's cost. In another defining characteristic of the home computer, instead of a command line, the BASIC interpreter served double duty as a user interface. Coupled to a character-based screen or line editor, BASIC's file management commands could be entered in direct mode. The operating systems provided little other support to application programs, but application programs usually accessed hardware directly to perform a specific task, often switching out the ROM based OS anyway to free the address space it occupied and maximize RAM capacity. As multitasking was not common on home computers until late in the '80s, this lack of API support wasn't much of a liability.
In an enduring reflection of their early cassette-oriented nature, most home computers loaded their disk operating system (DOS) separately from the main OS. The DOS was only used to send commands to the floppy disk drive and was not loaded to perform other computing functions. One notable exception was Commodore, whose disk drives actually contained a 6502 processor and Commodore DOS in ROM. Many home computers also had a cartridge interface which accepted ROM-based software. This was occasionally used for expansion or upgrades such as fast loaders. Application software on cartridge did exist, but the vast majority of cartridges were games.[17]
From about 1985, the high end of the home computer market began to be dominated by "next generation" home computers using the 16-bit Motorola 68000 chip, which enabled the greatly increased abilities of the Amiga and Atari ST series. Graphics resolutions approximately doubled, and color palettes increased from dozens to hundreds or thousands of colors available. Stereo sound became standard for the first time. Clock rates on these systems were approximately 8 MHz with RAM capacities of 256 kB (for the base Amiga 1000 system) up to 1024 kB (1 megabyte, a milestone, first seen on the Atari 1040 ST). These systems had built-in 3.5" floppy disks from the beginning but 5.25" drives were made available to facilitate data exchange with the IBM PC compatibles. The Amiga and ST both had GUIs inspired by the Apple Macintosh, but at a list price of $2495 (over $5000 in 2007 dollars), the Macintosh itself was too expensive for most households.
[edit] Radio frequency interference
After the first wave of computers landed in American homes, the United States Federal Communications Commission (FCC) began receiving complaints of electromagnetic interference to television reception. By 1979 the FCC demanded that home computer makers submit samples for radio frequency interference testing. It was found that "first generation" home computers, which often included their own screens, emitted too much radio frequency noise for household use. Some companies appealed to the FCC to waive the requirements for home computers, while others (with compliant designs) objected to the waiver. Eventually techniques to suppress interference became standardized.[18]
[edit] The Home Computer "Revolution"
See also: Microcomputer revolution
This section is written like a personal reflection or essay and may require cleanup. Please help improve it by rewriting it in an encyclopedic style. (September 2010)
In the late 1970s and early 1980s, from about 1977 to 1983, it was widely predicted [19] that computers would soon revolutionize many aspects of home and family life as they had business practices in the previous decades.[20] Mothers would keep their recipe catalog in "kitchen computer" databases and turn to a medical database for help with child care, fathers would use the family's computer to manage family finances and track automobile maintenance. Children would use disk-based encyclopedias for school work and would be avid video gamers. Home automation would bring about the intelligent home of the '80s. Using Videotex, NAPLPS or some sort of as-yet unrealized computer technology, television would gain interactivity. The personalized newspaper was a commonly-predicted application. Morning coffee would be brewed automatically under computer control. The same computer would control the house lighting and temperature. Robots would take the garbage out, and be programmable to perform new tasks by the home computer. Electronics were expensive, so it was generally assumed that each home would have only one multitasking computer for the entire family to use in a timesharing arrangement, with interfaces to the various devices it was expected to control.
“ The single most important item in 2008 households is the computer. These electronic brains govern everything from meal preparation and waking up the household to assembling shopping lists and keeping track of the bank balance. Sensors in kitchen appliances, climatizing units, communicators, power supply and other household utilities warn the computer when the item is likely to fail. A repairman will show up even before any obvious breakdown occurs.
Computers also handle travel reservations, relay telephone messages, keep track of birthdays and anniversaries, compute taxes and even figure the monthly bills for electricity, water, telephone and other utilities. Not every family has its private computer. Many families reserve time on a city or regional computer to serve their needs. The machine tallies up its own services and submits a bill, just as it does with other utilities.[21]
”
—Mechanix Illustrated, November 1968 edition
All this was predicted to be commonplace sometime before the end of the decade, but virtually every aspect of the predicted revolution would be delayed or prove entirely impractical. The computers available to consumers of the time period just weren't powerful enough to perform any single task required to realize this vision, much less do them all simultaneously. The home computers of the early 1980s could not multitask. Even if they could, memory capacities were too small to hold entire databases or financial records, floppy disk-based storage was inadequate in both capacity and speed for multimedia work, and the graphics of the systems could only display blocky, unrealistic images and blurry, jagged text. Before long, a backlash set in—computer users were "geeks", "nerds" or worse, "hackers". The North American video game crash of 1983 soured many on home computer technology. The computers that were bought for use in the family room were either forgotten in closets or relegated to basements and children's bedrooms to be used exclusively for games and the occasional book report.
It took another 10 years for technology to mature, for the graphical user interface to make the computer approachable for non-technical users, and for the internet to provide a compelling reason for most people to want a computer in their homes. Predicted aspects of the revolution were left by the wayside or modified in the face of an emerging reality. The cost of electronics dropped precipitously and today many families have a computer for each family member, or a laptop for mom's active lifestyle, a desktop for dad with the kids sharing a computer. Encyclopedias, recipe catalogs and medical databases are kept online and accessed over the world wide web -- not stored locally on floppy disks or CD-ROM. TV has yet to gain substantial interactivity; instead, the web has evolved alongside television, but the HTPC or services like Netflix, Google TV or Apple TV along with internet video sites such as YouTube and Hulu may one day replace traditional broadcast and cable television. Our coffee may be brewed automatically every morning, but the computer is a simple one embedded in the coffee maker, not under external control. As of 2008, robots are just beginning to make an impact in the home, with Roomba and Aibo leading the charge.
This delay wasn't out of keeping with other technologies newly introduced to an unprepared public. Early motorists were widely derided with the cry of "Get a horse!"[22] until the automobile was accepted. Television languished in research labs for decades before regular public broadcasts began. In an example of changing applications for technology, before the invention of radio, the telephone was used to distribute opera and news reports, whose subscribers were denounced as "illiterate, blind, bedridden and incurably lazy people".[23] Likewise, the acceptance of computers into daily life today is a product of continuing refinement of both technology and perception.
[edit] Use today
As older computer hardware becomes obsolete (and in some cases nonfunctional), and the supply of replacement parts dwindles, it has become popular among enthusiasts[24] to emulate these machines, their environments[25] on modern hardware. One of the more well-known emulators is the Multiple Emulator Super System which can emulate most of the better known home computers. A more or less complete list of home computer emulators can be found here. Games for many 8 and 16 bit home computers are becoming available for the Wii Virtual Console.
Retrocomputing is gaining in popularity, with many enthusiasts using real Commodore 64 hardware to perform modern tasks such as surfing the web and email. The 64 has also been repackaged as the C-One and C64 Direct-to-TV, both designed by Jeri Ellsworth with modern enhancements.[26] Many enthusiasts have started to collect home computers, with older and rarer systems being much sought after. Sometimes the collections turn into a virtual museum presented on web sites.[27]
As cloud computing develops, future home computer users may opt for the all-in-one simplicity of a console, netbook, nettop or set top box over a standard PC, possibly running a "stripped down" operating system like Chrome OS. This could lead to a new era of home computers as distinct from business computers running a more traditional OS. Game consoles are starting to incorporate most of the most common uses for PCs in the home - in addition to gaming, all of the 2008 console generation feature music playing ability, and the Wii and PlayStation 3 can be used to browse the web. The Xbox 360 also features instant messaging. Through the web browser component, word processing, email and photo editing are available on these consoles using Web applications. Laptops and tablet computers such as the iPad are becoming popular for use in the home, which may redefine the term personal computer itself as a truly personal accessory, similar to a digital audio player or mobile phone and used by an individual in both work and leisure settings.
[edit] Notable home computers
The 1977 Apple II with 2 Disk II disk drives and an Apple monitor
The list below shows many of the most popular or significant home computers of the late 1970s and of the 1980s.
The most popular home computers in the USA up to 1985 were: the TRS-80 (1977), various models of the Apple II family (first introduced in 1977), the Atari 400/800 (1979) along with its follow up models the 800XL and 130XE, and the Commodore VIC-20 (1980) and the Commodore 64 (1982). The VIC was the first computer of any type to sell over one million units, and the 64 is still the highest-selling single model of personal computer ever, with over 17 million produced before production stopped in 1994 – a 12-year run with only minor changes.[28]
In Europe the situation was slightly different, as many of the British made systems like Sinclair's ZX81 and Spectrum, and later the Amstrad/Schneider CPC were generally much cheaper in Europe than US systems (such as the Atari and Apple models). The reverse was also true, as popular British systems like the Spectrum never became popular in the US. A few British Sinclair models were sold for low prices in the US by Timex Corporation, such as the Timex Sinclair 1000 and the ill-fated Timex Sinclair 2068. The result was that these British systems were much more popular in Europe than in the USA, the only notable exception being the Commodore 64 (C64), which competed favorably price-wise with the British systems, and was the most popular system in Europe as in the USA.[29][30]
Until the introduction of the IBM PC in 1981, computers such as the Apple II and TRS 80 also found considerable use in office work.[31][32]
(For a comprehensive overview of home computers, i.e. not just the most notable ones given below, see the List of home computers.)
[edit] 1970s
This section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed. (July 2008)
Three microcomputers were the prototypes for what would later become the home computer market segment; but when introduced they sold as much to hobbyists and small businesses as to the home.
* June 1977: Apple II (North America), color graphics, eight expansion slots; one of the first computers to use a typewriter-like plastic case design.
* August 1977: Tandy Radio Shack TRS-80 (N. Am.), first home computer for less than US$600, used a dedicated monitor for U.S. Federal Communications Commission (FCC) rules compliance.
* December 1977: Commodore PET (N. Am.), first all-in-one computer: keyboard/screen/tape storage.
The following computers also introduced significant advancements to the home computer segment:
* 1979: Atari 400/800 (N. Am.), first computer with custom chip set and programmable video chip and built-in audio output.
* 1979: TI-99/4, first home computer with a 16-bit processor.
[edit] 1980s
This section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed. (July 2008)
No computer has sold more units than the Commodore 64.[33]
The East German Robotron KC 85/1 was virtually not available for sale due to huge demand by industrial, educational, and military institutions.
* 1980: Commodore VIC-20 (N. Am.), under US$300; first computer of any kind to pass one million sold.
* 1980: TRS-80 Color Computer (N. Am.), Motorola 6809, optional OS-9 multi-user multi-tasking.
* June 1981: Texas Instruments TI-99/4A, based on the less successful TI-99/4, first to add sprite graphics.
* 1981: Sinclair ZX81 (Europe), £49.95 in kit form; £69.95 pre-built, released as Timex Sinclair 1000 in US in 1982.
* 1981: BBC Micro (Europe) (premier educational computer in the UK for a decade; advanced BBC BASIC with integrated 6502 machine code assembler, featured a myriad of I/O ports, ~ 1.5 million sold.
* April 1982: Sinclair ZX Spectrum (Europe), best-selling British home computer; catalysed the UK software industry, widely cloned by the Soviet Union.
* June 1982: MicroBee (Australia), initially as a kit, then as a finished unit.
* August 1982: Dragon 32(UK) became, for a short time, the best-selling home micro in the United Kingdom.
* August 1982: Commodore 64 (N. Am.), custom graphic & synthesizer chipset, best-selling computer model of all time: ~ 17 million sold.
* Jan. 1983: Apple IIe, Apple II enhanced. Reduced component count and production costs enabled high-volume production, until 1993.
* Apr. 1984: Apple IIc, Apple II compact. No expansion slots, and built-in ports for pseudo-plug and play ease of use. The Apple II most geared to home use, to complement the Apple IIe's dominant education market share.
* 1983: Acorn Electron A stripped down 'sibling' of the BBC microcomputer with limited functionality. The Electron recovered from a slow start to become one of the more popular home computers of that era in the UK.
* 1983: Coleco Adam, one of the few home computers to be sold as a complete system with storage device and printer; cousin to the ColecoVision game console; one of the first systems to be "orphaned" by its maker, a casualty of the North American video game crash of 1983.
* 1983: MSX (Japan, Korea, Arabia, Europe, N+S. Am.), a computer 'reference design' by ASCII and Microsoft, produced by several companies: ~ 5 million sold.
* 1983: VTech Laser 200, entry level computer aimed at being the cheapest on market, also sold as Salora Fellow, Texet TX8000 & Dick Smith VZ 200.
* 1984: The Apple Macintosh is introduced, providing many consumers their first look at a graphical user interface, which would eventually replace the home computer as it was known.
* 1984: Amstrad/Schneider, CPC, PCW ranges (Europe), British standard before IBM PC; German sales next to C64.
* 1985: Elektronika BK-0010, one of the first 16-bit home computers, and the only "official" home computer in USSR.
* 1985: Robotron KC 85/1 (Europe), one of the few home computers produced by the East German VEB Robotron-Meßelektronik "Otto Schön" Dresden.
* 1985: Atari ST (N. Am.), first with built-in MIDI interface; also 1MB RAM for less than US$1000; Motorola 68000 processor.
* 1985: Commodore 128 (N. Am.) Final, most advanced 8-bit Commodore, retained full C64 compatibility while adding CP/M in a complex multi-mode architecture
* July 1985: Commodore Amiga (N. Am.), custom chip set for graphics and digital audio; multitasking OS with both GUI and CLI interfaces; Motorola 68000 processor.
* 1987: Acorn Archimedes (Europe), launched with an 8 MHz 32-bit ARM 2 microprocessor, with between 512kB and 4MB of RAM, and an optional 20 or 40MB hard drive.
* 1989: SAM Coupé (Europe), based on 6 MHz Z80 microprocessor; marketed as a logical upgrade from the Sinclair ZX Spectrum.
[edit] See also
Wikimedia Commons has media related to: Home computers
* Computer magazines
* History of computing hardware (1960s-present)
* Honeywell 316 a "home computer" from 1969
* List of home computers
* List of home computers by category
* List of home computers by video hardware
* List of video game consoles
* The influence of the IBM-PC on the PC market
* Microprocessor development board and List of early microcomputers, first microprocessor based systems used by hobbyists
* Personal computer
* Pirates of Silicon Valley - docu-fiction focused on Apple and Microsoft evolution
* Triumph of the Nerds
* Video Display Controller, chips that were used to create the video graphics of many early home computers
[edit] References
From Wikipedia, the free encyclopedia
Jump to: navigation, search
This article is primarily about a certain class of Personal computers from the late 1970s to mid-1980s, see Domotics or Home servers for home computers used in home automation.
Children playing Paperboy on an Amstrad CPC 464 in the 1980s
Most home computers, such as this Tandy Color Computer 3, featured a version of the BASIC programming language. The sometimes-sprawling nature of the well-outfitted home computer system is very much in evidence.
Home computers were a class of personal computers entering the market in 1977, and becoming increasingly common during the 1980s.[1] They were marketed to consumers as affordable, accessible personal computers and more capable than video game consoles. These computers typically cost much less than business, scientific or engineering-oriented desktop personal computers of the time, and were generally less powerful in terms of memory and expandability. However, a home computer often had better graphics and sound than contemporary business personal computers. Usually they were bought for education, game play, and personal productivity use such as word processing.
Advertisements for early home computers were rife with possibilities for their use in the home, from cataloging recipes to personal finance to home automation,[2][3][4] but these were seldom realized in practice. For example, using a typical 1980s home computer as a home automation appliance would require the computer to be kept powered on at all times and dedicated to this task. Personal finance and database use required tedious data entry. If no packaged software was available for a particular application, the home computer user was required to learn computer programming; a significant time commitment many weren't willing to make. Still, for many the home computer offered the first opportunity to learn to program.[5]
Today the line between 'business' and 'home' computer market segments has blurred or vanished completely, since both categories of computers now typically use the same processor architectures, peripherals, operating systems, and applications. Often the only difference may be the sales outlet through which they are purchased. Another change from the home computer era is that the once-common endeavour of writing one's own software programs has almost vanished from home computer use.[6]
A RadioShack TRS-80 released in 1977.
The Commodore PET released in 1977. This model featured a built in Datassette drive.
Contents
[hide]
* 1 Background
* 2 Technology
* 3 Radio frequency interference
* 4 The Home Computer "Revolution"
* 5 Use today
* 6 Notable home computers
o 6.1 1970s
o 6.2 1980s
* 7 See also
* 8 References
* 9 External links
[edit] Background
Computers became affordable for the general public due to the mass production of the microprocessor. Early microcomputers had front-mounted switches and blinkenlights to control and indicate internal system status, and were often sold in kit form. These kits would contain an empty printed circuit board which the buyer would fill with the integrated circuits, other individual electronic components, wires and connectors, and then hand-solder all the connections.[7] In contrast, home computers were designed to be used by the average consumer, not necessarily an electronics hobbyist.
While two early home computers (Sinclair ZX80, and Acorn Atom) could be bought either in kit form or assembled, most home computers were only sold pre-assembled. They were enclosed in plastic or metal cases similar in appearance to typewriter or hi-fi equipment enclosures, which were more familiar and attractive to consumers and lower cost than the metal card-cage enclosures used by the Altair and similar computers. A keyboard was usually built into the same case as the motherboard. Ports for plug-in peripheral devices such as a video display, cassette tape recorders, joysticks, and (later) disk drives either were built-in or available as add-on cards. Usually the manufacturer would sell peripheral devices designed to be compatible with their computers as extra cost accessories. Often peripherals were not interchangeable between brands of home computer, or even between successive models of the same brand.
To save the cost of a dedicated monitor, the home computer often would connect either directly or through an RF modulator to the family TV set which served as both video display and sound system.[8]
Almost universally, home computers had a version of a BASIC interpreter combined with a line editor in permanent read-only memory with which one could type in BASIC programs and execute them immediately. In direct mode, the BASIC interpreter was also used as the user interface, and given tasks such as loading, saving, managing, and running files.[9] One exception was the Jupiter Ace, which had a Forth interpreter built in. A programming language was seen as a requirement for any computer of the era due to the dearth of commercially-available productivity software as well as the widely varying applications users had in mind for the new devices.
After the success of systems like the RadioShack TRS-80, the Commodore PET and the Apple II in 1977, large numbers of new machines of all types began to appear during the late 1970s and early 1980s. Some home computers sold many units over several years, such as the BBC Micro, Sinclair ZX Spectrum, Atari 800XL and Commodore 64, and attracted third-party software development. By 1982, an estimated 621,000 home computers were in use in the United States, at an average sales price of $530.[10]
Low-end home computers competed with video game consoles. The markets weren't entirely distinct, as both could be used for games. A common marketing tactic was to show a computer system and console playing games side by side, then emphasising the computer's greater ability by showing it running user-created programs, education software, word processing, spreadsheet and other applications while the game console showed a blank screen or continued playing the same repetitive game. Books were available for most models of computer with titles along the lines of "64 Amazing BASIC Games for the Commodore 64". These books would include type in program listings and sometimes an mail-in offer to obtain the programs on disk or cassette and were a popular and low-cost means of both learning to program and software distribution. Some video game consoles offered "programming packs", consisting of a version of BASIC in a ROM cartridge. For the ColecoVision console Coleco even announced an expansion module which would convert it into a full-fledged computer system. This never materialised, but a standalone computer, the Coleco Adam was eventually released.[11] During the peak years of the home computer market, scores of models were produced, usually with little or no thought given to compatibility between different manufacturers or even within product lines of one manufacturer.[12] The concept of a computer platform did not exist, except for the Japanese MSX standard.[13]
Soon after its August 1981 introduction, the IBM Personal Computer would eventually become the standard platform used in business. This was largely due to the system's open architecture, which encouraged production of third-party clones of the design. The Visicalc-running Apple II would be quickly displaced for office use,[14] but Apple Computer's 1984 release of the Apple Macintosh introduced a new model for interacting with the computer to the market, which IBM-compatible computers would eventually also adopt.[15] Throughout the 1980s, PCs spread through businesses like wildfire, leading, by the end of the decade, to sub-$1000 IBM PC XT-class white box machines, usually built in Asia and sold by US companies like PCs Limited.
The declining cost of the IBM-compatibles on the one hand, and the greatly increased graphics, sound, and storage abilities of fourth generation video game consoles such as the Sega Genesis and Super Nintendo Entertainment System on the other, combined to cause the market segment for home computers to vanish by the early 1990s in the US. In Europe, the home computer remained a distinct presence for a few years more, with the Amiga and Atari ST lines being the dominant players, but today a computer bought for home use anywhere will be very similar to those used in offices - made by the same manufacturers, with compatible peripherals, operating systems, and application software.
[edit] Technology
A Commodore 64c system, showing the basic layout of a typical home computer system of the era. Pictured are the CPU/keyboard unit, floppy disk drive, and dedicated color monitor. Many systems also had a dot matrix printer for producing paper output.
Eastern Bloc computers were often significantly different in appearance from western computers. Pictured is a KC 85/3 with its keyboard placed on top, by VEB Mikroelektronik Mühlhausen released in 1986 and based on an East German Zilog Z80 clone.
The Soviet Elektronika BK0010-01 home computer was based on the К1801ВМ1 (Soviet LSI-11-compatible CPU) and shared architectural similarities with PDP-11.
Many home computers were superficially similar. Most had a keyboard integrated into the case; sometimes a cheap-to-make membrane or chiclet keyboard in the early days, although full-travel keyboards quickly became universal due to overwhelming consumer preference. Most systems could use an RF modulator to display 20–40 column text output on a home television. Indeed, the use of a television set as a display almost defines the pre-PC home computer. Although dedicated composite or "green screen" computer displays were available for this market segment and offered sharper text display and sometimes increased graphics resolution, a monitor was often a later purchase made only after users had bought a floppy disk drive, printer, modem, and the other pieces of a full system. This "peripherals sold separately" approach is another defining characteristic of the home computer era. Many first time computer buyers brought a base C-64 system home and hooked it up to their TV only to find they needed to buy a disk drive or Datassette before they could make use of it as anything but a game machine.
In the early part of the 1980s, the dominant microprocessors used in home computers were the 8-bit MOS Technology 6502 (Apple, Commodore, Atari) and Zilog Z80 (TRS-80). A notable exception was the TI-99 series, announced in 1979 with a 16-bit TMS9900 CPU.[16]
Processor clock rates were typically 1–2 MHz for 6502 based CPU's and 2–4 MHz for Z80 based systems (yielding roughly equal performance), but this aspect was not emphasized by users or manufacturers, as the systems' limited RAM capacity, graphics abilities and storage options had more of an effect on performance than CPU speed. Clock rate was considered a technical detail of interest only to users needing accurate timing for their own programs. To economize on component cost, often the same crystal used to produce color television compatible signals was also divided down and used for the processor clock. This meant processors rarely operated at their full rated speed, and had the side-effect that European and North American versions of the same home computer operated at slightly different speeds and different video resolution due to different television standards.
Initially, many home computers used the then-ubiquitous compact audio cassettes as a storage mechanism. A rough analogy to how this worked would be to place a recorder on the phone line as a file was uploaded by modem to "save" it, and playing the recording back through the modem to "load". Most cassette implementations were notoriously slow and unreliable, but floppy disk drives as found on more costly business-oriented microcomputers were expensive and used disks eight inches wide at the beginning of the home computer era. Costs declined toward the end of the 1980s as sales of microcomputers increased and mass production of 5.25" drive mechanisms enabled economy of scale. The 5.25" floppy disk drives would remain the standard throughout the 8-bit era. Though external 3.5" drives were made available for most systems toward the latter part of the 1980s, most software sold for 8-bit home computers remained on 5.25" disks; 3.5" drives were used for data storage. Standardization of disk formats was not common; sometimes even different models from the same manufacturer used different disk formats.
Various copy protection schemes were developed for floppy disks; most were broken in short order. Many users would only tolerate copy protection for games, as wear and tear on disks was a significant issue in an entirely floppy-based system. The ability to make a "working backup" disk of vital application software was seen as important. Copy programs that advertised their ability to copy or even remove common protection schemes were a common category of utility software in this pre-DMCA era.
In contrast to modern computers, home computers most often had their operating system (OS) stored in ROM chips. This made startup times very fast - no more than a few seconds - but made OS upgrades difficult or impossible without buying a new unit. Usually only the most severe bugs were fixed by issuing new ROMs to replace the old ones at the user's cost. In another defining characteristic of the home computer, instead of a command line, the BASIC interpreter served double duty as a user interface. Coupled to a character-based screen or line editor, BASIC's file management commands could be entered in direct mode. The operating systems provided little other support to application programs, but application programs usually accessed hardware directly to perform a specific task, often switching out the ROM based OS anyway to free the address space it occupied and maximize RAM capacity. As multitasking was not common on home computers until late in the '80s, this lack of API support wasn't much of a liability.
In an enduring reflection of their early cassette-oriented nature, most home computers loaded their disk operating system (DOS) separately from the main OS. The DOS was only used to send commands to the floppy disk drive and was not loaded to perform other computing functions. One notable exception was Commodore, whose disk drives actually contained a 6502 processor and Commodore DOS in ROM. Many home computers also had a cartridge interface which accepted ROM-based software. This was occasionally used for expansion or upgrades such as fast loaders. Application software on cartridge did exist, but the vast majority of cartridges were games.[17]
From about 1985, the high end of the home computer market began to be dominated by "next generation" home computers using the 16-bit Motorola 68000 chip, which enabled the greatly increased abilities of the Amiga and Atari ST series. Graphics resolutions approximately doubled, and color palettes increased from dozens to hundreds or thousands of colors available. Stereo sound became standard for the first time. Clock rates on these systems were approximately 8 MHz with RAM capacities of 256 kB (for the base Amiga 1000 system) up to 1024 kB (1 megabyte, a milestone, first seen on the Atari 1040 ST). These systems had built-in 3.5" floppy disks from the beginning but 5.25" drives were made available to facilitate data exchange with the IBM PC compatibles. The Amiga and ST both had GUIs inspired by the Apple Macintosh, but at a list price of $2495 (over $5000 in 2007 dollars), the Macintosh itself was too expensive for most households.
[edit] Radio frequency interference
After the first wave of computers landed in American homes, the United States Federal Communications Commission (FCC) began receiving complaints of electromagnetic interference to television reception. By 1979 the FCC demanded that home computer makers submit samples for radio frequency interference testing. It was found that "first generation" home computers, which often included their own screens, emitted too much radio frequency noise for household use. Some companies appealed to the FCC to waive the requirements for home computers, while others (with compliant designs) objected to the waiver. Eventually techniques to suppress interference became standardized.[18]
[edit] The Home Computer "Revolution"
See also: Microcomputer revolution
This section is written like a personal reflection or essay and may require cleanup. Please help improve it by rewriting it in an encyclopedic style. (September 2010)
In the late 1970s and early 1980s, from about 1977 to 1983, it was widely predicted [19] that computers would soon revolutionize many aspects of home and family life as they had business practices in the previous decades.[20] Mothers would keep their recipe catalog in "kitchen computer" databases and turn to a medical database for help with child care, fathers would use the family's computer to manage family finances and track automobile maintenance. Children would use disk-based encyclopedias for school work and would be avid video gamers. Home automation would bring about the intelligent home of the '80s. Using Videotex, NAPLPS or some sort of as-yet unrealized computer technology, television would gain interactivity. The personalized newspaper was a commonly-predicted application. Morning coffee would be brewed automatically under computer control. The same computer would control the house lighting and temperature. Robots would take the garbage out, and be programmable to perform new tasks by the home computer. Electronics were expensive, so it was generally assumed that each home would have only one multitasking computer for the entire family to use in a timesharing arrangement, with interfaces to the various devices it was expected to control.
“ The single most important item in 2008 households is the computer. These electronic brains govern everything from meal preparation and waking up the household to assembling shopping lists and keeping track of the bank balance. Sensors in kitchen appliances, climatizing units, communicators, power supply and other household utilities warn the computer when the item is likely to fail. A repairman will show up even before any obvious breakdown occurs.
Computers also handle travel reservations, relay telephone messages, keep track of birthdays and anniversaries, compute taxes and even figure the monthly bills for electricity, water, telephone and other utilities. Not every family has its private computer. Many families reserve time on a city or regional computer to serve their needs. The machine tallies up its own services and submits a bill, just as it does with other utilities.[21]
”
—Mechanix Illustrated, November 1968 edition
All this was predicted to be commonplace sometime before the end of the decade, but virtually every aspect of the predicted revolution would be delayed or prove entirely impractical. The computers available to consumers of the time period just weren't powerful enough to perform any single task required to realize this vision, much less do them all simultaneously. The home computers of the early 1980s could not multitask. Even if they could, memory capacities were too small to hold entire databases or financial records, floppy disk-based storage was inadequate in both capacity and speed for multimedia work, and the graphics of the systems could only display blocky, unrealistic images and blurry, jagged text. Before long, a backlash set in—computer users were "geeks", "nerds" or worse, "hackers". The North American video game crash of 1983 soured many on home computer technology. The computers that were bought for use in the family room were either forgotten in closets or relegated to basements and children's bedrooms to be used exclusively for games and the occasional book report.
It took another 10 years for technology to mature, for the graphical user interface to make the computer approachable for non-technical users, and for the internet to provide a compelling reason for most people to want a computer in their homes. Predicted aspects of the revolution were left by the wayside or modified in the face of an emerging reality. The cost of electronics dropped precipitously and today many families have a computer for each family member, or a laptop for mom's active lifestyle, a desktop for dad with the kids sharing a computer. Encyclopedias, recipe catalogs and medical databases are kept online and accessed over the world wide web -- not stored locally on floppy disks or CD-ROM. TV has yet to gain substantial interactivity; instead, the web has evolved alongside television, but the HTPC or services like Netflix, Google TV or Apple TV along with internet video sites such as YouTube and Hulu may one day replace traditional broadcast and cable television. Our coffee may be brewed automatically every morning, but the computer is a simple one embedded in the coffee maker, not under external control. As of 2008, robots are just beginning to make an impact in the home, with Roomba and Aibo leading the charge.
This delay wasn't out of keeping with other technologies newly introduced to an unprepared public. Early motorists were widely derided with the cry of "Get a horse!"[22] until the automobile was accepted. Television languished in research labs for decades before regular public broadcasts began. In an example of changing applications for technology, before the invention of radio, the telephone was used to distribute opera and news reports, whose subscribers were denounced as "illiterate, blind, bedridden and incurably lazy people".[23] Likewise, the acceptance of computers into daily life today is a product of continuing refinement of both technology and perception.
[edit] Use today
As older computer hardware becomes obsolete (and in some cases nonfunctional), and the supply of replacement parts dwindles, it has become popular among enthusiasts[24] to emulate these machines, their environments[25] on modern hardware. One of the more well-known emulators is the Multiple Emulator Super System which can emulate most of the better known home computers. A more or less complete list of home computer emulators can be found here. Games for many 8 and 16 bit home computers are becoming available for the Wii Virtual Console.
Retrocomputing is gaining in popularity, with many enthusiasts using real Commodore 64 hardware to perform modern tasks such as surfing the web and email. The 64 has also been repackaged as the C-One and C64 Direct-to-TV, both designed by Jeri Ellsworth with modern enhancements.[26] Many enthusiasts have started to collect home computers, with older and rarer systems being much sought after. Sometimes the collections turn into a virtual museum presented on web sites.[27]
As cloud computing develops, future home computer users may opt for the all-in-one simplicity of a console, netbook, nettop or set top box over a standard PC, possibly running a "stripped down" operating system like Chrome OS. This could lead to a new era of home computers as distinct from business computers running a more traditional OS. Game consoles are starting to incorporate most of the most common uses for PCs in the home - in addition to gaming, all of the 2008 console generation feature music playing ability, and the Wii and PlayStation 3 can be used to browse the web. The Xbox 360 also features instant messaging. Through the web browser component, word processing, email and photo editing are available on these consoles using Web applications. Laptops and tablet computers such as the iPad are becoming popular for use in the home, which may redefine the term personal computer itself as a truly personal accessory, similar to a digital audio player or mobile phone and used by an individual in both work and leisure settings.
[edit] Notable home computers
The 1977 Apple II with 2 Disk II disk drives and an Apple monitor
The list below shows many of the most popular or significant home computers of the late 1970s and of the 1980s.
The most popular home computers in the USA up to 1985 were: the TRS-80 (1977), various models of the Apple II family (first introduced in 1977), the Atari 400/800 (1979) along with its follow up models the 800XL and 130XE, and the Commodore VIC-20 (1980) and the Commodore 64 (1982). The VIC was the first computer of any type to sell over one million units, and the 64 is still the highest-selling single model of personal computer ever, with over 17 million produced before production stopped in 1994 – a 12-year run with only minor changes.[28]
In Europe the situation was slightly different, as many of the British made systems like Sinclair's ZX81 and Spectrum, and later the Amstrad/Schneider CPC were generally much cheaper in Europe than US systems (such as the Atari and Apple models). The reverse was also true, as popular British systems like the Spectrum never became popular in the US. A few British Sinclair models were sold for low prices in the US by Timex Corporation, such as the Timex Sinclair 1000 and the ill-fated Timex Sinclair 2068. The result was that these British systems were much more popular in Europe than in the USA, the only notable exception being the Commodore 64 (C64), which competed favorably price-wise with the British systems, and was the most popular system in Europe as in the USA.[29][30]
Until the introduction of the IBM PC in 1981, computers such as the Apple II and TRS 80 also found considerable use in office work.[31][32]
(For a comprehensive overview of home computers, i.e. not just the most notable ones given below, see the List of home computers.)
[edit] 1970s
This section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed. (July 2008)
Three microcomputers were the prototypes for what would later become the home computer market segment; but when introduced they sold as much to hobbyists and small businesses as to the home.
* June 1977: Apple II (North America), color graphics, eight expansion slots; one of the first computers to use a typewriter-like plastic case design.
* August 1977: Tandy Radio Shack TRS-80 (N. Am.), first home computer for less than US$600, used a dedicated monitor for U.S. Federal Communications Commission (FCC) rules compliance.
* December 1977: Commodore PET (N. Am.), first all-in-one computer: keyboard/screen/tape storage.
The following computers also introduced significant advancements to the home computer segment:
* 1979: Atari 400/800 (N. Am.), first computer with custom chip set and programmable video chip and built-in audio output.
* 1979: TI-99/4, first home computer with a 16-bit processor.
[edit] 1980s
This section does not cite any references or sources.
Please help improve this article by adding citations to reliable sources. Unsourced material may be challenged and removed. (July 2008)
No computer has sold more units than the Commodore 64.[33]
The East German Robotron KC 85/1 was virtually not available for sale due to huge demand by industrial, educational, and military institutions.
* 1980: Commodore VIC-20 (N. Am.), under US$300; first computer of any kind to pass one million sold.
* 1980: TRS-80 Color Computer (N. Am.), Motorola 6809, optional OS-9 multi-user multi-tasking.
* June 1981: Texas Instruments TI-99/4A, based on the less successful TI-99/4, first to add sprite graphics.
* 1981: Sinclair ZX81 (Europe), £49.95 in kit form; £69.95 pre-built, released as Timex Sinclair 1000 in US in 1982.
* 1981: BBC Micro (Europe) (premier educational computer in the UK for a decade; advanced BBC BASIC with integrated 6502 machine code assembler, featured a myriad of I/O ports, ~ 1.5 million sold.
* April 1982: Sinclair ZX Spectrum (Europe), best-selling British home computer; catalysed the UK software industry, widely cloned by the Soviet Union.
* June 1982: MicroBee (Australia), initially as a kit, then as a finished unit.
* August 1982: Dragon 32(UK) became, for a short time, the best-selling home micro in the United Kingdom.
* August 1982: Commodore 64 (N. Am.), custom graphic & synthesizer chipset, best-selling computer model of all time: ~ 17 million sold.
* Jan. 1983: Apple IIe, Apple II enhanced. Reduced component count and production costs enabled high-volume production, until 1993.
* Apr. 1984: Apple IIc, Apple II compact. No expansion slots, and built-in ports for pseudo-plug and play ease of use. The Apple II most geared to home use, to complement the Apple IIe's dominant education market share.
* 1983: Acorn Electron A stripped down 'sibling' of the BBC microcomputer with limited functionality. The Electron recovered from a slow start to become one of the more popular home computers of that era in the UK.
* 1983: Coleco Adam, one of the few home computers to be sold as a complete system with storage device and printer; cousin to the ColecoVision game console; one of the first systems to be "orphaned" by its maker, a casualty of the North American video game crash of 1983.
* 1983: MSX (Japan, Korea, Arabia, Europe, N+S. Am.), a computer 'reference design' by ASCII and Microsoft, produced by several companies: ~ 5 million sold.
* 1983: VTech Laser 200, entry level computer aimed at being the cheapest on market, also sold as Salora Fellow, Texet TX8000 & Dick Smith VZ 200.
* 1984: The Apple Macintosh is introduced, providing many consumers their first look at a graphical user interface, which would eventually replace the home computer as it was known.
* 1984: Amstrad/Schneider, CPC, PCW ranges (Europe), British standard before IBM PC; German sales next to C64.
* 1985: Elektronika BK-0010, one of the first 16-bit home computers, and the only "official" home computer in USSR.
* 1985: Robotron KC 85/1 (Europe), one of the few home computers produced by the East German VEB Robotron-Meßelektronik "Otto Schön" Dresden.
* 1985: Atari ST (N. Am.), first with built-in MIDI interface; also 1MB RAM for less than US$1000; Motorola 68000 processor.
* 1985: Commodore 128 (N. Am.) Final, most advanced 8-bit Commodore, retained full C64 compatibility while adding CP/M in a complex multi-mode architecture
* July 1985: Commodore Amiga (N. Am.), custom chip set for graphics and digital audio; multitasking OS with both GUI and CLI interfaces; Motorola 68000 processor.
* 1987: Acorn Archimedes (Europe), launched with an 8 MHz 32-bit ARM 2 microprocessor, with between 512kB and 4MB of RAM, and an optional 20 or 40MB hard drive.
* 1989: SAM Coupé (Europe), based on 6 MHz Z80 microprocessor; marketed as a logical upgrade from the Sinclair ZX Spectrum.
[edit] See also
Wikimedia Commons has media related to: Home computers
* Computer magazines
* History of computing hardware (1960s-present)
* Honeywell 316 a "home computer" from 1969
* List of home computers
* List of home computers by category
* List of home computers by video hardware
* List of video game consoles
* The influence of the IBM-PC on the PC market
* Microprocessor development board and List of early microcomputers, first microprocessor based systems used by hobbyists
* Personal computer
* Pirates of Silicon Valley - docu-fiction focused on Apple and Microsoft evolution
* Triumph of the Nerds
* Video Display Controller, chips that were used to create the video graphics of many early home computers
[edit] References
Subscribe to:
Posts (Atom)