Upcoming program will slow the spread of network pests, the computer maker promises.
SAN FRANCISCO--Hewlett-Packard plans to give customers a new weapon against viruses: software that crimps their spread.
Early next year, the computer maker will begin selling software designed to slow the spread of viruses from its ProLiant servers and ProCurve networking equipment, an HP executive said on Tuesday. A version for HP's personal computers is planned for later release.
The software will give administrators time to respond to an attack, Tony Redmond, chief technology officer of HP Services, said at an HP security event here. The time lag between a vulnerability in software being discovered and a virus being written is getting ever shorter, and viruses are spreading at a breakneck rate, he said.
"Ten years ago, all we worried about were floppy disk attacks. People would walk from PC to PC with an infected floppy. Five years ago, with "I Love You" and "Melissa" (viruses), we had a sudden acceleration of the threat," Redmond said. "Today, the type of viruses and worms we see are spreading at computational speed--a speed that a human can't deal with."
HP, based in Palo Alto, Calif., touted the software at a media event designed to spotlight the company's security efforts. Security is an active research area at HP Labs, and the company has 16 patents relating to the virus-throttling technology.
The program can distinguish between regular server process behavior and viruses to detect an attack. "A rogue process such as a worm or virus tends to be making the same type of connection at a much more frequent pace," Redmond said. "If a process probes a particular socket on 1,000 systems a minute, what can you conclude? It's probably not a user or (a legitimate) server process."
The faster a virus is set to propagate, the easier it is to distinguish it from conventional computer tasks, Redmond said. Speedy propagation is a serious danger to networks and servers; the SQL Slammer attack hit 79,000 systems within 31 minutes, he said.
Once the software detects a process with viruslike characteristics, it slows that procedure down, without affecting regular processes. "Eventually it chokes it off," Redmond said.
HP will release virus-throttling support--likely as part of an add-on pack--for ProLiant servers running Windows 2000 and 2003 in early 2005. At the same time, it will release a version for its ProCurve network switching equipment. The software is undergoing Windows compatibility testing now, Redmond said.
Redmond declined to say when a PC version of the software might be released. It's in testing at HP Labs but, unlike the server version, is not in use as part of HP computing operations. He also declined to say whether a Linux version of the software would be coming, but said he hoped one would be released. Nothing technological stands in the way of a Linux version; indeed, prototypes were first shown on Linux.
At the security event, HP announced several other products, services and partnerships that could help turn fears of network-based computer attacks into new revenue.
The company unveiled its PC Security Center, where consumers can sign up for free over-the-phone security training classes when new viruses break out. The company also offers free e-mail and instant-message support for security issues and telephone support that costs $40 per call.
In addition, a partnership with Symantec will be expanded in coming months, said Anson Lee, a senior product manager at the security software maker. Currently, HP loads Symantec's antivirus software and a 60-day subscription for updates to the program in its PCs. It also provides Symantec's firewall software, which blocks unauthorized network communications.
In the spring of 2005, HP will deliver Norton Internet Security, which includes not just the antivirus and firewall software but also features for blocking spam, providing parental controls over Internet use, and preventing the transmission of private information.