Biology analogy stirs flap in computer-security circles

After Dan Geer published a paper last fall comparing the pervasiveness of Microsoft software to a biologic “monoculture,” the analogy has sparked a controversy in computer-security circles. A full-fledged flap developed when Geer was fired by his employer, the security firm @stake Inc., which has had Microsoft as a major client.

Geer insists there’s been a silver lining to his dismissal. Once it got discussed on and other online forums, the debate about Microsoft’s ubiquity gained in prominence.

“No matter where I look, I seem to be stumbling over the phrase ‘monoculture’ or some analog of it,” Geer, 53, said in an interview with the Associated Press.

In biology, species with little genetic variation–or “monocultures”–are the most vulnerable to catastrophic epidemics. Species that share a single fatal flaw could be wiped out by a virus that can exploit that flaw. Genetic diversity increases the chances that at least some of the species will survive every attack.

“When in doubt, I think of, ‘how does nature work?'” said Geer, who holds a doctorate in biostatistics from Harvard University.

“Which leads you, when you think about shared risk, to think about monoculture, which leads you to think about epidemic. Because the idea of an epidemic is not radically different from what we’re talking about with the internet.”

Geer isn’t the first to argue that the logic of living viruses also applies to the computer variety, and that the dominance and tight integration of Microsoft operating systems and software makes the global computing ecosystem vulnerable to a cascading failure.

Geer’s paper did little more than make the point with particular fervor–which only intensified when Geer was fired.

“The hoopla around him losing his job gave the story some extra frisson,” said internet security expert Bruce Schneier, a co-author of Geer’s. “He got fired because @stake wanted to be nice to their masters. But it’s like the Christian Church boycotting a movie–everybody wants to see it now.”

Microsoft, which denies pressuring @stake to fire Geer, says the comparison between computers and living organisms works only so well.

“Once you start down the road with that analogy, you get stuck in it,” said Scott Charney, chief security strategist for Redmond, Wash.-based Microsoft.

Charney says monoculture theory doesn’t suggest any reasonable solutions; more use of the Linux open-source operating system, a rival to Microsoft Windows, might create a “duoculture,” but that would hardly deter sophisticated hackers.

True diversity, Charney said, would require thousands of different operating systems, which would make integrating computer systems and networks virtually impossible. Without a Microsoft monoculture, he said, most of the recent progress in information technology could not have happened.

Another difference: Computers can be unplugged from the network and rebooted; organisms cannot.

The theory also has skeptics outside of Microsoft.

Security consultant Marcus Ranum has emphasized that many network threats have little to do with the vulnerabilities of monoculture. Planting three strains of corn offers insurance against some diseases, he notes, but without a fence, deer will eat all three.

But Ranum also says the monoculture story “would barely be news” if @stake “hadn’t done a brilliant surgical marketing strike on its left foot by firing Dan.”

At an October hearing of the House Government Reform Committee’s technology subcommittee, Steven Cooper–the Homeland Security Department’s chief information officer–was questioned about the federal government’s vulnerability to monoculture.

Cooper acknowledged it was a concern and said the department would likely expand its use of Linux and Unix as a precaution.

The monoculture idea is also influencing how experts look for solutions to security problems.

Mike Reiter of Carnegie Mellon University and Stephanie Forrest, a University of New Mexico biologist who has been gleaning lessons for computer security from living organisms for years, recently received a $750,000 National Science Foundation grant to study methods to diversify software code automatically.

Daniel DuVarney and R. Sekar of the State University of New York-Stony Brook are exploring “benign mutations” that would diversify software, preserving the functional portions of code but shaking up the nonfunctional portions that are often targeted by viruses.

Geer–who continues to consult, lecture, and work with a startup these days–also believes monoculture theory points the way to possible solutions. But those solutions are dramatic, and haven’t always been followed. They would require, for example, banning from the internet computers whose software hasn’t been updated with the latest anti-virus patches.

Geer doesn’t believe breaking up Microsoft is the answer, even though his paper was published by the Computer and Communications Industry Association, which aggressively backed the antitrust case that tried to split up the company.

But Geer says the company should disentangle its tightly integrated products, such as Microsoft Word and Outlook.

Microsoft contends, as it did during its antitrust trial, that the integration of those products is the heart of what it offers consumers.

Still, Microsoft’s Charney doesn’t entirely dismiss the idea of examining computer security through a biological lens. “Although biodiversity-monoculture issues may be more complex than people have been thinking about them, it does not mean you can’t learn from [them] and draw some parallels,” he said.

Geer calls such comments proof the idea is resonating.

“You see Microsoft talking about it,” he said, “when before, they didn’t.”


Computer and Communications Industry Association

Geer’s paper



“Veterans History Project” records the stories of America’s war veterans

From the American Folklife Center and the Library of Congress comes a unique online resource designed to preserve the stories and experiences of America’s 19 million living war veterans. The “Veterans History Project,” organized by former President Bill Clinton, seeks to collect and preserve videotaped oral histories–along with documentary materials such as letters, diaries, maps, photographs, and home movies–of America’s war veterans and those who served in support of them. While visiting the project’s web site, students will be able to read actual letters written by soldiers to their loved ones during many of the nation’s most trying times. The site includes the personal accounts of soldiers and civilians from all branches of service in World Wars I and II, as well as the Korean, Vietnam, and Persian Gulf wars. To keep the project going, students, citizens, and organizations are invited to contribute using the Project Kit, which provides all of the necessary information and forms required to interview a veteran about his or her experiences for inclusion in the archive. Librarians, museum directors, school officials, and civic leaders can read about model veterans projects and learn how to start an initiative of their own.


$12.9 million in matching grants for using advanced technologies

TOP, a program of the Commerce Department’s National Telecommunications and Information Administration, is a highly competitive, merit-based matching grant program that promotes the use of advanced telecommunications and information technologies in the nonprofit and public sectors. TOP provides organizations with the opportunity to explore the possibilities that new interactive technologies offer to improve the provision of educational, health care, or public information. These projects encourage the deployment of broadband infrastructure, services, and applications throughout the nation. TOP will hold Technical Assistance Workshops for applicants in Washington, D.C., and Los Angeles in March. Check the program’s web site for more details.


Grants to help students pursue technical careers

Through Partners in Education, Symbol Technologies supports a number of educational institutions locally and nationally, but is particularly eager to assist students pursuing technical careers. Symbol prides itself upon its scientific and entrepreneurial innovations; therefore, the company is dedicated to supporting a number of initiatives that propel the continuation of research and innovation within universities and colleges, as well as other venues.


Grants for programs that emphasize math and science education

Westinghouse actively contributes to programs that benefit nonprofit organizations. Areas of emphasis include health and welfare, education, and civic and social pursuits. Within each area, Westinghouse encourages programs that help to meet the needs of populations such as the disadvantaged, the young, the elderly, minorities, and people with disabilities. In the area of education, emphasis is given to elementary, secondary, and high school educational programs that emphasize math and science, although consideration will be given to other relevant, non-fine arts programs.


Grants for education from the Ford Motor Co.

The Ford Motor Co. Fund makes awards in six categories: education, environment, public policy, health and social programs, civic affairs and community development, and arts and humanities. Across these areas, Ford Fund grants to nonprofit organizations totaled $83.8 million in 2002 and $77.4 million in 2003.


Free satellite educational programming and equipment

The DIRECTV Goes to School program offers educators a free, nonviolent educational programming package and satellite equipment to reach students through auditory, kinesthetic, and visual means. The programming package, called SCHOOL CHOICE, is available to state-accredited public and private schools serving students in grades K-12. A free DIRECTV Multi-Satellite System also will be provided, although there is a limited quantity available. Installation costs are not included.


Grants to provide advanced learning opportunities to students

The Teammates for Kids Foundation accepts proposals for grants from nonprofit organizations that specialize in working with children. Grants support the ongoing work of operating organizations that help needy children in the areas of health, education, and inner-city services. The foundation’s priorities focus on educational achievement in areas of documented weakness; advanced learning opportunities to gifted children who would otherwise lack the resources necessary to pursue dreams and talents; and exposing children to learning opportunities they would otherwise not experience because of insufficient financial resources. The foundation will accept applications twice in 2005: Feb. 1 and July 31.


$150,000 in grants for hands-on invention experiences

The Lemelson-MIT Program for Invention and Innovation will provide 15 grants of up to $10,000 each to high school InvenTeams in October 2004. Grants will be awarded to teams composed of students, teachers, and mentors from industry, formed for the purpose of inventing something useful that solves a problem the team has identified.


$4,500 in cash and grants from regional Teacher of the Year contest

Teachers’ Insurance Plan, an auto insurance program exclusively for educators, has opened the nomination process for its 2003-04 “Teacher of the Year” award in Connecticut, New York, and Pennsylvania. A winning teacher in each of those states will receive $1,000 and a $500 grant toward his or her school. Teachers, students, and parents can nominate any accredited teacher. Teachers also may nominate themselves.