Reviews - Channel Insider
Empowering the next generation Channel
 
Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™
  • HP PartnerONE | SolutionsINFINITE Visit us at hp.com/partners/us/go/4



  •  

    Microsoft Research Builds 'BrowserShield'

    in Reviews


    Article Rating:starstarstarstarstar / 0
    Article Views: 1371

    Rate This Article:
    Add This Article To:
    Microsoft's Internet Explorer browser could soon start automatically rewriting and redisplaying content from Web sites rigged with malicious attack code.

    Microsoft researchers are experimenting with an automatic code zapper for the company's Internet Explorer Web browser.

    Researchers at the Redmond, Wash., company have completed work on a prototype framework called BrowserShield that promises to allow IE to intercept and remove, on the fly, malicious code hidden on Web pages, instead showing users safe equivalents of those pages.

    The BrowserShield project—the brainchild of Helen Wang, a project leader in Microsoft Research's Systems & Networking Research Group, and an outgrowth of the company's Shield initiative to block network worms—could one day even become Microsoft's answer to zero-day browser exploits such as the WMF (Windows Metafile) attack that spread like wildfire in December 2005.

    "This can provide another layer of security, even on unpatched browsers," Wang said in an interview with eWEEK. "If a patch isn't available, a BrowserShield-enabled tool bar can be used to clean pages hosting malicious content."

    Click here to view a slide show on the new security features of Internet Explorer 7 RC1.

    BrowserShield, described by Wang as a tool for deleting embedded scripts before a Web page is displayed on a browser, can inspect and clean both static and dynamic content. Dynamic content has become a popular vector for Web-borne malware attacks of late, security experts have said.

    Resource Library:

    The framework could work particularly well, as it could provide a safety net, protecting many Web surfers from themselves.

    Malicious hackers typically embed scripts on Web sites and then use social engineering techniques to trick unsuspecting visitors into downloading Trojans, bots, spyware programs and other harmful forms of malware.

    With BrowserShield, Wang argues, many such attacks could be blocked. BrowserShield can be used as a framework that rewrites HTML pages to deny any attempt at executing harmful code on browsers.

    "We basically intercept the Web page, inject our logic and transform the page that is eventually rendered on the browser," Wang said. "We're inserting our layer of code at run-time to make the Web page safe for the end user."

    If the prototype is eventually folded into a Microsoft product, it could also protect against drive-by attacks that target flaws in IE, which is used by approximately 90 percent of Web surfers worldwide.

    Indeed, during testing, Wang's team was able to inject HTML-rewriting logic into Web pages at an enterprise firewall. BrowserShield transparently rewrote and rendered many familiar Web sites that use JavaScript, a scripting language that can be used to run arbitrary server-provided code on a client computer.

    "The framework could react in many ways to detect exploits," Wang wrote in a paper detailing the prototype tests. "Vulnerability-driven filtering should prevent all exploits (of a flaw) and should not disrupt any exploit free pages."

    The research group tested BrowserShield against eight IE patches released in 2005 and found that BrowserShield—when used in tandem with standard anti-virus and HTTP filtering—would have provided the same protection as the software patches in every case, Wang wrote in a research paper.

    Without BrowserShield, anti-virus software would have provided patch-equivalent protection for only one of the eight browser patches, according to Wang.

    Thus, the Microsoft researchers believe the shield might even serve as an alternative to or at least an intermediary for software patches before they are made available.

    Microsoft's security guru goes to Amazon.com. Click here to read more.

    BrowserShield's design—it's a so-called framework rather than an application feature—could also potentially allow it to be deployed outside of browsers, at the enterprise firewall-level or in servers, Wang said.

    It could also include additional features. Wang said the research team built its prototype to support add-ons for securing AJAX (Asynchronous JavaScript and XML) applications and to block things such as phishing attempts.

    BrowserShield is one of many security-related projects coming out of Microsoft Research.

    The research unit's Cyber-security and Systems Management group has found success with a project called Strider HoneyMonkey that trawls the Internet looking for Web sites hosting malicious code.

    Microsoft Research also has worked on a tool called Strider URL Tracer that looks for large-scale typo squatters; Strider GhostBuster, a rootkit scanner that looks for stealthy forms of malware; Strider Search Defender, a project that pinpoints search engine spammers; and Strider Gatekeeper, a spyware management utility.

    Check out eWEEK.com's for the latest security news, reviews and analysis. And for insights on security coverage around the Web, take a look at eWEEK.com Security Center Editor Larry Seltzer's Weblog.



    Discuss Microsoft Research Builds 'BrowserShield'
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Reviews Articles          >>> More By Ryan Naraine
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    How to Unleash Application Performance with Solid-State Drives and Sun Servers
    Unleash the Beast! Learn from Sun and Intel experts how Sun servers equipped with Flash-enabled solid-state drives offer dramatic improvements to HPC, Web 2.0, and data center application performance Watch this video to learn more
    Watch Video
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Easily Monitor Virtual, Physical, and Cloud based assets, applications and services from a unified Dashboard with up.time. Deep Monitoring across platforms and best-of-breed reporting. Over 700 enterprise customers in 32 countries.
    Read Article