[ news_security_news ] Microsoft's BrowserShield Shows Promise
Doug Caverly Staff Writer
2006-09-05
Insider Reports RSS Feed
Microsoft wants to "save people," and a research project called BrowserShield is designed to do just that. Helen Wang and John Dunagan are in charge of the project, which offers "vulnerability-driven filtering of network data."
"We basically intercept the Web page, inject our logic and transform the page that is eventually rendered on the browser," Wang explained to eWEEK's Ryan Naraine. "We're inserting our layer of code at run-time to make the Web page safe for the end user."
"This can provide another layer of security, even on unpatched browsers," she continued. "If a patch isn't available, a BrowserShield-enabled tool bar can be used to clean pages hosting malicious content."
Naraine commented on the product's possible impact. "If the prototype is eventually folded into a Microsoft product," he wrote, "it could also protect against drive-by attacks that target flaws in IE, which is used by approximately 90 percent of Web surfers worldwide."
Indeed, "the research group tested BrowserShield against eight IE patches released in 2005 and found that BrowserShield - when used in tandem with standard anti-virus and HTTP filtering - would have provided the same protection as the software patches in every case."
Naraine also noted that BrowserShield is only "one of many security-related projects coming out of Microsoft Research. The research unit's Cyber-security and Systems Management group has found success with a project called Strider HoneyMonkey that trawls the Internet looking for Web sites hosting malicious code."
"Microsoft Research," he continued, "also has worked on a tool called Strider URL Tracer that looks for large-scale typo squatters; Strider GhostBuster, a rootkit scanner that looks for stealthy forms of malware; Strider Search Defender, a project that pinpoints search engine spammers; and Strider Gatekeeper, a spyware management utility."
Tag: BrowserShield
Add to Del.icio.us | Digg | Yahoo! My Web | Furl
Get all the updates in RSS:
About the Author:
Doug is a staff writer for SecurityProNews, InternetFinancialNews, SearchNewz, and WebProNews.
More news_security_news Articles
Insider Reports RSS Feed
|
|