Microsoft Research Builds 'BrowserShield' - Techist - Tech Forum

Go Back   Techist - Tech Forum > Computer Software > Microsoft Windows and Software
Click Here to Login
Closed Thread
Thread Tools Display Modes
Old 09-11-2006, 06:52 AM   #1 (permalink)
Newb Techie
Join Date: Sep 2006
Posts: 6
Default Microsoft Research Builds 'BrowserShield'

Microsoft researchers are experimenting with an automatic code zapper for the company's Internet Explorer Web browser.

Researchers at the Redmond, Wash., company have completed work on a prototype framework called BrowserShield that promises to allow IE to intercept and remove, on the fly, malicious code hidden on Web pages, instead showing users safe equivalents of those pages.

The BrowserShield project—the brainchild of Helen Wang, a project leader in Microsoft Research's Systems & Networking Research Group, and an outgrowth of the company's Shield initiative to block network worms—could one day even become Microsoft's answer to zero-day browser exploits such as the WMF (Windows Metafile) attack that spread like wildfire in December 2005.

BrowserShield, is a tool for deleting embedded scripts before a Web page is displayed on a browser, can inspect and clean both static and dynamic content. Dynamic content has become a popular vector for Web-borne malware attacks of late, security experts have said.

The framework could work particularly well, as it could provide a safety net, protecting many Web surfers from themselves.

Malicious hackers typically embed scripts on Web sites and then use social engineering techniques to trick unsuspecting visitors into downloading Trojans, bots, spyware programs and other harmful forms of malware.

If the prototype is eventually folded into a Microsoft product, it could also protect against drive-by attacks that target flaws in IE, which is used by approximately 90 percent of Web surfers worldwide.

The research group tested BrowserShield against eight IE patches released in 2005 and found that BrowserShield—when used in tandem with standard anti-virus and HTTP filtering—would have provided the same protection as the software patches in every case, Wang wrote in a research paper.

Thus, the Microsoft researchers believe the shield might even serve as an alternative to or at least an intermediary for software patches before they are made available.

BrowserShield's design—it's a so-called framework rather than an application feature—could also potentially allow it to be deployed outside of browsers, at the enterprise firewall-level or in servers, Wang said.

It could also include additional features. Wang said the research team built its prototype to support add-ons for securing AJAX (Asynchronous JavaScript and XML) applications and to block things such as phishing attempts.

BrowserShield is one of many security-related projects coming out of Microsoft Research.

The research unit's Cyber-security and Systems Management group has found success with a project called Strider HoneyMonkey that trawls the Internet looking for Web sites hosting malicious code.

Microsoft Research also has worked on a tool called Strider URL Tracer that looks for large-scale typo squatters; Strider GhostBuster, a rootkit scanner that looks for stealthy forms of malware; Strider Search Defender, a project that pinpoints search engine spammers; and Strider Gatekeeper, a spyware management utility.

Visit me @
meriyaslounge is offline  
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off

Copyright 2002- Social Knowledge, LLC All Rights Reserved.

All times are GMT -5. The time now is 11:48 AM.

Powered by vBulletin® Version 3.8.8 Beta 1
Copyright ©2000 - 2018, vBulletin Solutions, Inc.