This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies.  > Find out more here

 

All the latest UK technology news, reviews and analysis

Microsoft's Rozzle bolsters drive-by malware defences

by Gareth Morgan

22 May 2012

View Comments

  • Tweet this
Concept image representing virus malware

Microsoft researchers have shown off a new anti-malware tool which could be used to defeat so-called drive-by attacks, where users' computers are infected without them actively installing rogue software.

Drive-by attacks typically rely on vulnerabilities in JavaScript but are near-impossible for traditional static and runtime anti-malware tools to detect, according to the researchers.

These JavaScript attacks typically target specific browsers running certain plugins. Unless the malware detects that specific set up, the trap will not be sprung, which makes it hard to detect.

But Benjamin Livshits and Benjamin Zorn of Microsoft Research, along with Clemens Kolbitsch from the Technical University of Vienna have devised a virtual machine tool, known as Rozzle [PDF], which dramatically improves detection of the JavaScript threats.

Rozzle is a JavaScript virtual machine that can simultaneously mimic different set-ups by presenting the malware with multiple execution paths, increasing the likelihood that it can be detected. In effect, it provides a tool to decloak this hidden JavaScript malware.

Rozzle was put head-to-head against a traditional runtime malware detector on more than 65,000 samples of JavaScript malware. The traditional anti-malware tool detected just 2.5 per cent, while Rozzle achieved a 17.5 per cent detection rate.

While that's far from perfect, it does validate the approach, according to the researchers.

“The goal of our work is to increase the effectiveness of dynamic crawler searching for malware so as to imitate multiple browser and environment configurations,” they wrote in their research paper.

They also showed that Rozzle was three times as effective as traditional tools for uncovering malicious URLs.

Earlier this year, security firm FireEye warned that malware writers were increasingly turning to JavaScript vulnerabilities to breach enterprise defences because it was nearly impossible for firms to lock down the volume of devices running JavaScript.

Rozzle is being presented at the IEEE Symposium on Security and Privacy in San Francisco today.

Do you agree

blog comments powered by Disqus

Poll

Business security poll

How concerned are you by the rising tide of cyber threats?

17%

55%

10%

9%

9%

Popular Threads

Powered by Disqus
BlackBerry Q5

BlackBerry Q5 video demo

BlackBerry's latest smartphone is a mid-tier handset that will cost less than the Q10 and Z10

Updating your subscription status Loading

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

newsletter sign-up button

mcafee

7 requirements for hybrid web delivery

It's no longer one or other with web security; you can now have a virtualisation and SaaS hybrid model

navisite

BYOD: the implications for the IT team

BYOD is important for employee satisfaction, but poses challenges in terms of security, productivity loss and costs

PHP Developer - £30,000 - £35,000

PHP Developer £30,000 - £35,000 We are looking for...

Senior Project Manager - must speak fluent German

Massive is looking for a diligent, motivated, fluent...

Corporate Treasurer - Banking - London

Corporate Treasurer - Banking London - £70k-£120k...

Product Manager – Insurance (Telematics)

Product Manager – Insurance (Telematics) £40k-£50k...

To send to more than one email address, simply separate each address with a comma.