LAS VEGAS: With the first year of its Blue Hat security campaign nearing an end, Microsoft is touting the security benefits of the research effort, which will see it hand out $250,000 prize money to its partners later this week.
Introduced last year at the Black Hat conference in Las Vegas, Blue Hat challenged security researchers to work with Microsoft on developing new methods for spotting and removing malware and system attacks.
Mike Reavey, senior director for Microsoft's Security Response Centre, told V3 that when the company awards the $250,000 cash and software prizes to three developers at the conference later this week, it will mark the close of a successful debut for the campaign.
"We said, instead of focusing on ways to attack products, can you focus on ways to defend them?" Reavey explained.
"We are happy with what we have seen, and we are taking ideas on the floor at Black Hat."
Microsoft has already included one of the projects proposed by an entrant - a return-oriented programming (ROP) defence system - into its Enhanced Mitigation Experience Toolkit (EMET) 3.5 Technology Preview.
ROPGuard was developed by Croatian programmer Ivan Fratric as a way to negate attacks that use ROP - a technique used by attackers to combine short pieces of code already present in a system, for malicious purposes.
"Developing a prototype is one thing, but having it integrated with an actual product is something else," said Fratric.
"One of the questions that we had was if we got a bunch of great ides, will we get ideas that we can actually implement?" Reavey said.
"In any industry it is challenging to take those ideas and make them practical."
Fratric will find out on Thursday, along with the two other finalist, who will win the $200,000 first prize.
The best Black Friday tech bargains out there
Russell Group slammed for misusing student data in donation campaigns
Linus Torvalds is unhappy with current approaches to Linux security
Bug prevents ASLR from randomising location of important data