Security researcher slams Microsoft over IE9 malware blocking stats

'Where's the beef?' asks Sophos researcher

By , Computerworld |  Security, ie9, web browsers

Haber said that 90% of all downloads do not trigger a warning by IE9, but of the 1-in-10 downloads that do display an alert, the "false positive" rate -- meaning that the warning was incorrectly flagging a legitimate file -- was between 30% and 75%.

"If that's true, will you continue to pay attention to the warning when it really matters?" Wisniewski asked. "People may get sick of it, just like they did with [User Account Control] warning in Vista."

IE9's App Rep uses a file's hash -- which identifies the file contents -- and its digital certificate to determine whether it's a known application with an established reputation. If the App Rep algorithm ranks the file as unknown -- perhaps because the hash value hasn't been seen before -- IE9 throws up a warning when users try to run or save the file.

Wisniewski noted problems with that approach.

"The problem with code signing is that we regularly see it abused," Wisniewski said, using the Stuxnet worm as an example. One variant of Stuxnet, the worm that experts have concluded was created to wreak havoc on Iran's nuclear program, used a pair of stolen certificates to masquerade as legitimate software.

"One of the things that Zeus does is grab all the digital signatures on a [compromised] computer," Wisniewski added, talking about the pervasive crimeware kit responsible for a large percentage of financially-motivated hacks.

Legitimate software that hasn't yet been "approved" by Microsoft could also confuse users into either rejecting the download -- bad for that product's developer -- or worse, "teach" IE9 users to ignore the warnings altogether.

"I love the idea of reputation-based blocking moving forward," acknowledged Wisniewski, who tipped his hat to Microsoft and IE9 for "trying to get ahead of the curve" with App Rep. "We're doing about all we can do in the reaction side.

But in his eyes, Microsoft's missed an opportunity by touting numbers that told only half the story.

"They made this PR move, showing us half the picture," he said. "They missed the mark."

Gregg Keizer covers Microsoft, security issues, Apple, Web browsers and general technology breaking news for Computerworld. Follow Gregg on Twitter at @gkeizer or subscribe to Gregg's RSS feed . His e-mail address is gkeizer@computerworld.com .

Read more about security in Computerworld's Security Topic Center.


Originally published on Computerworld |  Click here to read the original story.
Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Answers - Powered by ITworld

Join us:
Facebook

Twitter

Pinterest

Tumblr

LinkedIn

Google+

Ask a Question
randomness