'Reputation' weapons help spurn Web 2.0 malware

The browser has become the new battleground

Reputation-measurement is one of the newer ways of blocking malware in a world where threats have grown more elaborate and cunning, and Web 2.0 has grown the audience for rich media.

While the continuing usefulness of traditional virus-signature identification should not be underrated, at least two techniques are now in common use whose specific aim to evade it, according to Scott Montgomery, vice-president of global technical strategy at Californian-based Secure Computing.

The first technique is polymorphism, which involves producing a piece of malware in a number of variants with similar payload and mode of attack but written so as to offer a slightly different signature to filters.

A more widespread problem, however, is packer malware. This involves compressing, and sometimes even encrypting, agents before sending them, so as to evade filters tuned to particular signatures. The key to unscramble the infective agent and make it operational is then sent in a separate transmission.

Measures of malicious traffic by German malware analyst AVtest.org show no less than 48 per cent of recent malware came in packed and/or encrypted form, says Montgomery. Signature-based detectors are of little use against this type of malware. The best hope of detecting its presence is by its behavior.

"If it tries to change permissions on files, change registry entries or start up a shell, then it's probably up to no good."

The new weapon against malware -- and one that is quite potent -- involves rating sources of traffic by reputation, says Montgomery. The domains of people and companies you know and trust, or who have a good commercial reputation, are given a high "reputation" score; while domains that send out a lot of traffic but have little or no in-coming traffic fall under suspicion of being potential spam sources.

Some reputation-scoring can be done by the receiving individual or organization, but companies like Secure Computing maintain a large population of sensors and build reputation scores internationally, by means of continuous monitoring.

Adding the two together helps build up a picture of who can be trusted. "But it's a question of risk analysis," Montgomery says. Reputation analysis can only give a score; it's up to the receiver to decide where to draw the line between probably okay and probably not okay.

The set of developments known collectively as Web 2.0 involve richer media and a growing amount of dynamic content that works interactively within the browser, rather than at the server level.

"The browser has become the new battleground," says Montgomery.

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Stephen Bell

Computerworld
Show Comments

Father’s Day Gift Guide

Brand Post

Bitdefender 2019

Bitdefender solutions stop attacks before they even begin! Get cybersecurity that 500 MILLION users already have and trust.

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Luke Hill

MSI GT75 TITAN

I need power and lots of it. As a Front End Web developer anything less just won’t cut it which is why the MSI GT75 is an outstanding laptop for me. It’s a sleek and futuristic looking, high quality, beast that has a touch of sci-fi flare about it.

Emily Tyson

MSI GE63 Raider

If you’re looking to invest in your next work horse laptop for work or home use, you can’t go wrong with the MSI GE63.

Laura Johnston

MSI GS65 Stealth Thin

If you can afford the price tag, it is well worth the money. It out performs any other laptop I have tried for gaming, and the transportable design and incredible display also make it ideal for work.

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Featured Content

Product Launch Showcase

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?