Microsoft Research creates a JavaScript malware scanner
Friday, 03 December 2010

Keeping JavaScript based malware at bay might just be a job for an AI-trained tool called Zozzle.

 

Banner

JavaScript is useful but the need to guard against malware hiding in deeply obsfucated code is a growing problem. Microsoft Research has invented a scanner that can detect malware using mostly static analysis - and has called it Zozzle.

Zozzle is a product of AI techniques. The researchers used a statistical classifier to scan millions of web pages for malware. The JavaScript has to be de-obfuscated first and then analysed for features that are characteristic of malware. The features are created using an abstract syntax tree. Zozzle hooks into the JavaScript engine to get the final expanded version of the JavaScript code the page contains.

MSR

At the moment the tool is in the research phase and there is no date set for release into the wild. Current performance is claimed as less than 1% false positive with a typical 2-5 millisecond processing time per Kbyte of code.

The researchers say that they can envisage it being used both within a browser context to protect against malware on the fly or in an offline context to classify and blacklist infected sites.

More information

http://research.microsoft.com/pubs/141930/tr.pdf

 

Banner


The Raspberry Pi Gets A HAT
23/08/2014

The latest version of the Raspberry Pi single board computer has a new feature that allows it to use expansion cards more intelligently. The new boards are called HATs, Hardware Attached on Top, and t [ ... ]



Goodbye Google Maps API for Flash
14/08/2014

The, already deprecated, Google Maps API for Flash will be finally switched off on September 2nd. So if you haven't already migrated to the JavaScript version you need to do so pdq (pretty darn quick) [ ... ]


More News

Last Updated ( Friday, 03 December 2010 )
 
 

   
RSS feed of news items only
I Programmer News
Copyright © 2014 i-programmer.info. All Rights Reserved.
Joomla! is Free Software released under the GNU/GPL License.