Security researcher slams Microsoft over IE9 malware blocking stats
'Where's the beef?' asks Sophos researcher
Computerworld - Microsoft's claims that Internet Explorer 9 (IE9) blocks attacks just don't add up, a security researcher charged Friday.
"They're presenting only half of the equation," said Chet Wisniewski, a security researcher at U.K.-based vendor Sophos. "They put lots of numbers to make it seem all 'sciencey,' but they raise more questions than they answer. So really, where's the beef?"
Wisniewski was reacting to a Tuesday blog post by Jeb Haber, the program manager lead for Microsoft's SmartScreen technology. In this post, Haber cited a wide range of statistics to show that IE9, which includes a new feature dubbed SmartScreen Application Reputation, blocked a significant number of attempted malicious downloads from reaching PCs running Vista or Windows 7.
Among Haber's key points: Microsoft's data showed that one in every 14 downloads by Windows users is malicious, and thus blocked by IE9.
Microsoft also argued that IE9's Application Reputation, or "App Rep," stymied socially engineered attacks, the kind that rely on duping users into downloading and installing a dangerous file containing code that compromises a computer and infects it with malware.
"Microsoft is comparing apples to ... nothing," Wisniewski said in a Friday interview. Because IE9's unable to block exploits of such software as Adobe Reader and Flash, Apple's iTunes or Oracle's Java, Microsoft's data doesn't show the real picture.
"Where are the numbers of exploits?" Wisniewski asked, referring to the attacks, often conducted not through downloads but by drive-by hacks leveraging vulnerabilities in Microsoft's own software or popular third-party programs.
The result is a partial picture, one that Microsoft presented as a public relations move, Wisniewski said.
"They're not comparing their numbers with actual exploits, so I feel like they're lying to me," he said. "No way do I ever get near a factual argument."
Wisniewski also pointed out flaws in IE9's download blocking, using Microsoft's own statistics to back up his case.
Haber said that 90% of all downloads do not trigger a warning by IE9, but of the 1-in-10 downloads that do display an alert, the "false positive" rate -- meaning that the warning was incorrectly flagging a legitimate file -- was between 30% and 75%.
"If that's true, will you continue to pay attention to the warning when it really matters?" Wisniewski asked. "People may get sick of it, just like they did with [User Account Control] warning in Vista."
IE9's App Rep uses a file's hash -- which identifies the file contents -- and its digital certificate to determine whether it's a known application with an established reputation. If the App Rep algorithm ranks the file as unknown -- perhaps because the hash value hasn't been seen before -- IE9 throws up a warning when users try to run or save the file.
- 15 Non-Certified IT Skills Growing in Demand
- How 19 Tech Titans Target Healthcare
- Twitter Suffering From Growing Pains (and Facebook Comparisons)
- Agile Comes to Data Integration
- Slideshow: 7 security mistakes people make with their mobile device
- iOS vs. Android: Which is more secure?
- 11 sure signs you've been hacked
- The 12 PCI DSS 3.0 requirements addressed by Peer 1 Hosting This handy quick reference outlines the 12 PCI DSS 3.0 requirements, who needs to be compliant and how Alert Logic solutions address the...
- Defense Throughout the Vulnerability Life Cycle This whitepaper provides insight into how to leverage threat and log management technologies to protect your IT assets throughout their vulnerability life cycle.
- Mobile Policy Checklist Here's what to consider when putting together a mobile policy designed to support a highly productive workforce.
- Securing BYOD Mobile computing is becoming so ubiquitous that people no longer bat an eye seeing someone working two devices simultaneously. Individuals and organizations are...
- Live Webcast On-demand webinar: "Mobility Mayhem: Balancing BYOD with Enterprise Security" Check out this on-demand webinar to hear Sophos senior security expert John Shier deep dive into how BYOD impacts your enterprise security strategy...
- Live Webcast Endpoint Backup & Restore: Protect Everyone, Everywhere Arek Sokol from the bleeding-edge IT team at Genentech/Roche explains how he leverages cross-platform enterprise endpoint backup in the public cloud as part...
- Streamline Software Asset Management, Compose a software Management Symphony Keeping track of your organization's software is easy with effective software management solutions from CDW. View the videos in our software solutions channel
- Druva inSync: Endpoint Data Protection & Governance CLICK HERE to watch this video about protecting corporate data on laptops and mobile devices, sponsored by Druva. All Security White Papers | Webcasts