Chrome improves anti-malware blocking score by 340%
But Microsoft's IE9 stymies seven times more dangerous URLs
Computerworld - Google's Chrome blocked four times more malicious sites and malware than a year ago, but Firefox 4 was much less effective at warning users of danger than Mozilla's browser last year, according to a report released Monday.
Both were thrashed by Microsoft's Internet Explorer 9 (IE9), however, which easily retained its crown, said NSS Labs in a reprise of a 2010 study of browser anti-malware technologies.
Even with Chrome's improved detection -- it blocked 13.2% of the malware links that NSS threw at it during a 14-day run ending June 10 -- IE9 beat it with a score seven-and-a-half times higher.
According to NSS' test results, IE9 displayed a warning message for 96% of the malicious URLs, with the program's Application Reputation feature stymying an additional 3.2% for a total blocking score of 99.2%. Last year, IE9 posted a 99% score.
Application Reputation, or "App Rep," uses a file's hash -- which identifies the file contents -- and its digital certificate to determine whether it's a known application with an established reputation. For instance, "firefox.exe" would be labeled a legitimate download with a known history and reputation. If App Rep's algorithm ranks the file as unknown -- perhaps because the hash value hasn't been seen before -- IE9 throws up a warning when users try to run or save the file.
App Rep is a part of the overall SmartScreen technology included with IE9, the browser that runs only on Windows 7 and Vista.
NSS did not retest IE8, the newest Microsoft browser that works with Windows XP, still the most widely used edition of the operating system. Last year when it put IE8 through the paces, the 2009 browser blocked 90% of the sites that tried to download attack code.
Hackers spread "social-engineered malware" -- NSS Labs' term -- by enticing users to visit malicious sites that then dupe them into downloading attack code. Such downloads often pose as an update to popular software, an innocuous video codec or a seemingly-useful antivirus program.
The tests did not include sites that attack browsers without any user interaction through drive-by attacks that exploit vulnerabilities in Windows or its applications.
Rick Moy, president of NSS Labs, said that Microsoft's SmartScreen technology remains the browser anti-malware technology to beat, pointing out that it easily trumped Google's rival Safe Browsing API, which is used by Chrome, Firefox and Apple's Safari.
Google maintains a blacklist of suspected or known malicious sites, then serves that list via the Safe Browsing API to its own and other browsers.
The troika that uses the API fared poorly in NSS' tests.
Chrome was the best of the three, blocking 13.2%, up 10.2 percentage points from last year, a 340% improvement. Firefox 4, however, displayed a warning on only 7.6% of the URLs, a drop of 11.4 points from Firefox 3.6. (NSS Labs ran its tests before Mozilla shipped Firefox 5.)
Browser wars
- Mozilla to Firefox: 'Browser, heal thyself'
- Best case, Mozilla's Firefox for Windows 8 will ship in October
- Microsoft's browser auto-update pays off as IE10 share doubles
- Sued Opera designer fingers Mozilla's 'Search Tabs' as root of $3.4M claim
- Update: Opera slaps former designer with $3.4M lawsuit for spilling secrets
- As browsing goes mobile, Apple wins, Mozilla loses
- Mozilla pulls tracking trigger for Firefox 22, ignores ad industry attacks
- Mozilla refines Firefox's private browsing, patches 13 browser bugs
- Mobile's browser usage share jumps 26% in three months
- Mozilla again rejects porting Firefox to iOS
- 12 iPhones Apps That Will Make You a Networking Star
- 10 Careers Robots Are Taking From You
- Big Data Gold Isn't Always Where You Would Expect It
- 6 Tips to Build Your Social Media Strategy
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Streamlining Information Workflows In order to streamline your workflows effectively, you will need to properly align your file transfer solution with your business requirements.
- Securing Internet File Transfers This solution brief describes the four essential elements of secure Internet transfers.
- Live Webcast
Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider - Storage Validation at Go Daddy: Best Practices from the World's #1 Web Hosting Provider
- Live Webcast
MFT and FileXpress - An Overview - Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity.
- Live Webcast
Bridging HTTP and FTP with FileXpress Internet Server - What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- Bridging HTTP and FTP with FileXpress Internet Server What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Security White Papers | Webcasts
