SmartScreen Application Reputation in IE9

Status
Not open for further replies.

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
[......]
IE9 adds another layer of defense against socially engineered attacks that now looks at the application being downloaded.
This new layer of protection is called SmartScreen Application Reputation. When it comes to program downloads, other browsers today either warn on every file or don’t warn at all. Neither of these approaches helps the user make a better decision. Application Reputation also addresses a limitation present in all block-based approaches that happens at the beginning of new attacks, before a Web site or program has been identified as malicious.

Using reputation helps protect users from newly released malware programs - pretending to be legitimate software programs - that are not yet detected by existing defense mechanisms. Reputation also enables IE9 to remove unnecessary warnings for downloads with an established positive reputation. Both publishers and individual applications build reputation. For example, a digitally signed application from a well-known publisher that has been widely downloaded has a better reputation than an unsigned application that has not yet been downloaded widely and has just been posted on a newly created Web site.

20110517-SmartScreenHighLevelVisio.png


Read more
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Thanks for this. I thought they added something new when it flagged SumatraPDF as suspicious (or not commonly downloaded). VirtualBox was also at one point flagged.

I wish SmartScreen to be system-wide on Windows 8, instead of limited to IE9.
 

Jack

Administrator
Thread author
Verified
Staff Member
Well-known
Jan 24, 2011
9,378
Trend Micro Joins Sophos in Criticizing Microsoft SmartScreen Stats

Trend Micro researchers are backing up anti- from Sophos in claiming that Microsoft's recently published SmartScreen numbers are of little relevance and might actually lead to a false sense of security.

Starting with Internet Explorer 9 Microsoft has added an application reputation component to the browser's already existent SmartScreen filter.

The SmartScreen technology was originally introduced in Internet Explorer 7 as a malicious URL blocking feature and, according to the browser vendor, it has blocked 160 million phishing pages and 1.5 billion malware distribution sites so far.

Microsoft claims that IE's new app reputation filter kicks in immediately when a new attack is launched, unlike traditional antivirus signatures that start appearing after the eleventh hour.

The company says that SmartScreen warnings only appear for one in ten downloads and that one in fourteen downloaded files ultimately confirmed as malware.

Chester Wisniewski, a senior security advisor at Sophos, expressed several concerns about the numbers released by Microsoft to outline the success of IE9's app reputation feature.

As the security expert points out, there's a big problem with these statistics. They lack comparison with other, more prevalent, web infection vectors like drive-by downloads.

Drive-by download attacks occur when websites exploit vulnerabilities in plug-ins like Java, Flash or Adobe Reader to install malware on computers. In these cases, the browser has no control over the downloads.

"While we cannot comment on the exact methodology used in Microsoft’s own tests, we have to agree with Sophos’ questioning of the rather surprising results Microsoft published," said Martin Roesler, director for threat research at Trend Micro.

Read more

exposure_score_fig1.png
 

McLovin

Level 76
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,224
Looks interesting for those IE users. I only use IE when either Google Chrome or Firefox does not work.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
stormgtr said:
I wish SmartScreen to be system-wide on Windows 8, instead of limited to IE9.

Some leak pictures before in Windows 8 about SmartScreen Filter options.
 

LoftedAphid86

New Member
Feb 24, 2011
1,107
jamescv7 said:
stormgtr said:
I wish SmartScreen to be system-wide on Windows 8, instead of limited to IE9.

Some leak pictures before in Windows 8 about SmartScreen Filter options.
Do you have a source of such an image?
If this is true, it could make Windows 8 a very secure Operating System, although it would require a lot of data to be sent to Microsoft servers if this was to be effective.
 

jamescv7

Level 85
Verified
Honorary Member
Mar 15, 2011
13,070
elliotcroft said:
Do you have a source of such an image?
If this is true, it could make Windows 8 a very secure Operating System, although it would require a lot of data to be sent to Microsoft servers if this was to be effective.

Thread

Windows-8-App-Blacklisting-Mechanism-Is-Real-3.jpg
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top