100 likes | 265 Views
Rozzle : De- Cloaking Internet Malware. Clemens Kolbitsch , Christian Seifert , Benjamin Livshits and Benjamin Zorn Microsoft Research Technical Report Presentation by David Ferreras. The P roblem.
E N D
Rozzle: De-Cloaking Internet Malware Clemens Kolbitsch,Christian Seifert, BenjaminLivshits and BenjaminZorn Microsoft ResearchTechnicalReport Presentationby David Ferreras
TheProblem • The browser isexposedtomaliciouscontentthataffectmillions of URLsusing JavaScript • Web-based malware tendstotarget a particular browser, oftenattackingspecificversions of installedplugins. • Environmentmatching • Fingerprinting • Client-Sidecloaking
TheSolutionProposed • Rozzle: Multi-execution JavaScript implementation • executebothpossibilitieswheneveritencounters control flowbranchingthatisdependentontheenvironment
TheSolutionProposed (Details) • SymbolicValues: Allenvironment-specificvaluesstartout as symbolic in Rozzle • Branchingonsymbolicvalues • Looping onsymbolicvalues • Creates a heap of values
Limitations • Server-sidecloaking • Breakingexistingcode • IdentifyingthatRozzleisenabledcould be usedconstructdenial-of serviceattackonRozzle-enabled browsers.