Microsoft engineers have created, as they say, the world's first platform specifically designed to stop exploit kits.
The tool is called “Kizzle” and is a fast signature compiler that aims to identify the common practice of code reuse by malware developers, to detect disguised signatures weeks before they are detected by current anti-virus techniques.
For those who don't know, exploit kits are an attempt to package multiple attack techniques and tools into one multi-tool.
Researchers Stock, Livshits, and Zorn from the University of Erlangen in Nuremberg and Microsoft engineers published the study Kizzle: A Signature Compiler for Exploit Kits (PDF) reporting that the Kits bundles looked wildly different until they were decompressed.
“The approach taken by the Kizzle tool is based on our observation that while exploit kits change the malware they contain frequently, kit authors generally reuse much of the code from version to version.
“Ironically, this is a software engineering practice that allows us to develop a scalable and accurate detector that is able to respond quickly to superficial, but frequent, changes in exploit kits.”
False positive alerts are less than 0.03%, so we are talking about a huge improvement compared to today's commercial anti-viruses.
The new technology from Microsoft marks a new era in cybersecurity, at least until malicious developers adapt their techniques.
In any case, the researchers' effort is very valuable for today's online community, which is also attacked by canned threats.
