July 2, 2008 9:15 AM PDT

IE 8 to have antimalware protection

On Wednesday, Microsoft announced new security features within the upcoming release of Internet Explorer 8 Beta 2. The features are designed to combat the rising tide of drive-by downloads and malicious scripts contained within carefully crafted links embedded in e-mail and Web pages. Most of the new features require systems to be running Windows Vista SP1 or Windows XP SP3.

Perhaps the most anticipated addition is Internet Explorer's new antimalware protection. Opera 9.5 and Firefox 3 both recently added antimalware protection. Safari has so far not announced plans for similar protection. Using mostly its own antimalware technology, Microsoft will block emerging threats by masking the entire IE 8 browser screen with a warning to users. The addition of malware protection to the existing antiphishing protection will be re-branded as the Microsoft SmartScreen filter.

IE 8 Beta 2 will have a Cross Site Scripting (XSS) filter, preventing scripts within a link from executing on the browser.

Previously announced features include highlighting domain names from the rest of the URL (so you can visually see that you are on eBay.com, not some other site), and extended verification SSL.

Using Data Execution Protection (DEP) within Windows XP SP3 and Windows Vista SP1, IE 8 will scan downloads and block any that it deems dangerous.

(Credit: Microsoft)

IE 8 Beta 1 has already introduced several changes when handling ActiveX components. Components will be installed per user, which eliminates the need for everyone to have administrator privileges. In addition, you must acknowledge or opt-in for the component to run, eliminating drive-by downloads. Components will be per site and will only be available from site of origin. Finally, site developers can request killbits from Microsoft which can be sent via Windows Update to terminate risky or outdated components.

For developers, Microsoft is including improvements for better communication between the client browser and Web server. Cross Domain Requests (CDR) is a more secure way for the browser to pull data from other domains; and Cross Domain Messaging (XDM) is a more secure means for a browser to send a message across a domain. Microsoft says it is working with other browser vendors to standardize these.

The public Beta 2 for Internet Explorer is expected sometime in August 2008.

Recent posts from Defense in Depth
Column: Raising Cain at Black Hat
Black Hat 2008: Notes from the field
Column: Finally, ID fraud protection that works
Column: Will you be ditching your antivirus app anytime soon?
A real simple answer to password protection
Add a Comment (Log in or register) 16 comments (Page 1 of 1)
by CmdrRickHunter July 2, 2008 10:07 AM PDT
How about fixing the malware instead of covering it up as you see it.
Reply to this comment View all 3 replies
by rmva July 2, 2008 10:22 AM PDT
CmdrRick, What does that mean?
Reply to this comment
by Lerianis July 2, 2008 10:58 AM PDT
How can they do that? Honestly, how can they do that when most of these 'malwares' take advantage of the same things that LEGITIMATE programs needs to run, CmdrRickHunter?
It's just IMPOSSIBLE for them to do that. The only thing Microsoft can legitimately do is warn you that a piece of software might be malware because it is coming from an 'unsafe' site, and keep you from downloading it.
Reply to this comment
by Penguinisto July 2, 2008 11:34 AM PDT
It appears that the mechanism is either a blacklist or some other "reporting" mechanism (similar to PhishTank.com, which has been around for roughly two years). Fair enough, but what on Earth insures that a "reported" website is really malware? The problem with blacklists is that it tends to trap false positives. PhishTank relies on human voting mechanisms to confirm or deny a bad site, which at least gives the process some transparency. What does MSFT have as an equivalent, so as to prevent false positives and/or allow a mechanism for site owners to remove themselves from the list if they accidentally get caught up in the blacklist?
Reply to this comment View all 2 replies
by Tergon July 2, 2008 2:03 PM PDT
As well as the issues voiced above by Lerianis and Penguinisto, I wonder about the effect on enterprise customers for the "feature" "Components will be installed per user" so does that mean each and every one of my employees must redownload flash or silverlight or acrobat or java or or or . . .
Reply to this comment
by i_made_this July 2, 2008 5:56 PM PDT
They advertised IE7 as the *great security upgrade* in 2006 - by 2008, most us have uninstalled or disabled all of these useless, cumbersome and hugely time-consuming crappy components which slowed surfing down to a crawl - and we're even getting tired of, if not mad as hell at that damn twirling circle that seems to take forever to find that report our boss needed an hour ago.

Microsoft knows they're in trouble with this browser business and and the proof is their starting to develop for FF as well as IE (just like Apple did before them for FF / Safari).

There is a simple and practical security solution Microsoft can deploy for securing IE8 and the O/S that'll come with it. Microsoft should pre-install their retail security suite/tune-up product - *Windows Live OneCare.* They're not selling terribly well and this is where that program truly belongs. For enterprise customers, I guess that'd be the corporate suite *Windows Forefront.*

So long as ActiveX remains a required program component within IE, WLOC (and WF) should be required without Microsoft's even asking us if we want it, as well. If we
prefer AVIRA or CHECK POINT or SYMANTEC etc, we can opt to disable WLOC.
Reply to this comment View reply
by dja1701 July 3, 2008 6:22 AM PDT
This "solution" sounds like it could cause problems. (like most microsoft solutions). I use a javascript to obscure my email address from crawlers. Clicking on an email link runs the script. From this description, it sounds like IE 8 would block that script.
Reply to this comment
by magusat999 July 3, 2008 3:25 PM PDT
Why does IE8 or any Windows product need "malware protection"? That's what Anti-Trojan, Anti-Virus, and Firewall Software is for. We don't need you (Microsoft) adding and "extra layer" onto our already protected systems. And besides, the specialists, such as Symantec, Eset, Comodo, etcetera don't have a million other eggs in their basket. They are doing just fine and the last thing we need is more junk added so you can justify higher prices and add another layer of conflicts with existing software... please, IE8 is fine - but stop with the silly "security features".
Reply to this comment
by blabtech July 6, 2008 9:56 AM PDT
It seems like they are trying to compete with Firefox

http://blabtech.blogspot.com
Reply to this comment
by AppleSuxLeo July 7, 2008 12:44 AM PDT
Safari IS malware ! Bwahahahaha !
Reply to this comment
Powered by Jive Software
advertisement
  • About Defense in Depth

  • Covering computer viruses and computer crime, Robert Vamosi goes beyond the hype to provide you with expert interviews of the top security researchers, as well as offering the hands-on, nontechnical advice you'll need to stay safe online.

Add this feed to your online news reader
Google
Yahoo
MSN

Latest tech news headlines

Featured blogs

Beyond Binary by Ina Fried

Coop's Corner by Charles Cooper

Defense in Depth by Robert Vamosi

Geek Gestalt by Daniel Terdiman

Green Tech

One More Thing by Tom Krazit

Outside the Lines by Dan Farber

The Iconoclast by Declan McCullagh

The Social by Caroline McCarthy

Underexposed by Stephen Shankland

Resource center from News.com sponsors
Same great protection. Reengineered for speed.
Norton Internet Security™2008

Click Here!
Norton still delivers award-winning protection and now uses 83% less memory and scans 48% faster than the competitor average. Get a FREE trial today!

Click Here!
Norton Beats the Competition

See how Norton Internet Security™2008 uses less memory, while scanning and booting faster than the competitor average.

Norton Protection Blog

Read the latest from our security experts as they help protect people from evolving online threats.

Protect Your Bluetooth Connection

Don't let fraudsters sink their teeth into your Bluetooth connection.

Vishing - What you need to know

Meet the latest ID theft scam: Voice Phishing.

Take Norton for a Test Drive Today!

Act now to get your FREE trial of Norton Internet Security 2008.

advertisement
On BNET: 10 reasons to embrace failure
Advanced
search
Advanced
search
Visit other CBS Interactive sites