New Developments From Microsoft Research
prostoalex writes "Information Week magazine runs a brief report from Microsoft Research, showcasing some of the new technologies the company's research division is working on. Among them — a rootkit that eliminates other rootkits, a firewall that blocks the traffic exploiting published vulnerabilities, a system for catching lost e-mail, a honeypot targeted at discovering zero-day exploits, and some anti-phishing applications."
> a rootkit that eliminates other rootkits
Well, there goes kernel stability.
I'm really not sure I want a future Norton RootKit Protector installing itself, bugs and all, into my kernel.
How the fuck does email get "lost"? How could that happen? Even a server crash should not cause that.
Why not, instead, spend the time and money finding the real problem in your email system and fixing that? I handle about 1,500 in-bound messages a day. By their calculations, I should be losing 15 or so, every day. Yet that does not seem to be happening.
There appears to be no legitimate purpose to such research.
1. A rootkit that eliminates other rootkits can probably also be eliminated, so this research does not really solve a problem.
2. Rather than perfecting a rootkit, they should be working towards making a rootkit an impossibility in their OS.
3. If you can write a rootkit, eliminating other rootkits does not appear to be that large of a challenge in the first place.
4. If you want to eliminate a rootkit, reinstalling the OS seems like a better idea.
5. There are countless illicit uses of such software.
Are they developing this rootkit in an effort to develop new security for their OS? I don't get it.
The "classic" honeypot is pretty much dead. Nobody uses a 0day against a random machine anymore. At the very least, one tries to avoid certain IPs and IP Ranges that are known to host pots. Whether MS wants to believe it or not, those lists exist. One of my pots has been discovered a while ago and on that machine, I've never had any detections since, except a few scriptkids that don't count.
Even "detecting" pots that simulate a user's behaviour and look actively for forged sites and such are getting out of usefulness, since a lot of distributors already start hardening their attacks against aggressive farming. Or they require you to go through very detailed steps that a bot cannot reproduce. I've recently had my first captcha-protected exploit (was a porn site, and what user wouldn't solve a captcha to get his pic when he surfed there just for that in the first place?).
Forget honeypots. Unless you put a human behind that VM it's running on. Automated pots are becoming less and less useful with attackers becoming more and more aware of them. Especially you can dump any kind of "honeypot kit", they are known and their quirks are tested painstakingly before an attack takes place.
We used to have a Bill of Rights. Now, with the rights gone, all we have left is the bill.