On mySimon: Toy Concept Polaris Rush Snowmobile
BNET Business Network:
BNET
TechRepublic
ZDNet

August 19th, 2009

IE8 outperforms competing browsers in malware protection -- again

Posted by Dancho Danchev @ 6:16 am

Categories: Anti Virus, Apple, Botnets, Browsers, Exploit code, Firefox, Hackers, Malware, Microsoft, Mozilla, Pen testing, Phishing, Research, Spam and Phishing

Tags: Malware, Microsoft Internet Explorer, Web Browser, IE8, Spyware, Adware & Malware, Cyberthreats, Viruses And Worms, Security, Dancho Danchev

A recently released study by NSS Labs is once again claiming that based on their internal tests, Microsoft’s Internet Explorer 8 outperforms competing browsers like Google’s Chrome, Mozilla’s Firefox, Opera and Apple’s Safari in terms of protecting their users against “socially engineered malware” and phishing attacks.

Not only did IE8 top the chart, but also, the rest of the browsers have in fact degraded their “socially engineered malware” and phishing block rate in comparison to the results released by the company in the March’s edition of the study.

How objective is the study? For starters, it’s Microsoft-sponsored one. Here’s how it ranks the browsers:

Socially engineered malware block rate:

  • Microsoft Internet Explorer v8 - 81% block rate
  • Mozilla Firefox v3 - 27% block rate
  • Apple Safari v4 - 21% block rate
  • Google Chrome 2 - 7% block rate
  • Google Chrome 2 - 7% block rate

Phishing attacks block rate:

  • Microsoft Internet Explorer v8 - 83% block rate
  • Mozilla Firefox v3  - 80% block rate
  • Opera 10 Beta - 54% block rate
  • Google Chrome 2 - 26% block rate
  • Apple Safari v4 - 2% block rate

What is “socially engineered malware” anyway? Basically, it’s the direct download dialog box that appears on a, for instance, scareware or Koobface video page spoofing Facebook’s layout, like the one attached. using “socially engineered malware” as a benchmark for malware block rate isn’t exactly the most realistic choice in today’s threatscape.

And even if it is, some pretty realistic conclusions can be drawn by using some internal traffic statistics from Koobface worm’s ongoing malware campaigns. The Koobface worm, one of the most efficient social engineering driven malware, is a perfect example of how security measures become obsolete when they’re not implemented on a large scale. The stats themselves:

- MSIE 7 - 255,891 visitors - 43.33%
- MSIE 8 - 189,380 visitors - 32.07%
- MSIE 6 - 76,797 visitors - 13.01%
- Javascript Enabled - 585,374 visitors - 99.13%
- Java Enabled - 576,782 visitors - 97.68%

What does this mean? It means that with or without the supposedly working “socially engineered malware” block filter using a modest sample of several hundred URLs, the Koobface botnet is largely driven by MSIE 7 users. The irony is that the previous edition of the study dubbed IE7 a browser which “practically offers no protection against malware” with the lowest block rate achieved back than - 4%.

Just like the previous edition of the study, this one also excludes the notion that client-side vulnerabilities (Secunia: Average insecure program per PC rate remains high; Secunia: popular security suites failing to block exploits) continue contributing to the “rise and rise” of web malware exploitation kits. By excluding client-side vulnerabilities, the study isn’t assessing IE8’s DEP/NX memory protection, as well as omitting  ClickJacking defenses and IE8’s XSS filter, once pointed out as a less sophisticated alternative to the Firefox-friendly NoScript.

Socially engineered malware is not the benchmark for a comprehensive assessment of a browser’s malware block rate. It’s a realistic assessment of the current and emerging threatscape combined with comprehensive testing of all of the browser’s currently available security mechanisms, a testing methodology which I think is not present in the study.

Dancho DanchevDancho Danchev is an independent security consultant and cyber threats analyst, with extensive experience in open source intelligence gathering, malware and cybercrime incident response. He's been an active security blogger since 2007, and maintains a popular security blog. See his full profile and disclosure of his industry affiliations.

Email Dancho Danchev

Subscribe to Zero Day via Email alerts or RSS.

  • Talkback
  • Most Recent of 163 Talkback(s)
Piss off loser (NT)
NT (Read the rest)
Posted by: No More Microsoft Software Ever! Posted on: 09/16/09 You are currently: a Guest | | Terms of Use
Well the credibility of the test is extremely...  mrlinux | 08/19/09
Have to agree with the Linux fanboys this time. Since it is  NeoGeneration | 08/19/09
But if one was done by  GuidingLight | 08/19/09
Good question  JonWayn | 08/19/09
Wrong  deepee912 | 08/20/09
Piss off loser (NT)  No More Microsoft Software Ever! | 09/16/09
Actually I would believe a study sponsored  CodeCurmudgeon | 08/19/09
Browser wars are on again?  Rude Union | 08/24/09
Presentation is everything...  Filker0_z | 08/27/09
OMG! You agree that Microsoft does ANYTHING to sell their warez! (NT)  No More Microsoft Software Ever! | 09/16/09
Well, on the flip side of that  GuidingLight | 08/19/09
If the report was false...  Marty R. Milette | 08/19/09
Sounds like a fellow who's never heard of RedHat  FrankleeMiDeer | 08/19/09
So WHERE is THEIR report?  Marty R. Milette | 08/19/09
Uhh ... why do one?  daboochmeister | 08/20/09
Exactly  Mikael_z | 08/25/09
What's with the FUD about ActiveX?  Marty R. Milette | 08/25/09
The report is not credible  Filker0_z | 08/19/09
Internet Explorer relys on third parties...  JCitizen | 08/19/09
Instead of your whole life story...  Rubix_z | 08/20/09
@Rubix_z - You are a troll (My professional opinion)  Isocrates | 08/22/09
Credibility of the test doesn't necessarily rely on who sponsored it  Cayble | 08/19/09
Statistics can say whatever you want them to say  shanee25 | 08/19/09
Nobody, not even MS suggested this proves IE8 is better.  xuniL_z | 08/20/09
root-kitted Linux boxes  tmsbrdrs | 08/21/09
Enough "Neighbor loaded with malware" anecdotes. I believe you BUT....  xuniL_z | 08/21/09
@xuniL_z - Suppressed evidence: Evading the issue & Straw man fallacy  Isocrates | 08/22/09
@Isocrates. Right away, you show a lack of humility with your self...  xuniL_z | 08/23/09
@tmsbrdrs your answer and a request.  xuniL_z | 08/23/09
What has Bing "Linux botnets" to do with IE8?  Ole Man | 08/24/09
@xuniL_z  tmsbrdrs | 08/26/09
@tmsbrdrs I have to disagree.  xuniL_z | 09/01/09
Why Indeed?  sirpaul1 | 08/21/09
Sounds like  rMatey | 08/25/09
Another MS "study" proves that MS is the best. Surprise surprise... nt  T1Oracle | 08/19/09
Well I guess according to these results  Michael Kelly | 08/19/09
Probably complacency, not gullibility  rapson | 08/19/09
That's certainly a good hypothesis  Michael Kelly | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  DannyO_0x98 | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  Loverock Davidson | 08/19/09
Sorry Love  gnesterenko | 08/19/09
well...  davidhite | 08/19/09
That may be the case  Loverock Davidson | 08/19/09
I Use NoScript  mdsock@... | 08/19/09
Since you mention NoScript...  JCitizen | 08/19/09
Mozilla Site Adviser  sirpaul1 | 08/19/09
That'll work!...  JCitizen | 08/20/09
Re:Since you mention........  Disgruntled M$ User | 08/20/09
Thank you very much!...(nt)  JCitizen | 08/20/09
Typical Linux solution...  Marty R. Milette | 08/19/09
Microsoft and POWER  Roc Riz | 08/20/09
Escape the stone age...  Marty R. Milette | 08/24/09
And you think ...  JonWayn | 08/19/09
Common Sense is better protection still.  User 13 | 08/19/09
true  gnesterenko | 08/19/09
Common sense  zdnet-gregc | 08/19/09
Which unfortunately is A LOT of users...nt  ItsTheBottomLine | 08/19/09
Sadly, browsing isn't the only area in which many people lack common sense  Laraine Anne Barker | 08/19/09
Ehh  gnesterenko | 08/19/09
Re: Ehh  boomchuck1 | 08/19/09
Re: Chrome Security  dvm | 08/19/09
Opera is the king  thorsthunder | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  steve@... | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  nle9@... | 08/19/09
IE 8  blyas@... | 08/19/09
IE 8 beta  boomchuck1 | 08/19/09
Compatibility View  kjpino | 08/19/09
The issues were multiple  nle9@... | 08/19/09
"Threatscape"...cool vocabulary  feskridge@... | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  brussellradio | 08/19/09
Try this...  Dietrich T. Schmitz | 08/19/09
On Vista the right click menu has "run as administrator" instead of runas..  xuniL_z | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  mcd_jeannot@... | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  hornplayer6339@... | 08/19/09
I see no use for using IE8. Only Firefox 3.5 or Chrome.  Grayson Peddie | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  agrussner | 08/19/09
Come on guys... Throw Microsoft a bone...  i8thecat | 08/19/09
Don't waste our time with MS sponsored studyies  bruce@... | 08/19/09
Hmm... If only I can come up with my own metrics...  billcheng | 08/19/09
I don't think Dancho should feel the heat for publishing  mhenriday | 08/19/09
IT DOESN'T MATTER  ecrap | 08/19/09
Firefox 3.5.2 plus NoScript equals peace of mind for me.  D. W. Bierbaum | 08/19/09
For non-MS sponsiored results...  rbsjrx | 08/19/09
did you read your link  jdbukis@... | 08/25/09
Come on guys  don3605 | 08/19/09
Master Joe Says...  MasterJoe | 08/19/09
false claims  znetlol | 08/19/09
In the field, it's the IE8 users have the most trouble  WiredGuy | 08/19/09
Not with Vista x64!...  JCitizen | 08/19/09
Seriously...  Cayble | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  jimszd01 | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  1863650 | 08/19/09
Whoops...  1863650 | 08/19/09
Yeah, I'd believe that...  JCitizen | 08/19/09
This "test" is skewed  Roc Riz | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  daveginorge | 08/19/09
Misleading title  Filker0_z | 08/19/09
If you don't find it more compliant...  Spiritusindomit@... | 08/24/09
No need for personal abuse  Filker0_z | 08/25/09
Bravo!  Isocrates | 09/03/09
Are any studies not tilted?  Narg | 08/19/09
How about W3C Standards Compliance?  Warazen | 08/19/09
IE8: I'm Actually IMPRESSED.  XweAponX | 08/19/09
Damn.  Lester Young | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  NBSF | 08/19/09
Please provide proof that NSS Labs is biased.  xuniL_z | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  NBSF | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  erniem1970@... | 08/19/09
Dede,  r.u.FED.up.2 | 08/19/09
I add security to both IE8 and Firefox withZoneAlarm  I am Gorby | 08/19/09
Reputable testing firms haven't given it..  JCitizen | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  pfreire | 08/19/09
MS "study" proves that MS Browser is the best - again  awasson@... | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  cpwong | 08/19/09
RE: IE8 outperforms competing browsers in malware protection -- again  avoidz | 08/19/09
If Microsoft would have given instruction..  JCitizen | 08/19/09
Is ZDNET now an anon subsidiary of MS? Then change the sites name to: MSNZD  gennx30 | 08/19/09
Linux?  erasmusp@... | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  ereal_2000@... | 08/20/09
Who should respond?  erasmusp@... | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  Wm_Hayashi | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  nolimel@... | 08/20/09
Did Microsoft pay for this study?  aandruli@... | 08/20/09
Studies Funded By Microsoft - IE 8 "Safest" Web Browser  Ole Man | 08/23/09
RE: IE8 outperforms competing browsers in malware protection -- again  ulfahl69@... | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  ulfahl69@... | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  stuffinator@... | 08/20/09
NSS Labs is a reliable company  JordanN. | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  JordanN. | 08/20/09
IE8 lost me on the first web address key in  david@... | 08/20/09
Re IE 8 Not to dispute your findings, However...  Aaron A Baker | 08/20/09
Since you have a very capable computer...  JCitizen | 08/20/09
Thanks JC  Aaron A Baker | 08/20/09
Your welcome! I no longer..  JCitizen | 08/21/09
Puts my mind at ease...  bbneo | 08/20/09
I'd still do this...  JCitizen | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  itet | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  The_Quietman | 08/20/09
RE: IE8 outperforms competing browsers in malware protection -- again  recordman10@... | 08/20/09
Noscript is not a part of Firefox.  IE8 | 08/21/09
Viruses  milldogtjm | 08/23/09
Not true  jdbukis@... | 08/24/09
Why can't you get your story straight...  Marty R. Milette | 08/24/09
Microsoft's IE 8 puts giant web hole on notice  Ole Man | 08/24/09
Well  jdbukis@... | 08/24/09
Do you always put words in people's mouths?  Marty R. Milette | 08/24/09
Wow! Take a Break and Step Away From The Computer!  chessmen | 08/25/09
As I understand it  jdbukis@... | 08/25/09
Irritate you much?  Ole Man | 08/25/09
A very SAD individual...  Marty R. Milette | 08/25/09
Any excuse is a good one  Ole Man | 09/05/09
RE: IE8 outperforms competing browsers in malware protection -- again  SystemVoid | 08/25/09
RE: IE8 outperforms competing browsers in malware protection -- again  CastleDI | 08/25/09
The last malware spyware scan I ran produced results  cymru999 | 08/25/09
RE: IE8 outperforms competing browsers in malware protection -- again  znetlol | 08/25/09
No script  jdbukis@... | 08/25/09
RE: IE8 outperforms competing browsers in malware protection -- again  reed@... | 08/27/09
RE: IE8 outperforms competing browsers in malware protection -- again  reed@... | 08/27/09
No a user issue  reed@... | 08/27/09
In the corporate environment...  Marty R. Milette | 08/27/09
How about lynx?  Filker0_z | 08/27/09
Why am I NOT surprised by this?  nbahn | 09/01/09
This guy is lost (or an MS Shill).!  No More Microsoft Software Ever! | 09/16/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here