CFA/Security-Research/MalwareDetection

« Comparative Feature Analyses
« Security Notes
« Security Research

Current Capabilities

  • Notification whenever downloading or installing software
  • Warn me when sites try to install add-ons

Upcoming Capabilities

  • Tell me if a download is suspected malware - FF3

Features by 3rd parties or other browsers

  • Real-time with behavior-based profiling algorithms - Finjan SecureBrowsing FF extension, Haute Secure
    • Executable blocked
    • Embedded content blocked (ad, video, blog, photo, etc.)
    • Page blocked
    • Site blocked
  • Protected Mode - runs in isolation from other applications in the OS. Restricts exploits and malware from writing to any location beyond Temporary Internet Files without explicit user consent - IE7
  • Cross-domain barriers - prevent script on webpages from interacting with content from the other domains or windows; protects against malware by helping prevent malicious websites from manipulating flaws in other websites - IE
  • Removes spyware - IE extension SpyWall Anti-Spyware
  • Using virtual machine techniques - GreenBorder (bought by Google)

Additional features

  • Integrate sandboxing feature like Sandboxie; integrate virus scanning and malware protection for retrieved content/files - FF brainstorm
  • Ability to disable handling and downloading of certain file types - FF brainstorm
  • Extension installation - one click to permanently add site to whitelist - FF brainstorm

Screenshots

"site:" lets you use google to search a specific site:

 

Safari SnapBack button takes you back to search results:

 

Conclusions