Re: Obfuscated web pages

Jon Oberheide <[email protected]>
Newsgroups gmane.comp.security.ids
Message-ID <1203042533.6307.4.camel@apollo>
On Thu, 2008-02-14 at 16:17 -0500, Gary Flynn wrote:
> Tim wrote:
> > The specific issue of JavaScript obfuscation drives this point home
> > quite well.   IMO, it is unlikely that any IDS engine could implement
> > the beast that is ECMAScript and all of it's children and still be safe
> > while reliably detecting attacks.  It approaches issues similar to the
> > halting problem.
> 
> I suspect that no vendors support this feature ( actual code
> execution in some sort of sandbox ) and I was just trying to
> verify it.

I would recommend checking out SpyProxy, presented at last year's USENIX
Security.  While it's not a commercial vendor-supported product and has
its share of limitations, it does demonstrate that an inline
execution-based IDS/IPS proxy may be feasible:

http://www.cs.washington.edu/homes/tbragin/spyproxy.pdf

Regards,
Jon Oberheide

-- 
Jon Oberheide <[email protected]>
GnuPG Key: 1024D/F47C17FE
Fingerprint: B716 DA66 8173 6EDD 28F6  F184 5842 1C89 F47C 17FE
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQBHtPjlWEIcifR8F/4RAjfAAKDyIMngEEO57gGj2EGCnhHohh4cJwCbB5A6
jFhDQfgOGHnDj27P20I/y6A=
=xvtf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.