ExploitShield appears to live up to its name | The Download Blog - CNET Download.com

ExploitShield appears to live up to its name

A brand-new security program looks like it puts a bullet in the head of many major software exploits, a complicated feat that could turn the world of computer security on its ear.

A new company called ZeroVulnerabilityLabs says that it has solved the Gordian knot of exploits, slicing through the complicated, Hydra-headed problem with a single stroke from a software weapon it calls ExploitShield.

Available exclusively today from Download.com, the first ExploitShield Browser Edition beta (download) appears to stop all manner of exploits, from those affecting browsers directly to browser plug-ins like PDF readers, Flash, and Java, to Microsoft Office components, to a handful of media players. The potential for raising the level of computer security here is huge, as a vast number of threats are actually mutations of malware, sold in kits like BlackHole, exploiting the same security holes in the same security programs.

The Windows-only ExploitShield is freeware for individuals and non-profits, part of ZeroVulnerabilityLabs' attempt to prove that the technology is so important that it's worth giving away. The company is working on a licensed version for businesses, although they don't have a timeline for its release yet.

Software exploits have long been a thorny software problem, hard to prevent because of source code complexity. For some notorious software, such as Java, Flash, and QuickTime, it can sometimes seem as though two exploits crop up for each one that gets patched. A panacea that cures all exploits, even ones that have yet to be used to breach a program, sounds too good to be true. Several Windows security suites have promised to block browser exploits, with Kaspersky's 2013 Automatic Exploit Prevention feature to be among the strongest offered, but that will set you back $60 retail.

In terms of features, ZeroVulnerabilityLabs plans on following in the footsteps of other free security programs that offer a paid upgrade. The free version of ExploitShield includes protection against drive-by downloads only, a powerful protection tool, as well as protection against attacks based on document file formats and media file formats. The company hopes to attracts businesses to the corporate upgrade by offering those features, and protection against DLL memory injection attacks, shield management for network deployment, quarantine management, and a centralized reporting portal.

ExploitShield is Silicon Valley's ZeroVulnerabilityLabs' first release. It's been in development for the past 12 months, according to its two co-founders, both of whom are experienced security researchers. Pedro Bustamante has more than 20 years' experience as a security researcher; the other co-founder is David Sanchez Lavado, a former employee of the security firm S21Sec and Panda Security, and ZeroVulnerabilityLabs' Chief Technical Officer.

"Ninety-five percent of successful exploits are Java- or PDF-based," said Bustamante in a meeting at CNET's San Francisco offices last June. "ExploitShield protects against exploit-delivered malicious payload," he said. "It's vulnerability-agnostic."

Because of the potentially implications of a freeware exploit-blocker that protects most major software, CNET insisted on permission from ZeroVulnerabilityLabs to hand off ExploitShield to independent experts to evaluate its efficacy.

Jeremiah Grossman, Chief Technical Officer of WhiteHat Security, said in an e-mail to CNET requesting comment on ExploitShield that the software offered a "concept and value proposition" that "sounds pretty good, especially in a corporate environment."

"There are a ton of important and unanswered questions here, but that's a good thing. This could be a strong emerging player that establishes a niche market. I'll be watching them for sure," he said.

Bustamante was reticent to explain how ExploitShield works, but did offer some insight in an e-mail. "It is not blacklisting, not whitelisting, and not sandboxing. We call it 'application shielding,' and it's basically a pro-active way of preventing vulnerability exploits. It blocks 100 percent of the exploits it protects against, 100 percent of the time. I think it's a new type of security software category, i.e., 'anti-exploits'," he said.

ZeroVulnerabilityLabs is making some heady claims with ExploitShield that so far appear to be supported by my everyday use of the software. Bustamante said in a subsequent e-mail to CNET that, "this is not an intrusive security technology like antivirus, whitelisting, or sandboxing. It is completely transparent to the user, install-and-forget."

Bustamante explained that currently known exploit methods against Microsoft's EMET and 32-bit based ASLR, such as ROP and anti-anti-ROP exploits, are blocked by ExploitShield.

At least on the counts of performance and stability, I have not noticed any appreciable differences in browser behavior. Bustamante did caution, however, that since ExploitShield is in beta, those problems could still crop up.

Adam J. O'Donnell, Chief Architect for the Cloud Technology Group at Sourcefire, said that the community of security experts will be curious about how ExploitShield works. "Once the thing is put up for download, everyone will be reversing it," he wrote to CNET in an e-mail earlier this week, after looking at ExploitShield. He also vouched for Bustamante's reputation, no small matter in the world of computer security.

Grossman agreed that ExploitShield could have far-reaching implications. "If this works as advertised, [it] sounds like they could have something very special here. The concept and value proposition sounds pretty good, especially in a corporate environment," he said.

CNET Top 5
Companies Apple could buy with their billions
Apple's sitting on a massive pile of cash. Here are five interesting ways they could spend it.
Play Video
 

Member Comments