Malicious Code Hidden in Rich Content Files Tough To Detect, According to Finjan Report

Finjan, a company that sells security products, said it has uncovered examples of obfuscated code embedded in rich-content files, and not just in HTML-based Web pages on legitimate Web sites. According to the vendor, code obfuscation remains the preferred technique for cybercriminals for their attacks.

Since JavaScript is the most-used scripting language for communication with Web browsers, third-party applications such as Flash player, PDF readers and other multimedia applications add support for JavaScript writing as part of their application, the company reported in its September 2008 "Malicious Page of the Month." This offers "crimeware" authors the opportunity to inject malicious code into rich-content files used by ads and user-generated content on Web 2.0 Web sites.

According to the report, only three of 36 virus-scanning products tested were able to detect the presence of that type of malicious code, which is dynamically embedded in the JavaScript.

Online ads and user-generated content on Web 2.0 Web sites are becoming more popular in directing users unwittingly to malware-infected content files. A recent survey by the company found that 46 percent of respondents stated that their organization didn't have a Web 2.0 security policy in place.

The company said real-time content inspection is the optimal way to detect and block dynamically obfuscated code, since it analyzes and understands the code embedded within Web content or files in real time--before it reaches users, who may unintentionally execute the Trojan on their machines.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • MathGPT

    MathGPT AI Tutor Now Out of Beta

    Ed tech provider GotIt! Education has announced the general availability of MathGPT, an AI tutor and teaching assistant for foundational math support.

  • person signing a bill at a desk with a faint glow around the document. A tablet and laptop are subtly visible in the background, with soft colors and minimal digital elements

    California Governor Signs AI Content Safeguards into Law

    California Governor Gavin Newsom has officially signed off on a series of landmark artificial intelligence bills, signaling the state’s latest efforts to regulate the burgeoning technology, particularly in response to the misuse of sexually explicit deepfakes. The legislation is aimed at mitigating the risks posed by AI-generated content, as concerns grow over the technology's potential to manipulate images, videos, and voices in ways that could cause significant harm.

  • white desk with an open digital tablet showing AI-related icons like gears and neural networks

    Elon University and AAC&U Release Student Guide to AI

    A new publication from Elon University 's Imagining the Digital Future Center and the American Association of Colleges and Universities offers students key principles for navigating college in the age of artificial intelligence.

  • abstract technology icons connected by lines and dots

    Digital Layers and Human Ties: Navigating the CIO's Dilemma in Higher Education

    As technology permeates every aspect of life on campus, efficiency and convenience may come at the cost of human connection and professional identity.