<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>imchris.org &#187; research</title>
	<atom:link href="http://www.imchris.org/wp/category/research/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imchris.org/wp</link>
	<description>chris grier's web site</description>
	<lastBuildDate>Sun, 25 Dec 2011 04:15:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Anti-virus labels are not suitable for system evaluation</title>
		<link>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/</link>
		<comments>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 22:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=256</guid>
		<description><![CDATA[I won't name names, but there's plenty of researchers out there that rely on anti-virus labeling in their research. While this could work, without manual validation there's very little chance the AV labels can be used as any sort of ground truth.

Here's 5 reports:
1. fc39ce1593cfb6ca1eb0c289a2ca561c
2. c4d93b536f35b350a992a402dfd72e12
3. c77ba55255c1db38568ca3a73d4b8a72
4. e57d938e0754e4fbb3b87cf818a0fc69
5. e397696b7835ccdcfad9d768cf1a091c

Quick highlights in classification from each report:
1. Bredolab, Krap, Ursnif, Downloader, Generic, etc...
2. Krap, Kryptic, Generic packed, etc...
3. Bredolab, Oficla, Krap, Zbot, Ldpinch, etc...
4. Bredolab, Harnig, Krap, Ursnif, etc...
5. FakeAV, Bubnix, etc... <a href="http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Click Trajectories press!</title>
		<link>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/</link>
		<comments>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 06:22:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=226</guid>
		<description><![CDATA[The paper, “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, got quite a bit of pres recently so there&#8217;s a number of great articles that summarize the paper content and have gone out to get quotes from banks and &#8230; <a href="http://www.imchris.org/wp/2011/06/14/click-trajectories-press/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Naming some popular spambots</title>
		<link>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/</link>
		<comments>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 20:52:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=187</guid>
		<description><![CDATA[Part of what I've been doing lately is finding, running, and maintaining bots in a controlled environment. The first part, finding, which includes identifying the binaries I'm running, turns out to be difficult to do. <a href="http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Running research on AWS</title>
		<link>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/</link>
		<comments>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 23:38:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=173</guid>
		<description><![CDATA[At the beginning of the year, in the middle of the project that led to the CCS paper on Twitter spam, I decided to try out Amazon Web Services. As I&#8217;ve slowly become familiar with the process, I&#8217;ve found that &#8230; <a href="http://www.imchris.org/wp/2010/09/13/running-research-on-aws/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>a journal paper</title>
		<link>http://www.imchris.org/wp/2010/06/30/a-journal-paper/</link>
		<comments>http://www.imchris.org/wp/2010/06/30/a-journal-paper/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 19:39:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=163</guid>
		<description><![CDATA[In the summer of 2007 I wrote a paper on the OP web browser that was published at Oakland in 2008. A few months afterward I was invited to submit it as a "fast tracked" paper in a journal. I thought it would be a easy way to add in some of the work we had done while working on and using OP since summer 2007.

If, or when, the journal paper actually gets published, security and systems researchers will have been using Chrome since Sept 2008 (over 2 years), had the opportunity to read the Gazelle paper (summer 2009), use Firefox with out-of-process plugins (spring 2010), and possibly even try out a full multi-process Firefox (upcoming release?), not to mention LCIE in IE8 (spring 2009). And this list doesn't even include the many other security improvements that have been made in these browsers. <a href="http://www.imchris.org/wp/2010/06/30/a-journal-paper/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/06/30/a-journal-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter spam paper at CCS 2010</title>
		<link>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/</link>
		<comments>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 21:22:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=159</guid>
		<description><![CDATA[My paper about spam on Twitter has been accepted into ACM Conference on Computer and Communications Security in Oct 2010. It&#8217;s going to be a fun presentation in Chicago, and I&#8217;m looking forward to continuing the project now that we &#8230; <a href="http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New papers up &#8211; WWW, LEET, PETS</title>
		<link>http://www.imchris.org/wp/2010/05/14/new-papers-up-www-leet-pets/</link>
		<comments>http://www.imchris.org/wp/2010/05/14/new-papers-up-www-leet-pets/#comments</comments>
		<pubDate>Fri, 14 May 2010 20:34:56 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=154</guid>
		<description><![CDATA[I&#8217;ve put added recent publications to the research page including links to the PDFs. Shuo presented our paper on Alhambra at WWW, Cho presented our paper on MegaD infiltration at LEET, and Kurt will be presenting unFriendly at PETS this &#8230; <a href="http://www.imchris.org/wp/2010/05/14/new-papers-up-www-leet-pets/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/05/14/new-papers-up-www-leet-pets/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Moved to Berkeley: research and climbing</title>
		<link>http://www.imchris.org/wp/2010/01/24/moved-to-berkeley-research-and-climbing/</link>
		<comments>http://www.imchris.org/wp/2010/01/24/moved-to-berkeley-research-and-climbing/#comments</comments>
		<pubDate>Mon, 25 Jan 2010 03:40:17 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[vacation]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=139</guid>
		<description><![CDATA[Last fall I moved to Berkeley and started as a postdoc in the EECS department for Vern Paxson. I&#8217;ve been there now for about 4 months working on a number of different security topics ranging from web security to bot &#8230; <a href="http://www.imchris.org/wp/2010/01/24/moved-to-berkeley-research-and-climbing/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/01/24/moved-to-berkeley-research-and-climbing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gazelle press!</title>
		<link>http://www.imchris.org/wp/2009/07/25/gazelle-press/</link>
		<comments>http://www.imchris.org/wp/2009/07/25/gazelle-press/#comments</comments>
		<pubDate>Sat, 25 Jul 2009 17:26:42 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=123</guid>
		<description><![CDATA[The Gazelle web browser, which was my summer project in 2008 at MSR, has been getting a lot of press lately and even has a wikipedia page now. It&#8217;s interesting to read and see what different writers say and how &#8230; <a href="http://www.imchris.org/wp/2009/07/25/gazelle-press/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2009/07/25/gazelle-press/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
<enclosure url="http://ee380.stanford.edu/cgi-bin/videologger.php?target=090415-ee380-300.asx" length="70" type="video/x-ms-asf" />
		</item>
		<item>
		<title>Gazelle &#8211; MSR project update</title>
		<link>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/</link>
		<comments>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 23:05:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=84</guid>
		<description><![CDATA[The project that I designed and developed at MSR last summer is going to be at USENIX security (and was previously a tech report). It&#8217;s available as a PDF here. Simply put, Gazelle is a browser with an OS architecture &#8230; <a href="http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

