<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>imchris.org</title>
	<atom:link href="http://www.imchris.org/wp/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imchris.org/wp</link>
	<description>chris grier's web site</description>
	<lastBuildDate>Sun, 25 Dec 2011 04:15:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Chrome extensions and security</title>
		<link>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/</link>
		<comments>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/#comments</comments>
		<pubDate>Mon, 03 Oct 2011 20:17:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=272</guid>
		<description><![CDATA[Adrienne wrote a blog post about some of her recent work analyzing Google Chrome extensions for security related bugs. It&#8217;s a nice read and illuminates mistakes made by a surprisingly large number of extension developers (27 / 100 extensions leak &#8230; <a href="http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/10/03/chrome-extensions-and-security/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>paper at IMC 2011</title>
		<link>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/</link>
		<comments>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/#comments</comments>
		<pubDate>Fri, 16 Sep 2011 08:26:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=264</guid>
		<description><![CDATA[This year we have a paper studying the activity of suspended users on Twitter, which will appear at IMC in November. The title is &#8220;Suspended Accounts In Retrospect: An Analysis of Twitter Spam&#8220;, and the paper presents a unique perspective &#8230; <a href="http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/16/paper-at-imc-2011/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Anti-virus labels are not suitable for system evaluation</title>
		<link>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/</link>
		<comments>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 22:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=256</guid>
		<description><![CDATA[I won't name names, but there's plenty of researchers out there that rely on anti-virus labeling in their research. While this could work, without manual validation there's very little chance the AV labels can be used as any sort of ground truth.

Here's 5 reports:
1. fc39ce1593cfb6ca1eb0c289a2ca561c
2. c4d93b536f35b350a992a402dfd72e12
3. c77ba55255c1db38568ca3a73d4b8a72
4. e57d938e0754e4fbb3b87cf818a0fc69
5. e397696b7835ccdcfad9d768cf1a091c

Quick highlights in classification from each report:
1. Bredolab, Krap, Ursnif, Downloader, Generic, etc...
2. Krap, Kryptic, Generic packed, etc...
3. Bredolab, Oficla, Krap, Zbot, Ldpinch, etc...
4. Bredolab, Harnig, Krap, Ursnif, etc...
5. FakeAV, Bubnix, etc... <a href="http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Click Trajectories press!</title>
		<link>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/</link>
		<comments>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/#comments</comments>
		<pubDate>Wed, 15 Jun 2011 06:22:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=226</guid>
		<description><![CDATA[The paper, “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, got quite a bit of pres recently so there&#8217;s a number of great articles that summarize the paper content and have gone out to get quotes from banks and &#8230; <a href="http://www.imchris.org/wp/2011/06/14/click-trajectories-press/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/06/14/click-trajectories-press/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Papers at 2011 IEEE Symp. on S&amp;P</title>
		<link>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/</link>
		<comments>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/#comments</comments>
		<pubDate>Thu, 19 May 2011 21:24:39 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=183</guid>
		<description><![CDATA[We had two papers at Oakland this year, and I&#8217;ve put the PDFs up online. Kirill and Kurt  presented on Tuesday afternoon (schedule) NYT Article on the &#8220;Click Trajectories&#8221; work: http://nyti.ms/j6sf5c “Click Trajectories: End-to-End Analysis of the Spam Value Chain”, &#8230; <a href="http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/05/19/papers-at-2011-ieee-symp-on-sp/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Naming some popular spambots</title>
		<link>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/</link>
		<comments>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 20:52:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=187</guid>
		<description><![CDATA[Part of what I've been doing lately is finding, running, and maintaining bots in a controlled environment. The first part, finding, which includes identifying the binaries I'm running, turns out to be difficult to do. <a href="http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>presenting at CCS Tuesday</title>
		<link>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/</link>
		<comments>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 01:53:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=179</guid>
		<description><![CDATA[I&#8217;m going to be at CCS 2010 in Chicago this week presenting @spam: The Underground on 140 Characters or Less. My presentation is the 3rd talk of the conference in the security session (on the first day).]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Illinois email going away!</title>
		<link>http://www.imchris.org/wp/2010/09/22/illinois-email-going-away/</link>
		<comments>http://www.imchris.org/wp/2010/09/22/illinois-email-going-away/#comments</comments>
		<pubDate>Wed, 22 Sep 2010 22:14:30 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=175</guid>
		<description><![CDATA[grier@uiuc.edu and grier@illinois.edu are going to stop working this Friday! CITES is officially done forwarding my email. Use my new ones @berkeley.edu, or better yet: grier@imchris.org!]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/09/22/illinois-email-going-away/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Running research on AWS</title>
		<link>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/</link>
		<comments>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/#comments</comments>
		<pubDate>Mon, 13 Sep 2010 23:38:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=173</guid>
		<description><![CDATA[At the beginning of the year, in the middle of the project that led to the CCS paper on Twitter spam, I decided to try out Amazon Web Services. As I&#8217;ve slowly become familiar with the process, I&#8217;ve found that &#8230; <a href="http://www.imchris.org/wp/2010/09/13/running-research-on-aws/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/09/13/running-research-on-aws/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>a journal paper</title>
		<link>http://www.imchris.org/wp/2010/06/30/a-journal-paper/</link>
		<comments>http://www.imchris.org/wp/2010/06/30/a-journal-paper/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 19:39:32 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=163</guid>
		<description><![CDATA[In the summer of 2007 I wrote a paper on the OP web browser that was published at Oakland in 2008. A few months afterward I was invited to submit it as a "fast tracked" paper in a journal. I thought it would be a easy way to add in some of the work we had done while working on and using OP since summer 2007.

If, or when, the journal paper actually gets published, security and systems researchers will have been using Chrome since Sept 2008 (over 2 years), had the opportunity to read the Gazelle paper (summer 2009), use Firefox with out-of-process plugins (spring 2010), and possibly even try out a full multi-process Firefox (upcoming release?), not to mention LCIE in IE8 (spring 2009). And this list doesn't even include the many other security improvements that have been made in these browsers. <a href="http://www.imchris.org/wp/2010/06/30/a-journal-paper/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/06/30/a-journal-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

