<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>imchris.org &#187; research</title>
	<atom:link href="http://www.imchris.org/wp/tag/research/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.imchris.org/wp</link>
	<description>chris grier's web site</description>
	<lastBuildDate>Sun, 25 Dec 2011 04:15:00 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3</generator>
		<item>
		<title>Anti-virus labels are not suitable for system evaluation</title>
		<link>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/</link>
		<comments>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/#comments</comments>
		<pubDate>Fri, 02 Sep 2011 22:11:00 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=256</guid>
		<description><![CDATA[I won't name names, but there's plenty of researchers out there that rely on anti-virus labeling in their research. While this could work, without manual validation there's very little chance the AV labels can be used as any sort of ground truth.

Here's 5 reports:
1. fc39ce1593cfb6ca1eb0c289a2ca561c
2. c4d93b536f35b350a992a402dfd72e12
3. c77ba55255c1db38568ca3a73d4b8a72
4. e57d938e0754e4fbb3b87cf818a0fc69
5. e397696b7835ccdcfad9d768cf1a091c

Quick highlights in classification from each report:
1. Bredolab, Krap, Ursnif, Downloader, Generic, etc...
2. Krap, Kryptic, Generic packed, etc...
3. Bredolab, Oficla, Krap, Zbot, Ldpinch, etc...
4. Bredolab, Harnig, Krap, Ursnif, etc...
5. FakeAV, Bubnix, etc... <a href="http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2011/09/02/anti-virus-labels-are-not-suitable-for-system-evaluation/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Naming some popular spambots</title>
		<link>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/</link>
		<comments>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/#comments</comments>
		<pubDate>Tue, 19 Oct 2010 20:52:46 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=187</guid>
		<description><![CDATA[Part of what I've been doing lately is finding, running, and maintaining bots in a controlled environment. The first part, finding, which includes identifying the binaries I'm running, turns out to be difficult to do. <a href="http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/19/naming-some-popular-spambots/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>presenting at CCS Tuesday</title>
		<link>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/</link>
		<comments>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/#comments</comments>
		<pubDate>Mon, 04 Oct 2010 01:53:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=179</guid>
		<description><![CDATA[I&#8217;m going to be at CCS 2010 in Chicago this week presenting @spam: The Underground on 140 Characters or Less. My presentation is the 3rd talk of the conference in the security session (on the first day).]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/10/03/presenting-at-ccs-tuesday/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Twitter spam paper at CCS 2010</title>
		<link>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/</link>
		<comments>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/#comments</comments>
		<pubDate>Mon, 28 Jun 2010 21:22:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=159</guid>
		<description><![CDATA[My paper about spam on Twitter has been accepted into ACM Conference on Computer and Communications Security in Oct 2010. It&#8217;s going to be a fun presentation in Chicago, and I&#8217;m looking forward to continuing the project now that we &#8230; <a href="http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2010/06/28/twitter-spam-paper-at-ccs-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Gazelle &#8211; MSR project update</title>
		<link>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/</link>
		<comments>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/#comments</comments>
		<pubDate>Sun, 12 Jul 2009 23:05:43 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=84</guid>
		<description><![CDATA[The project that I designed and developed at MSR last summer is going to be at USENIX security (and was previously a tech report). It&#8217;s available as a PDF here. Simply put, Gazelle is a browser with an OS architecture &#8230; <a href="http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2009/07/12/gazelle-msr-tech-report/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fall 2008</title>
		<link>http://www.imchris.org/wp/2008/11/02/fall-2008/</link>
		<comments>http://www.imchris.org/wp/2008/11/02/fall-2008/#comments</comments>
		<pubDate>Sun, 02 Nov 2008 22:48:57 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[school]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=55</guid>
		<description><![CDATA[Fall 08 started a quick and is already half over. I&#8217;ve been continuing my project from Microsoft Research, working with a security group there lead by Helen Wang and working on a couple other security projects at school. I&#8217;m almost &#8230; <a href="http://www.imchris.org/wp/2008/11/02/fall-2008/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2008/11/02/fall-2008/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Illinois Malicious Processor Paper</title>
		<link>http://www.imchris.org/wp/2008/04/14/illinois-malicious-processor-paper/</link>
		<comments>http://www.imchris.org/wp/2008/04/14/illinois-malicious-processor-paper/#comments</comments>
		<pubDate>Tue, 15 Apr 2008 04:18:18 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[hardware]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=3</guid>
		<description><![CDATA[The Illinois Malicious Processor (IMP) project I worked on was written up by InfoWorld! Its a great read: Read it here &#8211; That is in addition to it being published at LEET and being awarded a Best Paper Award! The &#8230; <a href="http://www.imchris.org/wp/2008/04/14/illinois-malicious-processor-paper/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2008/04/14/illinois-malicious-processor-paper/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Secure web browsing with the OP web browser</title>
		<link>http://www.imchris.org/wp/2008/03/05/secure-web-browsing-with-the-op-web-browser/</link>
		<comments>http://www.imchris.org/wp/2008/03/05/secure-web-browsing-with-the-op-web-browser/#comments</comments>
		<pubDate>Thu, 06 Mar 2008 04:21:06 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[browsers]]></category>
		<category><![CDATA[security]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=6</guid>
		<description><![CDATA[Sam, Shuo and I have had our paper accepted at the 2008 Symposium on Security and Privacy (Oakland) conference this spring. Here&#8217;s the PDF. It was also written up in the news! &#8220;Secure web browsing with the OP web browser&#8221;, &#8230; <a href="http://www.imchris.org/wp/2008/03/05/secure-web-browsing-with-the-op-web-browser/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2008/03/05/secure-web-browsing-with-the-op-web-browser/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Summer 2008 &#8211; Seattle and research</title>
		<link>http://www.imchris.org/wp/2008/03/01/summer-2008-seattle-and-research/</link>
		<comments>http://www.imchris.org/wp/2008/03/01/summer-2008-seattle-and-research/#comments</comments>
		<pubDate>Sat, 01 Mar 2008 14:48:14 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=21</guid>
		<description><![CDATA[I&#8217;m going to Microsoft Research for the summer after I present at the IEEE Symposium on Security and Privacy. I&#8217;ll be out in Redmond, WA at the end of May through August. I&#8217;m going to be doing some pretty interesting &#8230; <a href="http://www.imchris.org/wp/2008/03/01/summer-2008-seattle-and-research/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2008/03/01/summer-2008-seattle-and-research/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fall 2007 school and stuff</title>
		<link>http://www.imchris.org/wp/2007/08/22/fall-2007-school-and-stuff/</link>
		<comments>http://www.imchris.org/wp/2007/08/22/fall-2007-school-and-stuff/#comments</comments>
		<pubDate>Wed, 22 Aug 2007 14:57:10 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[research]]></category>
		<category><![CDATA[school]]></category>

		<guid isPermaLink="false">http://www.imchris.org/wp/?p=32</guid>
		<description><![CDATA[This fall is a little bit different than most semesters &#8211; no class. I decided that I could fill my time easily enough with research that I didn&#8217;t need any busy work from courses. I&#8217;m currently working on web related &#8230; <a href="http://www.imchris.org/wp/2007/08/22/fall-2007-school-and-stuff/">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
		<wfw:commentRss>http://www.imchris.org/wp/2007/08/22/fall-2007-school-and-stuff/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

