The Malware Scanner extension analyzes the pages and links discovered by IBM Security AppScan to determine whether they appear to be malicious or otherwise unwanted. System requirementsSecurity AppScan v7.8 or later BackgroundMalicious software (known as malware) is a big and rapidly growing problem. Today, it is primarily delivered through Web applications, either through malicious content that exploits client-side vulnerabilities (such as security holes in the browser, image rendering services, or Microsoft? ActiveX? controls) or by "socially engineering" (tricking) users into downloading software that contains hidden, malicious code. To make things worse, 70% or more of malware is served or linked from legitimate sites. These applications have been compromised through 0-day vulnerabilities, user-posted content and links, internal attackers, or through many other possible ways and are now attacking computers of those who browse them. This means that even security-conscious users can easily be attacked and compromised, and it also means that all Web site owners must ensure that their applications are not inadvertently serving or linking to malware. Failing to do so may lead to brand damage, loss of customer trust, legal problems, and more. The Malware Scanner helps you verify that your application is not hosting or linking to malware. The extension couples the deep-scanning capabilities of IBM Security AppScan with ISS X-Force technology that is used to identify malicious content and links. What it doesThe Malware Scanner checks these conditions:
How it worksThe Malware Scanner works in two phases:
When something needs to be brought to your attention, a security issue is created in Security AppScan so that you can benefit from the strength of Security AppScan results management capabilities, such as creating reports, saving and loading scans, and so forth. How to run the scannerAfter installing the Malware Scanner extension, a new Scan for Malware item will appear on the toolbar, as Figure 1 shows. Figure 1. Item added to the toolbar![]() After exploring an application, just click the Scan for Malware button, and a dialog box will appear. Note: http://demo./default.aspx?content=../malware/malware.htm This demo site does not actually serve malicious content, but rather a file called Eicar, which is an antivirus test file and causes no harm.
All configuration changes will persist for future scans, as well. Figure 2. Configuration options![]() Run the scan simply by clicking the Play button. The scanner analyzes the content and links and displays a log of actions during the scan (see Figure 3). You can click the Pause icon to stop the scan at any time and then click it again to resume when you are ready. Figure 3. Screen output of log actions and scan progress indicator![]() All problems found during the scan are reported in Security AppScan in order of severity, along with detailed Advisory, Fix Recommendation, and Issue Information tabs. Figure 4. AppScan report![]() Recommendations and known issues
Installation
SupportPlease post any questions, feedback, or other comments to the Security AppScan Forum. Download
ResourcesLearn
Get products and technologies
Discuss
|
|