BTemplates.com

Powered by Blogger.

Pageviews past week

Quantum mechanics

Auto News

artificial intelligence

About Me

Recommend us on Google!

Information Technology

Popular Posts

Showing posts with label Internet Explorer. Show all posts
Showing posts with label Internet Explorer. Show all posts

Wednesday, May 19, 2010

Software that Learns by Watching


KarDo learns how to perform common IT support tests by observing what the experts do.

Overworked and much in demand, IT support staff can't be in two places at once. But software designed to watch and learn as they carry out common tasks could soon help--by automatically performing the same jobs across different computers.
Me
Task manager: A screenshot 
shows KarDo performing administrative jobs 
via a graphical interface.
Credit: KarDo


The new software system, called KarDo, was developed by researchers at MIT. It can automatically configure an e-mail account, install a virus scanner, or set up access to a virtual private network, says MIT's Dina Katabi, an associate professor at MIT.

Crucially, the software just needs to watch an administrator perform this task once before being able to carry out the same job on computers running different software. Businesses spend billions of dollars each year on simple and repetitive IT tasks, according to reports from the analyst groups Forrester and Gartner. KarDo could reduce these costs by as much as 20 percent, Katabi says.

In some respects, KarDo resembles software that can be used to record macros--a set sequence of user actions on a computer. But KarDo attempts to learn the goal of each action in the sequence so it can be applied more generally later, says MIT post-graduate Hariharan Rahul, who codeveloped the system.

When IT staff want KarDo to learn a new task, they press a "start" button beforehand and a "stop" button afterwards. During a "learning phase," KarDo will attempt to map each of the actions performed in the graphical user interface, such as clicking on particular icons or buttons, with system-level actions, such as starting or closing a program, or opening a Web page. This allows a task to be applied across machines running different software, says Katabi. "I can go to my desktop, click on the Internet Explorer icon, go to a website, and then click on a particular link to download a file," she says. The same actions could then be applied by KarDo on a machine running a different Web browser like FireFox or Chrome. KarDo compares actions performed during the learning phase with a database of other tasks.

KarDo is able to reliably infer how to reproduce each of the subtasks after watching it being performed just once, says Rahul. For example, after watching an e-mail account being set up using Microsoft Outlook, it can do the same on other computers running different e-mail software. KarDo has been tested on hundreds of combinations of real tasks by IT staff at MIT and was found to get tasks right 82 percent of the time. When KarDo doesn't perform a task correctly, the results aren't serious, Katabi says.

The ultimate goal is for KarDo to intervene completely automatically, although this has not yet been tested. The idea is that when a user sends a request to the IT department , KarDo would perform the task automatically.

This sort of "programming by demonstration" is not a new idea, says Stephen Muggleton, an expert in machine learning at Imperial College London. But the approach has remained very much a research curiosity, he says. "An obvious concern from a user point of view will be the accuracy of the learned model," says Muggleton. Normally it takes relatively large amounts of data to generate error-free machine learning models, he notes.

"There's a great deal of promise in learning procedures and plans by watching," says Eric Horvitz of Microsoft Research in Redmond, WA. However, in general, this is very challenging to pull off. It is usually hard to do anything useful without constraining the nature of the task, says Horvitz.

KarDo was announced last week as the winner of the Web/IT track of MIT's $100K Entrepreneur Competition.

Wednesday, July 11, 2007

IE or Firefox: Who's to blame for newest browser zero-day?


Both browsers must be present for the vulnerability to be exploited


Confusion reigns around a zero-day browser vulnerability made public yesterday, with four researchers or organizations squaring off over whether Microsoft Corp.'s Internet Explorer or Mozilla Corp.'s Firefox is at fault.

Windows Internet ExplorerImage via Wikipedia

According to researcher Thor Larholm, the zero-day bug is in IE. "There is an input validation flaw in Internet Explorer that allows you to specify arbitrary arguments to the process responsible for handling URL protocols," Larholm said on his blog. That becomes a problem on PCs that also have Firefox 2.0.0.2 or later. Firefox, said Larholm, registers a URL protocol handler called FirefoxURL, designed to let Web pages force a Firefox launch if the "firefoxurl://" uniform resource identifier (URI) is used.

IE doesn't perform any input validation on the protocol, which means an attacker can use IE to pass malicious a script -- JavaScript code, say -- to the browser. The result: a PC hijack. Symantec Corp.'s analysts backed up Larholm's conclusion.

Larholm also said that the IE bug is similar to the input validation vulnerability in Safari 3.0 that he spotted the same day Apple Inc. released the Windows browser in beta.

Others, however, blamed Firefox for the vulnerability. In an e-mail, Thomas Kristensen, chief technology officer at Danish bug tracker Secunia, did not dispute Larholm's findings but did have a problem with his conclusion. "This is in fact not an IE issue, it is a Firefox issue," said Kristensen. "The way in which the URL handler was registered by Firefox causes any parameter to be passed from IE (or another application) to Firefox when firefoxurl:// is activated." FrSIRT, a French company that also monitors vulnerabilities, agreed with Secunia.

"Registering a URI handler must be done with care," said Kristensen, "since Windows does not have any proper way of knowing what kind of input potentially could be dangerous for an application. Improper usage of URI handlers and parameters supplied via URIs has historically caused problems."

No matter which browser is to blame, it takes two to tango or, in this case, both must be present to let an attacker inject malicious code. Only PCs with Firefox 2.0.0.2 or later (Firefox's most recent update was to 2.0.04) are vulnerable, and then only if the victim uses IE to surf to a malicious site sporting the firefoxurl:// protocol.

Secunia rated the threat as "highly critical," its second-highest ranking; FrSIRT, meanwhile, pegged it as "critical," its top-most warning. Several proof-of-concept exploits have been posted to security mailing lists or Web sites, including one by Larholm and another by a researcher named Billy Rios, who goes by the initials BK.

Mozilla FirefoxImage via Wikipedia

No fixes -- for either Firefox or IE -- are available, although in a comment posted last month to a security message forum, Dan Veditz, a Mozilla developer, said the team is preparing a patch. "[We are] working on protecting users from this on our end for a future security update," said Veditz. Nonetheless, Veditz, like Larholm and Symantec, said IE should shoulder responsibility for the zero-day vulnerability.

"I do think IE should escape quotes in URLs (RFC 1738 considers them an 'unsafe' character in URLs), but the Firefox team has been looking into back-stop protection in our app since we saw Thor Larholm's Safari 0-day post," Veditz wrote.

Source : Computer World



Reblog this post [with Zemanta]