Adobe to beef up PDF security with Reader sandboxing
- 21 July, 2010 01:03
- Comments
Adobe Systems Inc. today announced that it will harden the next version of its popular Reader PDF viewer, a frequent target of attacks, by adding "sandboxing" technology to the software.
Sandboxing, perhaps best known for its use in Google Inc. 's Chrome browser , isolates processes from one another and the rest of the machine, preventing or hindering malicious code from escaping an application to wreak havoc or infect the computer.
Previously, security experts had said that sandboxing Reader would be a smart move by Adobe as it struggled to lock down the program and prevent vulnerabilities from being exploited by hackers.
According to Brad Arkin, Adobe's director of security and privacy, sandboxing will be added to the next major Windows upgrade to Reader, Version 10, before the end of the year. The company declined to provide a more specific timeline.
"With sandboxing, anyone who encounters a malicious PDF will find that a successful exploit is kept within the sandbox," said Arkin, describing the advantages of the technology, which is also used by Microsoft 's Internet Explorer 7 and IE8, as well as by Office 2010. Although attacks may still succeed, they would require a second exploit, one that allows the attacker to move malware outside the sandbox, to be effective.
The Reader browser plug-in already makes use of IE7's and IE8's Protected Mode -- the name for sandboxing in Microsoft's browser -- as well as Chrome's isolation functionality, but the addition to Reader in general will also protect Firefox users from attack, as well as people who run the stand-alone version of the PDF viewer.
Initially, Reader will sandbox only "write" calls by the program -- blocking attempts by malware to install malicious code on the system -- but a minor release in the future will extend the technology to read-only activities, such as those aimed at pillaging the PC of important information, such as credit card numbers or passwords.
"In the first release, everything that is involved in rendering a PDF has to happen within the sandbox," said Arkin, noting that that includes parsing the PDF document and any associated images, and running JavaScript. The latter has been an especially attractive method of exploiting Reader vulnerabilities.
The technology, which will be switched on by default, will be tagged as Protected Mode, the same term used by Microsoft in IE7 and IE8.
Adobe did more than borrow the label from Microsoft. "Microsoft and Google offered a lot of advice," acknowledged Arkin, who said that Adobe based its technology on techniques described in 2007 by David LeBlanc, a Microsoft secure code expert, and with fellow Microsoft developer Michael Howard, co-author of Writing Secure Code .
Arkin also credited Nicolas Sylvain, a software engineer at Google, and that company's Chrome browser team, with helping Adobe craft Reader's Protected Mode.
Adobe's effort, which began more than a year ago, has been focused on what Arkin called the "broker process," which decides what functions Reader can conduct outside the sandbox, such as writing to disk or launching an attachment or executable from within the software. The broker is limited by preset policies -- which users can modify -- that restrict those kinds of functions, said Arkin.
Although he refused to guarantee that the broker process itself wouldn't be exploitable, Arkin said he was confident that it would be "rock-solid" when Reader 10 shipped, in part because the code for the broker is all new and was written with security in mind.
Last year, Adobe adopted a new development practice called Secure Product Lifecycle (SPLC), an approach similar to Microsoft's much better-known Software Development Lifecycle (SDL). Both involve several security-specific steps that programmers go through to make their software less likely to harbor bugs.
That move and others, including a quarterly security patch schedule, were made in 2009 in reaction to criticism following the company's slow fix for a flaw that was being exploited by attackers earlier that year.
Protected Mode is another aspect of that campaign, said Arkin, adding, "This is a really big change for Reader."
Reader and the associated Acrobat PDF creation program have been bombarded with attacks for the past 18 months, while Reader and Acrobat vulnerability tallies have also climbed dramatically.
Antivirus vendors McAfee and Symantec, for example, have reported surges in attacks exploiting bugs in Reader. Last April, McAfee said that exploits of Reader jumped 65% in the first quarter of 2010 compared with all of 2009. Last week, Danish bug-tracking firm Secunia chimed in, saying that the bulk of a ballooning number of bugs facing Windows users this year could be traced to third-party software like Adobe's.
Adobe will also use Reader's new automated update mechanism to "aggressively" move users from older, more vulnerable versions of the stand-alone program and browser plug-ins to Reader 10 and its sandboxing technology, Arkin said.
"We're going to take some feedback on how it operates in the field [after it's released], but our goal will be to start migrating users as aggressively as possible through the updater," he said.
At an unspecified future date, Adobe will likely prompt users running Reader 8 or Reader 9 to upgrade to the newer edition. "We'll urgently compel them to update," Arkin said.
Adobe has made security-related moves in its other software this year as well. In April, the company announced a partnership with Google that packages its Flash Player with Chrome and updates the media player using Chrome's hands-off update service.
Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.
- Bookmark this page
- Share this article
- Got more on this story? Email CIO
- Follow CIO on twitter
- Google Update - Computerworld
- Browsers Topic Center - Computerworld
- PDF exploits explode, continue climb in 2010 - Computerworld
- Microsoft Update: Latest news, features, reviews, opinions and more - Computerworld
- techniques described in 2007
- Writing Secure Code
- Facing criticism, Adobe rethinks PDF security - Computerworld
- Adobe: We know we're hackers' favorite target - Computerworld
- Third-party software bugs skyrocket in 2010 - Computerworld
- Google's Chrome now silently auto-updates Flash Player - Computerworld
- A buyer’s guide to application lifecycle management (ALM) solutions
- Enterprise Buyers Guide for Application Development Software
- Six tips for choosing a unified threat management (UTM) solution
- Transforming Software Delivery: An IBM Rational Case Study
- Effective Storage Management and Data Protection for Cloud Computing
-
All Systems Down
-
Married to your desk? 5 tips for a better relationship
-
Married to your desk? 5 tips for a better relationship
-
NBN to deliver disability support services to regional Australia
-
Beware of malicious QR codes: Report
-
Best Practices for Energy Efficient Storage Operations Version 1.0
The energy required to support data center IT operations is becoming a central concern worldwide. For some data centers, additional energy supply is simply not available, either due to finite power generation capacity in certain regions or the inability of the power distribution grid to accommodate more lines. Read on. -
Solutions Guide for Data-At-Rest
The purpose of this document is to provide guidance into some of the factors you should consider when evaluating storage security technology and solutions. As with any security project, acquiring technology is not the only step to properly protecting your data. Part of this process should include an evaluation of the current processes and security controls in place, such as physical access controls, environmental controls, and administrative controls. While there is no single set of requirements that applies to all organizations, this Guide can provide some baseline considerations. -
Securing and Managing Your Enterprise: An Integrated Approach
Your organization has a dizzying number of platforms, directories, systems and applications- all requiring your attention and administration. You know you need to manage this complex infrastructure correctly, or your diverse resources will cease to be assets, and instead become a serious drain on administrative time and budget. And even worse, if the management program you deploy isn't comprehensive, unsecured devices can expose your systems to significant security issues. So how you can you integrate and automate fragmented management tasks while addressing a full range of governance, risk and compliance (GRC) issues?
-
MYOB Software for Dummies 6E Australian Edition
-
Windows 7 for Dummies® Dvd+book Bundle
-
Office 2007 for Dummies
-
Office 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Windows 7 for Dummies®
-
Microsoft Office
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Computers for Seniors for Dummies, 2nd Edition









Comments
Post new comment