“CAMP bridges the gap between blacklists and whitelists by augmenting both approaches with a reputation system that is applied to unknown content,” the researchers wrote in the paper, adding: “One of CAMP’s important properties is to minimize the impact on user privacy while still providing protection.”
Google’s own real-world test–deploying the system to 200 million Chrome users over six months–found that CAMP could detect 98.6 percent of malware flagged by a virtual-machine-based analysis platform.
In many ways, CAMP is an answer to Microsoft’s SmartScreen, a technology that Microsoft built into its Internet Explorer and the latest version of its operating system, Windows 8.
The CAMP service renders a reputation–benign, malicious or unknown–for a file based on the information provided by the client and reputation data measure during certain time windows, including daily, weekly and quarterly measurements. Information about the download URL, the Internet address of the download server, any referrer information, the size and hash value of the download and any certificates used to sign the file are sent to Google to calculate a reputation score.
URL classification services–such as McAfee’s SiteAdvisor, Symantec’s Safe Web, and Google’s own Safe Browsing–fared eve
n worse, only detecting at most 11 percent of the URLs from which malicious files were downloaded.
The Google researchers who authored the paper–including Moheeb Abu Rajab and Niels Provos–decided to focus on executables downloaded by the user, not on malicious files that attempted to exploit a user’s system.