AUSTIN, Texas, Oct. 12, 2017 -- NSS Labs, Inc., a global leader and trusted source for independent fact-based cybersecurity guidance, today announced the release of its Web Browser Security Comparative Reports. The reports reveal how effective web browsers are at protecting users from socially engineered malware (SEM) and phishing attacks. To minimize exposure to emerging threats, enterprise have begun to limit the use of legacy browsers to internal and legacy applications. This has necessitated the adoption of other more modern browsers, resulting in a dual-browser strategy. For enterprises implementing this strategy, the NSS Labs Web Browser Comparative Reports provide insights regarding which modern browsers offer a secure browsing experience.
Web browsers are the first line of defense against web-based attacks, and according to the Verizon 2017 Data Breach Investigations Report, they are the second most common entry point for ransomware—one of the most common forms of malware plaguing users and enterprises. To measure browser effectiveness, NSS Labs conducted a series of tests focused on block rate, consistency of protection, and early protection against new threats. For 2017, cross-platform tests on desktops and tablets were added to verify security efficacy and consistency across devices. Test results indicate that regardless of platform, browsers are more effective at blocking SEM than phishing attacks.
For many years, the use of social engineering has accounted for the majority of cyberattacks targeting both consumers and enterprises. SEM attacks use a dynamic combination of social media, hijacked email accounts, false notification of computer problems, and other deceptions to encourage users to download malware. Industry experts estimate that 97% of malware is trying to trick a user through some type of social engineering scheme, and 93% of phishing emails are ransomware.
Phishing attacks are forms of fraud that gain the trust of users by masquerading as reputable entities to steal login credentials or sensitive account information. Examples of common approaches include an email designed to look like the sender is a credible organization or a disguise that makes the email appear as if it is from someone trusted inside a company, such as the IT department. In the last year alone, more than 1.2 million phishing attacks were reported—a 65% increase over the previous year.
To protect against malware, leading browser vendors provide cloud-based reputation services, which scour the Internet for malicious websites and then categorize content accordingly, either by adding it to blacklists or whitelists, or by assigning it a score. The time taken for these cloud-based reputation service updates are an integral part of the test.
“Web browsers are the primary interface used to consume information and are among the most common entry point for attackers,” said Jason Brvenik, Chief Technology Officer at NSS Labs. “Enterprises are increasingly adopting a bifurcated browser strategy to reduce exposure to emerging threats. Our test findings provide valuable insights that empower informed decision making and help both enterprises and users minimize risk for a secure browser experience.”
Browsers Tested:
Google Chrome: Version 60.0.3112.113
Microsoft Edge: Version 40.15063.0.0
Mozilla Firefox: Version 55.0.3
Key findings include:
• SEM testing results showed high block rates, zero-hour protection, and time-to-block capabilities
- SEM blocking rate ranged from 70.1% to 99.5%
- Zero-hour protection ranged from 53.8% to 99.8%
- One browser showed a high consistency of protection through the test
• Phishing testing results showed protection capabilities improved over time
- Phishing block rates ranged from 61.1% to 92.3%
- Zero-hour protection ranged from 50.7% to 81.8%
- Throughout the test, consistency of protection varied for all browsers
For more information on the NSS Labs Web Browser Security Comparative Reports and the test methodologies used, or to purchase reports, click here.
Additional Resources:
- Purchase the NSS Labs Web Browser Security Comparative Reports for Protection Against Socially Engineered Malware and Protection Against Phishing Attacks.
- View the SEM Test Methodology and Phishing Test Methodology
- Learn more about NSS Labs’ Security Product Testing
- Learn more about NSS Labs’ Test Policies
- Learn more about NSS Labs’ CAWS Continuous Security Validation Platform
• Follow NSS Labs on Twitter
• Follow NSS Labs on LinkedIn
• Browse the NSS Labs research library
About NSS Labs, Inc.
NSS Labs, Inc. is recognized globally as the most trusted source for independent, fact-based cybersecurity guidance. Our mission is to advance transparency and accountability within the cybersecurity industry. We empower enterprises by providing them with timely, relevant information on which to base their decisions. Our unmatched foundation in security testing, along with our extensive research and global threat analysis capabilities, provide the basis for our CAWS Continuous Security Validation Platform. CAWS measures the ongoing effectiveness of security controls, providing a real-time score card to help business leaders substantiate their security investments. Businesses can also leverage the threat data delivered by CAWS to strengthen their cyber risk posture and mitigate threats to their operating systems and applications. CISOs, Chief Security Architects, SOC and Threat Analysts, and information security professionals from many of the world's largest and most demanding enterprises rely on trusted insights from NSS Labs. For more information, visit www.nsslabs.com.
Contact:
Tom Resau
W2 Communications
Phone: +1 703-877-8103
[email protected]


Nvidia Nears $20 Billion OpenAI Investment as AI Funding Race Intensifies
AMD Shares Slide Despite Earnings Beat as Cautious Revenue Outlook Weighs on Stock
OpenAI Expands Enterprise AI Strategy With Major Hiring Push Ahead of New Business Offering
TrumpRx Website Launches to Offer Discounted Prescription Drugs for Cash-Paying Americans
Sony Q3 Profit Jumps on Gaming and Image Sensors, Full-Year Outlook Raised
SpaceX Pushes for Early Stock Index Inclusion Ahead of Potential Record-Breaking IPO
Nvidia, ByteDance, and the U.S.-China AI Chip Standoff Over H200 Exports
Amazon Stock Rebounds After Earnings as $200B Capex Plan Sparks AI Spending Debate
Rio Tinto Shares Hit Record High After Ending Glencore Merger Talks
Toyota’s Surprise CEO Change Signals Strategic Shift Amid Global Auto Turmoil
SpaceX Prioritizes Moon Mission Before Mars as Starship Development Accelerates
SoftBank Shares Slide After Arm Earnings Miss Fuels Tech Stock Sell-Off
Ford and Geely Explore Strategic Manufacturing Partnership in Europe
Baidu Approves $5 Billion Share Buyback and Plans First-Ever Dividend in 2026
FDA Targets Hims & Hers Over $49 Weight-Loss Pill, Raising Legal and Safety Concerns
CK Hutchison Launches Arbitration After Panama Court Revokes Canal Port Licences
Tencent Shares Slide After WeChat Restricts YuanBao AI Promotional Links 



