Identification of Malicious Web Pages Through Analysis of Underlying DNS and Web Server Relationships

被引:0
|
作者
Seifert, Christian [1 ]
Welch, Ian [1 ]
Komisarczuk, Peter [1 ]
Aval, Chiraag Uday [2 ]
Endicott-Popovsky, Barbara [2 ]
机构
[1] Victoria Univ Wellington, POB 600, Wellington 6140, New Zealand
[2] Univ Washington, Seattle, WA 98105 USA
关键词
Security; Client Honeypots; Drive-by-downloads; Intrusion Detection;
D O I
暂无
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Malicious web pages that launch drive-by-download attacks on web browsers have increasingly become a problem in recent years. High-interaction client honeypots are security devices that can detect these malicious web pages on a network. However, high-interaction client honeypots are both resource-intensive and unable to handle the increasing array of vulnerable clients. This paper presents a novel classification method for detecting malicious web pages that involves inspecting the underlying server relationships. Because of the unique structure of malicious front-end web pages and centralized exploit servers, merely counting the number of domain name extensions and Domain Name System (DNS) servers used to resolve the host names of all web servers involved in rendering a page is sufficient to determine whether a web page is malicious or benign, independent of the vulnerable web browser targeted by these pages. Combining high-interaction client honeypots and this new classification method into a hybrid system leads to performance improvements.
引用
收藏
页码:910 / +
页数:2
相关论文
共 50 条
  • [41] Identification of Important Images for Understanding Web Pages
    Zhong, Ying
    Matsubara, Masaki
    Morishima, Atsuyuki
    [J]. 2018 IEEE INTERNATIONAL CONFERENCE ON BIG DATA (BIG DATA), 2018, : 3568 - 3574
  • [42] Motivations underlying the creation of personal Web pages: An exploratory study
    Zinkhan, GM
    Conchar, M
    Gupta, A
    Geissler, G
    [J]. ADVANCES IN CONSUMER RESEARCH, VOL 26, 1999, 26 : 69 - 74
  • [43] ENiD: An Encrypted Web Pages Traffic Identification Based on Web Visiting Behavior
    Ge, Mengmeng
    Yu, Xiangzhan
    Sachidananda, Vinay Mysore
    Liu, Shangqing
    Liu, Likun
    [J]. 2022 IEEE INTERNATIONAL CONFERENCE ON DATA MINING WORKSHOPS, ICDMW, 2022, : 593 - 601
  • [44] Anonymous Web Browsing through Predicted Pages
    Yu, Shui
    Thapngam, Theerasak
    Tse, Hou In
    Wang, Jilong
    [J]. 2010 IEEE GLOBECOM WORKSHOPS, 2010, : 1581 - 1585
  • [45] Librarians' personal Web pages: An analysis
    Haines, A
    [J]. COLLEGE & RESEARCH LIBRARIES, 1999, 60 (06): : 543 - 550
  • [46] Structural analysis and grouping of Web pages
    Kojima, Shuichi
    Takasu, Atsuhiro
    Adachi, Jun
    [J]. NII Journal, 2002, (04): : 23 - 35
  • [47] 用Active Server Pages创建交互Web应用
    罗娟
    朱秋萍
    [J]. 计算机工程与应用, 1999, (08) : 94 - 96
  • [48] Web survey design with active server pages: A new research method
    Liu, C
    Armstrong, G
    Lee, D
    Lu, J
    [J]. CHALLENGES OF INFORMATION TECHNOLOGY MANAGEMENT IN THE 21ST CENTURY, 2000, : 1188 - 1189
  • [49] POSTER: Detecting Malicious Web Pages based on Structural Similarity of Redirection Chains
    Shibahara, Toshiki
    Yagi, Takeshi
    Akiyama, Mitsuaki
    Takata, Yuta
    Yada, Takeshi
    [J]. CCS'15: PROCEEDINGS OF THE 22ND ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2015, : 1671 - 1673
  • [50] Web services & Java']Java server pages - Building distributed applications
    Kanalakis, JM
    [J]. DR DOBBS JOURNAL, 2002, 27 (01): : 28 - +