Detection of shellcodes in drive-by attacks using kernel machines

被引:0
|
作者
Cherukuri, Manoj [1 ]
Mukkamala, Srinivas [2 ]
Shin, Dongwan [1 ]
机构
[1] New Mexico Inst Min & Technol, Comp Sci, Inst Complex Addit & Syst Anal, Socorro, NM 87801 USA
[2] New Mexico Inst Min & Technol, CAaNES LLC, Inst Complex Addit & Syst Anal, Socorro, NM 87801 USA
关键词
D O I
10.1007/s11416-013-0195-2
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In this paper, we propose a light-weight framework using kernel machines for the detection of shellcodes used in drive-by download attacks. As the shellcodes are passed in webpages as JavaScript strings, we studied the effectiveness of the proposed approach on about 9850 shellcodes and 10000 JavaScript strings collected from the wild. Our analysis shows that the trained SVMs (Support Vector Machines) classified with an accuracy of over 99%. Our evaluation of the trained SVM models with different proportions of training datasets proved to perform consistently with an average accuracy of 99.51% and the proposed static approach proved to be effective against detecting even the polymorphic shellcode variants. The performance of our approach was compared to an emulation based approach and observed that our approach performed with slightly better accuracies by consuming about 33% of the time consumed by the emulation based approach.
引用
收藏
页码:189 / 203
页数:15
相关论文
共 50 条
  • [31] Introduction and application of a drive-by damage detection methodology for bridges using variational mode decomposition
    Shandiz, Shahrooz Khalkhali
    Khezrzadeh, Hamed
    Azam, Saeed Eftekhar
    FRATTURA ED INTEGRITA STRUTTURALE-FRACTURE AND STRUCTURAL INTEGRITY, 2024, (70): : 24 - 54
  • [32] Application of empirical mode decomposition to drive-by bridge damage detection
    OBrien, Eugene J.
    Malekjafarian, Abdollah
    Gonzalez, Arturo
    EUROPEAN JOURNAL OF MECHANICS A-SOLIDS, 2017, 61 : 151 - 163
  • [33] A Feasibility Study of the Drive-By Method for Damage Detection in Railway Bridges
    Carnevale, Marco
    Collina, Andrea
    Peirlinck, Tim
    APPLIED SCIENCES-BASEL, 2019, 9 (01):
  • [34] The defense in-depth approach to the protection for browsing users against drive-by cache attacks
    Lai, Yeu-Pong
    Wu, Wei-Feng
    SECURITY AND COMMUNICATION NETWORKS, 2015, 8 (07) : 1422 - 1430
  • [35] Wireless reading of energy meters using drive-by method
    Business Unit Energy Metering, Hydrometer GmbH, Ansbach, Germany
    Euroheat Power Engl. Ed., 2006, 3 (46-48):
  • [36] Music Emotion Detection Using Hierarchical Sparse Kernel Machines
    Chin, Yu-Hao
    Lin, Chang-Hong
    Siahaan, Ernestasia
    Wang, Jia-Ching
    SCIENTIFIC WORLD JOURNAL, 2014,
  • [37] Drive-by damage detection with a TSD and time-shifted curvature
    Jennifer C. Keenahan
    Eugene J. OBrien
    Journal of Civil Structural Health Monitoring, 2018, 8 : 383 - 394
  • [38] Drive-by damage detection with a TSD and time-shifted curvature
    Keenahan, Jennifer C.
    OBrien, Eugene J.
    JOURNAL OF CIVIL STRUCTURAL HEALTH MONITORING, 2018, 8 (03) : 383 - 394
  • [39] Real-time drive-by bridge damage detection using deep auto-encoder
    Li, Zhenkun
    Lin, Weiwei
    Zhang, Youqi
    STRUCTURES, 2023, 47 : 1167 - 1181
  • [40] Drive-by damage detection methodology for high-speed railway bridges using sparse autoencoders
    de Souza, Edson Florentino
    Braganca, Cassio
    Ribeiro, Diogo
    Bittencourt, Tulio Nogueira
    Carvalho, Hermes
    RAILWAY ENGINEERING SCIENCE, 2024,