节点文献

基于HTTP会话过程跟踪的网页挂马攻击检测方法

Detection of Drive-By Download Attacks with HTTP Session Tracking of Web Pages

  • 推荐 CAJ下载
  • PDF下载
  • 不支持迅雷等下载工具,请取消加速工具后下载。

【作者】 王涛余顺争谢逸

【Author】 Wang Tao1, Yu Shunzheng2, and Xie Yi2 1(School of Automation, Guangdong University of Technology, Guangzhou 510006) 2(School of Information Science and Technology, Sun Yat-sen University, Guangzhou 510006)

【机构】 广东工业大学自动化学院中山大学信息科学技术学院

【摘要】 目前对网页挂马攻击的检测手段主要有网页代码特征匹配与高交互虚拟蜜罐技术,前者难以对抗代码加密与混淆变形技术,后者资源消耗较大难以在客户端直接部署.提出一种新型的基于HTTP会话过程跟踪的网页挂马攻击检测方法.首先跟踪用户访问正常网页与挂马网页的HTTP会话过程,并分析比较两者统计特征,包括会话链接树特征与所引用域名的特征等.进一步,基于会话过程统计特征及采用有监督的机器学习技术,建立了能有效识别挂马网页会话过程的分类模型.实验证明,该模型能够达到91.7%的网页挂马攻击检测率以及0.1%误检率.

【Abstract】 There were mainly two mechanisms to defend against drive-by download attacks, including signature matching with HTML codes and high-interaction virtual web-honeypots. The former might not be able to identify malicious HTML codes with encryption or obfuscation, and the latter is heavyweight and difficult to satisfy real-time deployment for clients. In this paper, we present a novel approach for detecting of drive-by download attacks. This approach characterizes drive-by download attacks based on HTTP session tracking, mainly including session link tree based and domain based features. Several statistical methods are used to analyze and compare the related features of normal and malicious Web pages. With these features and the techniques of supervised machine learning, we have built a classification model to identify malicious Web pages effectively. Experiment results show that we are able to successfully detect 91.7% of the malicious Web pages with a very low false positive rate of 0.1%.

【基金】 国家“八六三”高技术研究发展计划基金项目(2007AA01Z449);国家自然科学基金项目(60970146);广东省高校优秀青年创新人才培养计划资助项目(LYM11057);广东省自然科学基金博士启动项目(S2012040006666)
  • 【文献出处】 计算机研究与发展 ,Journal of Computer Research and Development , 编辑部邮箱 ,2012年S2期
  • 【分类号】TP393.08
  • 【被引频次】1
  • 【下载频次】277
节点文献中: 

本文链接的文献网络图示:

本文的引文网络