节点文献
基于HTTP会话过程跟踪的网页挂马攻击检测方法
Detection of Drive-By Download Attacks with HTTP Session Tracking of Web Pages
【摘要】 目前对网页挂马攻击的检测手段主要有网页代码特征匹配与高交互虚拟蜜罐技术,前者难以对抗代码加密与混淆变形技术,后者资源消耗较大难以在客户端直接部署.提出一种新型的基于HTTP会话过程跟踪的网页挂马攻击检测方法.首先跟踪用户访问正常网页与挂马网页的HTTP会话过程,并分析比较两者统计特征,包括会话链接树特征与所引用域名的特征等.进一步,基于会话过程统计特征及采用有监督的机器学习技术,建立了能有效识别挂马网页会话过程的分类模型.实验证明,该模型能够达到91.7%的网页挂马攻击检测率以及0.1%误检率.
【Abstract】 There were mainly two mechanisms to defend against drive-by download attacks, including signature matching with HTML codes and high-interaction virtual web-honeypots. The former might not be able to identify malicious HTML codes with encryption or obfuscation, and the latter is heavyweight and difficult to satisfy real-time deployment for clients. In this paper, we present a novel approach for detecting of drive-by download attacks. This approach characterizes drive-by download attacks based on HTTP session tracking, mainly including session link tree based and domain based features. Several statistical methods are used to analyze and compare the related features of normal and malicious Web pages. With these features and the techniques of supervised machine learning, we have built a classification model to identify malicious Web pages effectively. Experiment results show that we are able to successfully detect 91.7% of the malicious Web pages with a very low false positive rate of 0.1%.
【Key words】 drive-by download attack; malicious Web page; HTTP session tracking; machine learning; classification;
- 【文献出处】 计算机研究与发展 ,Journal of Computer Research and Development , 编辑部邮箱 ,2012年S2期
- 【分类号】TP393.08
- 【被引频次】1
- 【下载频次】277