• DocumentCode
    1283978
  • Title

    BrowserGuard: A Behavior-Based Solution to Drive-by-Download Attacks

  • Author

    Hsu, Fu-Hau ; Tso, Chang-Kuo ; Yeh, Yi-Chun ; Wang, Wei-Jen ; Chen, Li-Han

  • Author_Institution
    Nat. Central Univ., Jhongli, Taiwan
  • Volume
    29
  • Issue
    7
  • fYear
    2011
  • fDate
    8/1/2011 12:00:00 AM
  • Firstpage
    1461
  • Lastpage
    1468
  • Abstract
    Along with an increasing user population of various web applications, browser-based drive-by-download attacks soon become one of the most common security threats to the cyber community. A user using a vulnerable browser or browser plug-ins may become a victim of a drive-by-download attack right after visiting a vicious web site. The end result of such attacks is that an attacker can download and execute any code on the victim´s host. This paper proposes a runtime, behavior-based solution, BrowserGuard, to protect a browser against drive-by-download attacks. BrowserGuard records the download scenario of every file that is loaded into a host through a browser. Then based on the download scenario, BrowserGuard blocks the execution of any file that is loaded into a host without the consent of a browser user. Due to its behavior-based detection nature, BrowserGuard does not need to analyze the source file of any web page or the run-time states of any script code, such as Javascript. BrowserGuard also does not need to maintain any exploit code samples and does not need to query the reputation value of any web site. We utilize the standard BHO mechanism of Windows to implement BrowserGuard on IE 7.0. Experimental results show that BrowserGuard has low performance overhead (less than 2.5%) and no false positives and false negatives for the web pages used in our experiments.
  • Keywords
    Web sites; security of data; BrowserGuard; Javascript; cyber community; security threats; vulnerable browser; web applications; web page; web site; Browsers; Internet; Kernel; Malware; Servers; Web pages; Web browser; drive-by-download attack; heap spray; intrusion detection; malware; system security;
  • fLanguage
    English
  • Journal_Title
    Selected Areas in Communications, IEEE Journal on
  • Publisher
    ieee
  • ISSN
    0733-8716
  • Type

    jour

  • DOI
    10.1109/JSAC.2011.110811
  • Filename
    5963164