• DocumentCode
    139226
  • Title

    Browser JS Guard: Detects and defends against Malicious JavaScript injection based drive by download attacks

  • Author

    Kishore, K. Ravi ; Mallesh, M. ; Jyostna, G. ; Eswari, P.R.L. ; Sarma, Samavedam Satyanadha

  • Author_Institution
    Centre for Dev. of Adv. Comput., Hyderabad, India
  • fYear
    2014
  • fDate
    17-19 Feb. 2014
  • Firstpage
    92
  • Lastpage
    100
  • Abstract
    In the recent times, most of the systems connected to Internet are getting infected with the malware and some of these systems are becoming zombies for the attacker. When user knowingly or unknowingly visits a malware website, his system gets infected. Attackers do this by exploiting the vulnerabilities in the web browser and acquire control over the underlying operating system. Once attacker compromises the users web browser, he can instruct the browser to visit the attackers website by using number of redirections. During the process, users web browser downloads the malware without the intervention of the user. Once the malware is downloaded, it would be placed in the file system and responds as per the instructions of the attacker. These types of attacks are known as Drive by Download attacks. Now-a-days, Drive by Download is the major channel for delivering the Malware. In this paper, Browser JS Guard an extension to the browser is presented for detecting and defending against Drive by Download attacks via HTML tags and JavaScript.
  • Keywords
    Java; Web sites; authoring languages; invasive software; online front-ends; operating systems (computers); security of data; HTML tags; Internet; browser JS guard; download attacks; drive by download attacks; file system; malicious JavaScript injection; malware Web site; operating system; user Web browser; Browsers; HTML; Malware; Monitoring; Web pages; Web servers; DOM Change Methods; Drive by Download Attacks; HTML tags; JavaScript Functions; Malware; Web Browser; Web Browser Extensions;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Applications of Digital Information and Web Technologies (ICADIWT), 2014 Fifth International Conference on the
  • Conference_Location
    Bangalore
  • Print_ISBN
    978-1-4799-2258-1
  • Type

    conf

  • DOI
    10.1109/ICADIWT.2014.6814705
  • Filename
    6814705