• DocumentCode
    230789
  • Title

    Detection of plugin misuse drive-by download attacks using kernel machines

  • Author

    Cherukuri, Manoj ; Mukkamala, Srinivas ; Dongwan Shin

  • Author_Institution
    Inst. for Complex Additive & Syst. Anal., New Mexico Inst. of Min. & Technol., Socorro, NM, USA
  • fYear
    2014
  • fDate
    22-25 Oct. 2014
  • Firstpage
    546
  • Lastpage
    553
  • Abstract
    Malware distribution using drive-by download attacks has become the most prominent threat for organizations and individuals. Compromised web services and web applications hosted on the cloud act as the delivery medium for the exploits. The exploits included often target the vulnerabilities within the plugins of the web browsers. Implementing security controls to counter the exploits within the browsers for ensuring end point security has become a challenge. In this paper, a set of features is proposed and is extracted by monitoring the communications between the browser and the plugins during the rendering of webpages. The Support Vector Machines are trained using the defined features and the performance of the trained classifier is evaluated using a dataset with both malicious and benign use cases of the plugins. The dataset included 10,239 malicious use cases and 37,369 benign use cases. To compensate the imbalance in the distribution of the dataset, experiments were performed using weighted costs and oversampling. Our analysis shows that the Support Vector Machines trained by using the proposed set of features classified with an average accuracy of about 99.4%. On integrating the proposed approach as an inline defense, an average performance overhead of 5.14% was observed.
  • Keywords
    invasive software; online front-ends; support vector machines; Web browser; drive-by download attack; kernel machine; malware distribution; plugin detection; support vector machine; Analytical models; Browsers; Monitoring; Security; Web services; drive-by download; plugin exploits; web malware;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2014 International Conference on
  • Conference_Location
    Miami, FL
  • Type

    conf

  • Filename
    7014611