• DocumentCode
    628220
  • Title

    Detecting malicious landing pages in Malware Distribution Networks

  • Author

    Gang Wang ; Stokes, Jack W. ; Herley, Cormac ; Felstead, David

  • Author_Institution
    Comput. Sci., UC Santa Barbara, Santa Barbara, CA, USA
  • fYear
    2013
  • fDate
    24-27 June 2013
  • Firstpage
    1
  • Lastpage
    11
  • Abstract
    Drive-by download attacks attempt to compromise a victim´s computer through browser vulnerabilities. Often they are launched from Malware Distribution Networks (MDNs) consisting of landing pages to attract traffic, intermediate redirection servers, and exploit servers which attempt the compromise. In this paper, we present a novel approach to discovering the landing pages that lead to drive-by downloads. Starting from partial knowledge of a given collection of MDNs we identify the malicious content on their landing pages using multiclass feature selection. We then query the webpage cache of a commercial search engine to identify landing pages containing the same or similar content. In this way we are able to identify previously unknown landing pages belonging to already identified MDNs, which allows us to expand our understanding of the MDN. We explore using both a rule-based and classifier approach to identifying potentially malicious landing pages. We build both systems and independently verify using a high-interaction honeypot that the newly identified landing pages indeed attempt drive-by downloads. For the rule-based system 57% of the landing pages predicted as malicious are confirmed, and this success rate remains constant in two large trials spaced five months apart. This extends the known footprint of the MDNs studied by 17%. The classifier-based system is less successful, and we explore possible reasons.
  • Keywords
    Internet; cache storage; invasive software; knowledge based systems; query processing; search engines; telecommunication traffic; MDN; Web page cache; browser vulnerabilities; commercial search engine; drive-by download attacks; high-interaction honeypot; intermediate redirection servers; malicious content identification; malicious landing page detection; malware distribution networks; multiclass feature selection; traffic attraction; Browsers; Crawlers; Feature extraction; IP networks; Malware; Search engines; Servers; Drive-by download; malware distribution network; signature;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Dependable Systems and Networks (DSN), 2013 43rd Annual IEEE/IFIP International Conference on
  • Conference_Location
    Budapest
  • ISSN
    1530-0889
  • Print_ISBN
    978-1-4673-6471-3
  • Type

    conf

  • DOI
    10.1109/DSN.2013.6575316
  • Filename
    6575316