DocumentCode :
628220
Title :
Detecting malicious landing pages in Malware Distribution Networks
Author :
Gang Wang ; Stokes, Jack W. ; Herley, Cormac ; Felstead, David
Author_Institution :
Comput. Sci., UC Santa Barbara, Santa Barbara, CA, USA
fYear :
2013
fDate :
24-27 June 2013
Firstpage :
1
Lastpage :
11
Abstract :
Drive-by download attacks attempt to compromise a victim´s computer through browser vulnerabilities. Often they are launched from Malware Distribution Networks (MDNs) consisting of landing pages to attract traffic, intermediate redirection servers, and exploit servers which attempt the compromise. In this paper, we present a novel approach to discovering the landing pages that lead to drive-by downloads. Starting from partial knowledge of a given collection of MDNs we identify the malicious content on their landing pages using multiclass feature selection. We then query the webpage cache of a commercial search engine to identify landing pages containing the same or similar content. In this way we are able to identify previously unknown landing pages belonging to already identified MDNs, which allows us to expand our understanding of the MDN. We explore using both a rule-based and classifier approach to identifying potentially malicious landing pages. We build both systems and independently verify using a high-interaction honeypot that the newly identified landing pages indeed attempt drive-by downloads. For the rule-based system 57% of the landing pages predicted as malicious are confirmed, and this success rate remains constant in two large trials spaced five months apart. This extends the known footprint of the MDNs studied by 17%. The classifier-based system is less successful, and we explore possible reasons.
Keywords :
Internet; cache storage; invasive software; knowledge based systems; query processing; search engines; telecommunication traffic; MDN; Web page cache; browser vulnerabilities; commercial search engine; drive-by download attacks; high-interaction honeypot; intermediate redirection servers; malicious content identification; malicious landing page detection; malware distribution networks; multiclass feature selection; traffic attraction; Browsers; Crawlers; Feature extraction; IP networks; Malware; Search engines; Servers; Drive-by download; malware distribution network; signature;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Dependable Systems and Networks (DSN), 2013 43rd Annual IEEE/IFIP International Conference on
Conference_Location :
Budapest
ISSN :
1530-0889
Print_ISBN :
978-1-4673-6471-3
Type :
conf
DOI :
10.1109/DSN.2013.6575316
Filename :
6575316
Link To Document :
بازگشت