首页> 外文会议>IEEE 35th Annual IEEE International Conference on Computer Communications >Hunting for invisibility: Characterizing and detecting malicious web infrastructures through server visibility analysis
【24h】

Hunting for invisibility: Characterizing and detecting malicious web infrastructures through server visibility analysis

机译:寻找不可见性:通过服务器可见性分析来表征和检测恶意Web基础结构

获取原文
获取原文并翻译 | 示例

摘要

Nowadays, cyber criminals often build web infrastructures rather than a single server to conduct their malicious activities. In order to continue their malevolent activities without being detected, cyber criminals make efforts to conceal the core servers (e.g., C&C servers, exploit servers, and drop-zone servers) in the malicious web infrastructure. Such deliberate invisibility of those concealed malicious servers, however, makes them particularly distinguishable from benign web servers that are usually promoted to be public. In this paper, we conduct the first large-scale measurement study to investigate the visibility of both malicious and benign servers. From our intensive analysis of over 100,000 benign servers, 45,000 malicious servers and 40,000 redirections, we identify a set of distinct features of malicious web infrastructures from their locations, structures, roles, and relationships perspectives, and propose a lightweight yet effective detection system called VisHunter. VisHunter identifies malicious redirections from visible servers to invisible servers at the entryway of malicious web infrastructures. We evaluate VisHunter on both online public data and large-scale enterprise network traffic, and demonstrate that VisHunter can achieve an average 96.2% detection rate with only 0.9% false positive rate on the real enterprise network traffic.
机译:如今,网络犯罪分子经常建立Web基础结构,而不是单个服务器来进行恶意活动。为了不被发现继续进行其恶意活动,网络罪犯会努力隐藏恶意Web基础结构中的核心服务器(例如,C&C服务器,漏洞利用服务器和拖放区服务器)。但是,这些隐蔽的恶意服务器的这种故意的隐身性使得它们与通常被提升为公开的良性Web服务器特别有区别。在本文中,我们进行了首次大规模测量研究,以调查恶意和良性服务器的可见性。通过对100,000多个良性服务器,45,000恶意服务器和40,000重定向的深入分析,我们从恶意Web基础结构的位置,结构,角色和关系的角度确定了一组恶意功能,并提出了一个轻巧而有效的检测系统VisHunter 。 VisHunter在恶意Web基础结构的入口处识别从可见服务器到不可见服务器的恶意重定向。我们对在线公共数据和大规模企业网络流量上的VisHunter进行了评估,并证明VisHunter可以实现平均96.2%的检测率,而对真实企业网络流量的误报率仅为0.9%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号