首页> 外文会议>International Conference on Collaborative Computing: Networking, Applications and Worksharing >Detection of plugin misuse drive-by download attacks using kernel machines
【24h】

Detection of plugin misuse drive-by download attacks using kernel machines

机译:使用内核计算机检测插件滥用驱动程序下载攻击

获取原文

摘要

Malware distribution using drive-by download attacks has become the most prominent threat for organizations and individuals. Compromised web services and web applications hosted on the cloud act as the delivery medium for the exploits. The exploits included often target the vulnerabilities within the plugins of the web browsers. Implementing security controls to counter the exploits within the browsers for ensuring end point security has become a challenge. In this paper, a set of features is proposed and is extracted by monitoring the communications between the browser and the plugins during the rendering of webpages. The Support Vector Machines are trained using the defined features and the performance of the trained classifier is evaluated using a dataset with both malicious and benign use cases of the plugins. The dataset included 10,239 malicious use cases and 37,369 benign use cases. To compensate the imbalance in the distribution of the dataset, experiments were performed using weighted costs and oversampling. Our analysis shows that the Support Vector Machines trained by using the proposed set of features classified with an average accuracy of about 99.4%. On integrating the proposed approach as an inline defense, an average performance overhead of 5.14% was observed.
机译:使用偷渡式下载攻击的恶意软件分发已成为组织和个人面临的最主要威胁。托管在云上的受损Web服务和Web应用程序充当漏洞利用的传递媒介。所包含的漏洞通常针对Web浏览器插件中的漏洞。实施安全控制以应对浏览器中的漏洞,以确保端点安全已成为一项挑战。在本文中,提出了一组功能,这些功能是通过在网页呈现期间监视浏览器与插件之间的通信来提取的。支持向量机使用定义的功能进行训练,训练后的分类器的性能通过使用具有恶意和良性插件用例的数据集进行评估。数据集包括10,239个恶意用例和37,369个良性用例。为了补偿数据集分布中的不平衡,使用加权成本和过采样进行了实验。我们的分析表明,通过使用建议的特征集对支持向量机进行训练,其特征分类的平均准确度约为99.4%。将建议的方法集成为在线防御后,平均性能开销为5.14%。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号