【24h】

Automated Collection and Analysis of Malware Disseminated via Online Advertising

机译:通过网络广告自动收集和分析恶意软件

获取原文

摘要

Online advertising system has become a convenient and efficient channel to disseminate Web-based malware to the Internet users. Most of the free online services exist in exchange of the revenues generated through advertisements. Therefore, considerable efforts are made to deliver the ads to the appropriate audiences. Cyber criminals can easily exploit this online ad delivery system to deliver malware to a very large number of end-users and their vulnerable machines. We observe that this active approach by cyber criminals can be exploited to expedite the collection of malware. In this paper, we propose an automated system that mimics high-risk browsing activities such as clicking on suspicious online ads, and as a result collects malicious executable files for further analysis and diagnosis. Using our system we crawled over the Internet for a period of 7 days to collect a significant amount of ad frame URLs, which has been monitored for another period of 7 days to collect more than 800 malicious executables. The experimental results showed that our system is quite effective in collecting online malware samples using very limited resources compared to other malware collecting honeypot systems.
机译:在线广告系统已成为将基于Web的恶意软件传播给Internet用户的便捷有效的渠道。大多数免费的在线服务是通过交换广告产生的收入而存在的。因此,做出了相当大的努力来将广告分发给适当的受众。网络罪犯可以轻松利用此在线广告投放系统将恶意软件投放到大量最终用户及其易受攻击的机器。我们观察到,可以利用网络犯罪分子的这种积极方法来加速恶意软件的收集。在本文中,我们提出了一种自动系统,该系统可以模拟高风险的浏览活动,例如单击可疑的在线广告,从而收集恶意的可执行文件以进行进一步的分析和诊断。使用我们的系统,我们在Internet上进行了7天的爬网,以收集大量的广告框架URL,并对其进行了7天的监视,以收集800多个恶意可执行文件。实验结果表明,与其他恶意软件收集蜜罐系统相比,我们的系统在使用非常有限的资源收集恶意软件样本方面非常有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号