首页> 外文会议>IEEE Symposium on Computers and Communications >AutoBLG: Automatic URL blacklist generator using search space expansion and filters
【24h】

AutoBLG: Automatic URL blacklist generator using search space expansion and filters

机译:AutoBLOG:使用搜索空间扩展和过滤器的自动URL黑名单生成器

获取原文

摘要

Modern web users are exposed to a browser security threat called drive-by-download attacks that occur by simply visiting a malicious Uniform Resource Locator (URL) that embeds code to exploit web browser vulnerabilities. Many web users tend to click such URLs without considering the underlying threats. URL blacklists are an effective countermeasure to such browser-targeted attacks. URLs are frequently updated; therefore, collecting fresh malicious URLs is essential to ensure the effectiveness of a URL blacklist. We propose a framework called automatic blacklist generator (AutoBLG) that automatically identifies new malicious URLs using a given existing URL blacklist. The key idea of AutoBLG is expanding the search space of web pages while reducing the amount of URLs to be analyzed by applying several pre-filters to accelerate the process of generating blacklists. Auto-BLG comprises three primary primitives: URL expansion, URL filtration, and URL verification. Through extensive analysis using a high-performance web client honeypot, we demonstrate that AutoBLG can successfully extract new and previously unknown drive-by-download URLs.
机译:现代Web用户面临的浏览器安全威胁称为“下载驱动攻击”,这种威胁仅通过访问嵌入代码以利用Web浏览器漏洞的恶意统一资源定位符(URL)即可发生。许多Web用户倾向于在不考虑潜在威胁的情况下单击此类URL。 URL黑名单是针对此类针对浏览器的攻击的有效对策。网址经常更新;因此,收集新的恶意URL对于确保URL黑名单的有效性至关重要。我们提出了一个称为自动黑名单生成器(AutoBLG)的框架,该框架可以使用给定的现有URL黑名单自动识别新的恶意URL。 AutoBLG的关键思想是通过应用几个预过滤器来加快生成黑名单的过程,从而在扩展网页搜索空间的同时减少要分析的URL数量。 Auto-BLG包含三个主要原语:URL扩展,URL过滤和URL验证。通过使用高性能Web客户端蜜罐进行的广泛分析,我们证明了AutoBLG可以成功提取新的和以前未知的按下载下载的URL。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号