首页> 外文会议>IEEE International Conference on Trust, Security and Privacy in Computing and Communications >Automated Collection and Analysis of Malware Disseminated via Online Advertising
【24h】

Automated Collection and Analysis of Malware Disseminated via Online Advertising

机译:通过在线广告的自动收集和分析恶意软件

获取原文

摘要

Online advertising system has become a convenient and efficient channel to disseminate Web-based malware to the Internet users. Most of the free online services exist in exchange of the revenues generated through advertisements. Therefore, considerable efforts are made to deliver the ads to the appropriate audiences. Cyber criminals can easily exploit this online ad delivery system to deliver malware to a very large number of end-users and their vulnerable machines. We observe that this active approach by cyber criminals can be exploited to expedite the collection of malware. In this paper, we propose an automated system that mimics high-risk browsing activities such as clicking on suspicious online ads, and as a result collects malicious executable files for further analysis and diagnosis. Using our system we crawled over the Internet for a period of 7 days to collect a significant amount of ad frame URLs, which has been monitored for another period of 7 days to collect more than 800 malicious executables. The experimental results showed that our system is quite effective in collecting online malware samples using very limited resources compared to other malware collecting honeypot systems.
机译:在线广告系统已成为一种方便高效的渠道,可以传播基于Web的恶意软件到Internet用户。大多数免费的在线服务都存在于通过广告生成的收入交换。因此,使广告提供相当大的努力将广告提供适当的受众。网络犯罪分子可以轻松利用此在线广告传送系统,将恶意软件传送到大量最终用户及其弱势机器。我们观察到通过网络犯罪分子的这种积极方法可以利用来加快恶意软件的收集。在本文中,我们提出了一种自动化系统,用于模仿高风险浏览活动,例如点击可疑的在线广告,并因此收集恶意可执行文件以进行进一步的分析和诊断。使用我们的系统,我们在互联网上爬出了7天的时间,以收集大量的广告框架URL,这些URL已经监控了7天,以收集超过800个恶意可执行文件。实验结果表明,与收集蜜软件系统的其他恶意软件相比,我们的系统在使用非常有限的资源中收集在线恶意软件样本。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号