首页> 外文会议>Symposium on Chemistry as a second language >Preventing Drive-by Download via Inter-Module Communication Monitoring
【24h】

Preventing Drive-by Download via Inter-Module Communication Monitoring

机译:通过模块间通信监控防止驱动器下载

获取原文

摘要

Drive-by download attack is one of the most severe threats to Internet users. Typically, only visiting a malicious page will result in comproxnise of the client and infection of malware. By the end of 2008, drive-by download had already become the number one infection vector of malware [5]. The down loaded malware may steal the users' personal identification and password. They may also join botnet to send spams, host phishing site or launch distributed denial of service at tacks. Generally, these attacks rely on successful exploits of the vulnerabilities in web browsers or their plug-ins. There fore, we proposed an inter-module communication monitor ing based technique to detect malicious exploitation of vul nerable components thus preventing the vulnerability being exploited. We have implemented a prototype system that was integrated into the most popular web browser Microsoft Internet Explorer. Experimental results demonstrate that, on our test set, by using vulnerability-based signature, our system could accurately detect all attacks targeting at vul nerabilities in our definitions and produced no false positive. The evaluation also shows the performance penalty is kept low.
机译:通过下载攻击是对互联网用户最严重的威胁之一。通常,只有访问恶意页面将导致客户端的COUROXISE和恶意软件的感染。到2008年底,通过下载推动已经成为恶意软件的头号感染矢量[5]。下载的恶意软件可以窃取用户的个人识别和密码。他们还可以加入僵尸网络发送垃圾邮件,主机网络钓鱼站点或在钉子上发射分发拒绝服务。通常,这些攻击依赖于Web浏览器或其插件中的漏洞的成功利用。因此,我们提出了一个基于模块间通信监视器的技术,以检测普遍可达的组件的恶意开发,从而防止漏洞被利用。我们已经实现了一个原型系统,该系统被集成到最受欢迎的Web浏览器Microsoft Internet Explorer中。实验结果表明,在我们的测试集上,通过使用基于漏洞的签名,我们的系统可以在我们的定义中准确地检测目标,在我们的定义中瞄准众多攻击,并没有产生假阳性。评估还显示了性能惩罚保持低。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号