首页> 外文会议>Security and Privacy (SP), 2012 IEEE Symposium on >EvilSeed: A Guided Approach to Finding Malicious Web Pages
【24h】

EvilSeed: A Guided Approach to Finding Malicious Web Pages

机译:EvilSeed:查找恶意网页的指导方法

获取原文
获取原文并翻译 | 示例

摘要

Malicious web pages that use drive-by download attacks or social engineering techniques to install unwanted software on a user's computer have become the main avenue for the propagation of malicious code. To search for malicious web pages, the first step is typically to use a crawler to collect URLs that are live on the Internet. Then, fast prefiltering techniques are employed to reduce the amount of pages that need to be examined by more precise, but slower, analysis tools (such as honey clients). While effective, these techniques require a substantial amount of resources. A key reason is that the crawler encounters many pages on the web that are benign, that is, the "toxicity" of the stream of URLs being analyzed is low. In this paper, we present EVILSEED, an approach to search the web more efficiently for pages that are likely malicious. EVILSEED starts from an initial seed of known, malicious web pages. Using this seed, our system automatically generates search engines queries to identify other malicious pages that are similar or related to the ones in the initial seed. By doing so, EVILSEED leverages the crawling infrastructure of search engines to retrieve URLs that are much more likely to be malicious than a random page on the web. In other words EVILSEED increases the "toxicity" of the input URL stream. Also, we envision that the features that EVILSEED presents could be directly applied by search engines in their prefilters. We have implemented our approach, and we evaluated it on a large-scale dataset. The results show that EVILSEED is able to identify malicious web pages more efficiently when compared to crawler-based approaches.
机译:使用偷渡式下载攻击或社会工程学技术在用户计算机上安装不需要的软件的恶意网页已成为传播恶意代码的主要途径。要搜索恶意网页,第一步通常是使用搜寻器来收集Internet上实时存在的URL。然后,采用快速的预过滤技术来减少需要由更精确但速度较慢的分析工具(例如Honey Client)检查的页面数量。虽然有效,但是这些技术需要大量资源。一个关键原因是,爬网程序在Web上遇到许多良性的页面,即,所分析的URL流的“毒性”很低。在本文中,我们介绍了EVILSEED,这是一种更有效地在网络上搜索可能有害网页的方法。 EVILSEED从已知的恶意网页的初始种子开始。使用该种子,我们的系统会自动生成搜索引擎查询,以识别与初始种子中的页面相似或相关的其他恶意页面。通过这样做,EVILSEED利用搜索引擎的爬网基础结构来检索比Web上的随机页面更有可能是恶意的URL。换句话说,EVILSEED增加了输入URL流的“毒性”。此外,我们设想EVILSEED呈现的功能可以由搜索引擎在其预过滤器中直接应用。我们已经实施了我们的方法,并在大型数据集上对其进行了评估。结果表明,与基于搜寻器的方法相比,EVILSEED能够更有效地识别恶意网页。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号