首页> 外文期刊>IEICE transactions on information and systems >Automating URL Blacklist Generation with Similarity Search Approach
【24h】

Automating URL Blacklist Generation with Similarity Search Approach

机译:使用相似性搜索方法自动生成URL黑名单

获取原文
       

摘要

Modern web users may encounter a browser security threat called drive-by-download attacks when surfing on the Internet. Drive-by-download attacks make use of exploit codes to take control of user's web browser. Many web users do not take such underlying threats into account while clicking URLs. URL Blacklist is one of the practical approaches to thwarting browser-targeted attacks. However, URL Blacklist cannot cope with previously unseen malicious URLs. Therefore, to make a URL blacklist effective, it is crucial to keep the URLs updated. Given these observations, we propose a framework called automatic blacklist generator (AutoBLG) that automates the collection of new malicious URLs by starting from a given existing URL blacklist. The primary mechanism of AutoBLG is expanding the search space of web pages while reducing the amount of URLs to be analyzed by applying several pre-filters such as similarity search to accelerate the process of generating blacklists. AutoBLG consists of three primary components: URL expansion, URL filtration, and URL verification. Through extensive analysis using a high-performance web client honeypot, we demonstrate that AutoBLG can successfully discover new and previously unknown drive-by-download URLs from the vast web space.
机译:现代Web用户在Internet上冲浪时可能会遇到称为“下载驱动攻击”的浏览器安全威胁。通过下载进行驱动攻击利用漏洞利用代码来控制用户的Web浏览器。许多Web用户在单击URL时并未考虑到此类潜在威胁。 URL黑名单是阻止以浏览器为目标的攻击的实用方法之一。但是,URL黑名单无法应对以前看不见的恶意URL。因此,要使URL黑名单有效,保持URL更新至关重要。鉴于这些发现,我们提出了一个称为自动黑名单生成器(AutoBLG)的框架,该框架通过从给定的现有URL黑名单开始,自动收集新的恶意URL。 AutoBLG的主要机制是扩展网页的搜索空间,同时通过应用多个预过滤器(例如相似性搜索)来减少要分析的URL的数量,以加速生成黑名单的过程。 AutoBLG由三个主要组件组成:URL扩展,URL过滤和URL验证。通过使用高性能Web客户端蜜罐进行的广泛分析,我们证明了AutoBLG可以成功地从广阔的Web空间中发现新的和以前未知的通过下载驱动的URL。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号