首页> 外文期刊>Security and Communication Networks (Online) >Using HTML5 to prevent detection of drive‐by‐download web malware
【24h】

Using HTML5 to prevent detection of drive‐by‐download web malware

机译:使用HTML5防止检测到按下载下载的网络恶意软件

获取原文
           

摘要

The Web is experiencing an explosive growth in the last years. New technologies are introduced at a very fast pace with the aim of narrowing the gap between web‐based applications and traditional desktop applications. The results are web applications that look and feel almost like desktop applications while retaining the advantages of being originated from the Web. However, these advancements come at a price. The same technologies used to build responsive, pleasant, and fully featured web applications can also be used to write web malware able to escape detection systems. In this article, we present new obfuscation techniques, on the basis of some of the features of the upcoming HTML5 standard, which can be used to deceive malware detection systems. The proposed techniques have been experimented on a reference set of obfuscated malware. Our results show that the malware rewritten using our obfuscation techniques goes undetected while being analyzed by a large number of detection systems. The same detection systems were able to correctly identify the same malware in its original unobfuscated form. We also provide some hints about how the existing malware detection systems can be modified in order to cope with these new techniques. Copyright ? 2014 John Wiley & Sons, Ltd. We present new obfuscation techniques, on the basis of some of the features of the upcoming HTML5 standard, which can be used to deceive malware detection systems. The proposed techniques have been experimented on a reference set of obfuscated malware. Our results show that the malware rewritten using our obfuscation techniques go undetected while being analyzed by a large number of detection systems.
机译:在过去的几年中,Web正在经历爆炸性的增长。为了缩小基于Web的应用程序与传统桌面应用程序之间的差距,以非常快的速度引入了新技术。结果是外观和感觉几乎与桌面应用程序相似的Web应用程序,同时保留了源于Web的优点。但是,这些进步是有代价的。用于构建响应式,令人愉悦且功能齐全的Web应用程序的相同技术也可以用于编写能够逃脱检测系统的Web恶意软件。在本文中,我们将基于即将到来的HTML5标准的某些功能,提出新的混淆技术,这些技术可用于欺骗恶意软件检测系统。所提议的技术已在一组混淆的恶意软件参考上进行了实验。我们的结果表明,使用我们的混淆技术重写的恶意软件在被大量检测系统分析时未被发现。相同的检测系统能够以原始的原始形式正确识别相同的恶意软件。我们还提供一些有关如何修改现有恶意软件检测系统以应对这些新技术的提示。版权? 2014 John Wiley&Sons,Ltd.基于即将到来的HTML5标准的某些功能,我们提出了新的混淆技术,可用于欺骗恶意软件检测系统。所提议的技术已在一组混淆的恶意软件参考上进行了实验。我们的结果表明,使用我们的混淆技术重写的恶意软件在被大量检测系统分析时未被检测到。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号