首页> 外文期刊>Journal of computational science >Analysis of malware download sites by focusing on time series variation of malware
【24h】

Analysis of malware download sites by focusing on time series variation of malware

机译:通过关注恶意软件的时间序列变化来分析恶意软件下载站点

获取原文
获取原文并翻译 | 示例
           

摘要

As the use of Internet increases, malicious activity has become increasingly problematic. In particular, drive-by download attacks have become a serious problem. As part of an exploit-as-a-service ecosystem for drive-by download attacks, malware download sites play a particularly important role. In this study, we analyzed approximately 43,000 malware download URLs to investigate malware distribution and the behavior of malware download sites over an extended period, i.e., over 1.5 years. We found that some sites survive for a very long time and are revived frequently, a finding not revealed in previous research. By focusing on the malware variation, we have identified three categories of malware download sites, i.e., unchanged, every time changed, changed occasionally. We found that 10% of unchanged sites survived for more than 500 days, and 10% of changed occasionally sites were revived more than 15 times in the entire observation period. We also analyzed sites in terms of IP address changes, anti-virus application results, URL features, and Virus Total results. We found that each category had different attacker operational and resource characteristics. Finally, based on our findings, we discuss effective countermeasures for each category. (c) 2017 Elsevier B.V. All rights reserved.
机译:随着互联网的使用增加,恶意活动变得越来越成问题。特别是,过路下载攻击已成为一个严重的问题。作为用于驾乘式下载攻击的“即服务开发”生态系统的一部分,恶意软件下载站点扮演着特别重要的角色。在这项研究中,我们分析了大约43,000个恶意软件下载URL,以调查在较长时期内(即1.5年以上)的恶意软件分布和恶意软件下载网站的行为。我们发现某些站点可以生存很长时间,并且经常被恢复,这一发现在以前的研究中并未得到揭示。通过关注恶意软件的变化,我们确定了恶意软件下载站点的三类,即不变,每次更改,偶尔更改。我们发现,在整个观察期内,10%的未改变位点可以存活500天以上,而10%的偶尔改变的位点可以存活15次以上。我们还根据IP地址更改,防病毒应用程序结果,URL功能和“病毒总数”结果分析了站点。我们发现每个类别都有不同的攻击者操作和资源特征。最后,根据我们的发现,我们讨论每种类别的有效对策。 (c)2017 Elsevier B.V.保留所有权利。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号