基于频繁子树挖掘算法的网页木马检测技术

被引:5
作者
韩心慧 [1 ,2 ]
龚晓锐 [1 ,2 ]
诸葛建伟 [3 ]
邹磊 [1 ]
邹维 [1 ,2 ]
机构
[1] 北京大学计算机科学技术研究所
[2] 北京大学互联网安全技术北京市重点实验室
[3] 清华大学信息网络工程研究中心
基金
高等学校博士学科点专项科研基金;
关键词
网页木马; 频繁子树; 动态分析; 数据挖掘;
D O I
10.16511/j.cnki.qhdxxb.2011.10.021
中图分类号
TP393.08 [];
学科分类号
0839 ; 1402 ;
摘要
针对目前互联网安全的主要威胁之一网页木马,基于网页木马的树状链接结构特征,引入频繁子树挖掘算法,对前期积累的4万多个恶意网页木马场景进行子树模式挖掘,提取了35个网页木马场景共同子树结构特征,利用这些特征在网页木马动态分析过程中辅助检测。实验表明:在加入基于子树特征的检测方法判定的网页木马中,动态检测方法有近20%的漏报。因此,基于子树特征的检测方法有效地提高了动态检测的检测能力和效率,同时挖掘出的典型子树模式提供了网页木马分类和溯源的依据。
引用
收藏
页码:1312 / 1317
页数:6
相关论文
共 13 条
[1]  
Provos N,McNamee D,Mavrommatis P,et al.The ghost in thebrowser analysis of Web-based malware. Proceedings of theFirst Workshop on Hot Topics in Understanding Botnets . 2007
[2]  
Cova M,Kruegel C,Vigna G,et al.Detection and analysisof drive-bydownload attacks and malicious javascript code. Proceedings of the 19th International World Wide WebConference(WWW 10) . 2010
[3]  
Moshchuk A,Bragin T,Deville D,et al.SpyProxy:Execution-based detection of malicious web content. Proceedings of the 16th USENIX Security Symposium(Security 07) . 2007
[4]  
Seifert C,,Welch I,Komisarczuk P.Identification ofmalicious web pages with static heuristics. Proceedingsof the Austalasian Telecommunication Networks andApplications Conference . 2008
[5]  
Wang YiMin,D Beck,Jiang Xuxian et al.Automated web patrol with strider HoneyMonkeys: finding web sites that exploit browser vulnerabilities. Proc. of the 14th USENIX security symposium . 2006
[6]  
Provos N,Mavrommatis P,Rajab M A,et al.All YouriFrames point to us. 17th USENIXSecurity Symposium(USENIX Security 08) . 2008
[7]  
Nazario J.PHoneyC:A virtual client honeypot. 2ndUSENIX Workshop on Large-Scale Exploits and EmergentThreats(LEET 09) . 2009
[8]  
CHEN Zhijie,GU Guofei,Nazario Jose,et al.WebPatrol:Automated collection and replay of web-based malware. Proceedings of the 6th ACM Symposium on Information,Computer and Communications Security(ASIACCS 2011) . 2011
[9]  
A Moshchuk,T Bragin,SD Gribble.A crawler-based study of spyware on the web. Proc. of 13th Annual Network and Distributed System Security Symposium . 2006
[10]  
Davide Canali,Marco Cova,Giovanni Vigna,et al.Prophiler:A fast filter for the large-scale detection ofmalicious web pages. Proceedings of the 20thInternational World Wide Web Conference(WWW 11) . 2011