WebCop: Locating Neighborhoods of Malware on the Web

نویسندگان

  • Jack W. Stokes
  • Reid Andersen
  • Christian Seifert
  • Kumar Chellapilla
چکیده

In this paper, we propose WebCop to identify malicious web pages and neighborhoods of malware on the internet. Using a bottom-up approach, telemetry data from commercial Anti-Malware (AM) clients running on millions of computers first identify malware distribution sites hosting malicious executables on the web. Next, traversing hyperlinks in a web graph constructed from a commercial search engine crawler in the reverse direction quickly discovers malware landing pages linking to the malware distribution sites. In addition, the malicious distribution sites and web graph are used to identify neighborhoods of malware, locate additional executables distributed on the internet which may be unknown malware and identify false positives in AM signatures. We compare the malicious URLs generated by the proposed method with those found by a commercial, drive-by download approach and show that lists are independent; both methods can be used to identify malware on the internet and help protect end users.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

The Shape of Alerts: Detecting Malware Using Distributed Detectors by Robustly Amplifying Transient Correlations

We introduce a new malware detector – Shape-GD– that aggregates per-machine detectors into a robust global detector. Shape-GD is based on two insights: 1. Structural: actions such as visiting a website (waterhole attack) by nodes correlate well with malware spread, and create dynamic neighborhoods of nodes that were exposed to the same attack vector. However, neighborhood sizes vary unpredictab...

متن کامل

Neighborhoods: A Framework For Enabling Web Based Synchronous Collaboration And Hierarchical Navigation

The World-Wide Web (WWW) is an extremely effective mechanism for sharing information throughout the world via a web of links. These links allow anyone with a connection to the Internet to unearth large amounts of information on multitudes of topics. However, access to this information is asynchronous, with no way for users to interact with each other in real time. We have developed Neighborhood...

متن کامل

Exploiting Latent Attack Semantics for Intelligent Malware Detection

We introduce a newmalware detector – Shape-GD – that aggregates per-machine detectors into a robust global detector. Shape-GD is based on two insights: 1. Structural: actions such as visiting a website (waterhole attack) or membership in a shared email thread (phishing attack) by nodes correlate well with malware spread, and create dynamic neighborhoods of nodes that were exposed to the same at...

متن کامل

Locating of neighborhood self-help centers by combined FUZZY-AHP method (Case study: Sirous neighborhood of Tehran)

Background and Aim: Effective emergency response to earthquake occurrence in dysfunctional urban contexts requires a cycle of multiple and coordinated measures. Neighborhood self-help center is one of the emerging physical centers supporting emergency management which according to lessons learned from earthquake experiences, its establishment can play an effective role in providing on-time assi...

متن کامل

DyVSoR: dynamic malware detection based on extracting patterns from value sets of registers

To control the exponential growth of malware files, security analysts pursue dynamic approaches that automatically identify and analyze malicious software samples. Obfuscation and polymorphism employed by malwares make it difficult for signature-based systems to detect sophisticated malware files. The dynamic analysis or run-time behavior provides a better technique to identify the threat. In t...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2010