BLACKLISTING OF MALICIOUS WEB PAGES BY EVALUATION OF DOMAIN REGISTRATION INFORMATION
Proceeding: The Second International Conference on Cyber Security, Cyber Peacefare and Digital Forensic (CyberSec)Publication Date: 2013-03-04
Authors : Ralph Edem Agbefum Yoshiaki Hori Kouichi Sakurai;
Page : 262-273
Keywords : Drive by Download; Blac klist; Domain Information; Registrar; Domain Duration; Domain Freshness; Web Browser;
Abstract
Malicious web pages that host drive by download exploits have become a popular means by which an attacker delivers malicious contents onto computers across the internet. As a result of the increase in drive by download attack, researchers have developed systems to detect andstop such attacks. Blacklisting and in particular URL blacklisting is one main methods. URL blacklisting are however prone to evasion attacks when the lexical structure of the URL changes. In this paper, we propose the usage of domain related information for the detection of drive by download web pages. These domain features are used to model a scoring mechanism classification system. We show the effectiveness of detecting malicious web pages using domain basedby obtaining a high detection rateand a relatively low false negative.
Other Latest Articles
- AWAKEN THE CYBER DRAGON: CHINA'S CYBER STRATEGY AND ITS IMPACT ON ASEAN
- THE CYBER DOGS OF WAR: JOINT EFFORTS OF FUTURE WORLD LEADERS IN THE PREVENTION OF CYBERWARFARE
- ADAPTIVE SECURITY AND TRUST
- INHERENT ID: A NOVEL APPROACH TO DETECT COUNTERFEIT CONSUMER GOODS USING PRODUCT INHERENT FEATURES
- EMPIRICAL ASSESSMENT OF DATA PROTECTION AND CIRCUMVENTION TOOLS AVAILABILITY IN MOBILE NETWORKS
Last modified: 2013-06-18 22:05:50