ResearchBib Share Your Research, Maximize Your Social Impacts
Sign for Notice Everyday Sign up >> Login

BLACKLISTING OF MALICIOUS WEB PAGES BY EVALUATION OF DOMAIN REGISTRATION INFORMATION

Proceeding: The Second International Conference on Cyber Security, Cyber Peacefare and Digital Forensic (CyberSec)

Publication Date:

Authors : ;

Page : 262-273

Keywords : Drive by Download; Blac klist; Domain Information; Registrar; Domain Duration; Domain Freshness; Web Browser;

Source : Downloadexternal Find it from : Google Scholarexternal

Abstract

Malicious web pages that host drive by download exploits have become a popular means by which an attacker delivers malicious contents onto computers across the internet. As a result of the increase in drive by download attack, researchers have developed systems to detect andstop such attacks. Blacklisting and in particular URL blacklisting is one main methods. URL blacklisting are however prone to evasion attacks when the lexical structure of the URL changes. In this paper, we propose the usage of domain related information for the detection of drive by download web pages. These domain features are used to model a scoring mechanism classification system. We show the effectiveness of detecting malicious web pages using domain basedby obtaining a high detection rateand a relatively low false negative.

Last modified: 2013-06-18 22:05:50