Research Hub

대학 자원

대학 인프라와 자원을 공유해 공동 연구와 기술 활용을 지원합니다.

Loading...

논문 리스트

2015
ELPA:Emulation-based Linked Page Map Analysis for the Detection of Drive-by Attacks ELPA:Emulation-based Linked Page Map Analysis for the Detection of Drive-by Attacks
한국정보처리학회
김용민
논문정보
Publisher
JIPS(Journal of Information Processing Systems)
Issue Date
2015-12-31
Keywords
-
Citation
-
Source
-
Journal Title
-
Volume
103745
Number
jips030045
Start Page
1
End Page
14
DOI
ISSN
1976913X
Abstract
Despite the convenience brought by the advances in web and Internet technology, users are increasingly being exposed to the danger of various types of cyber attacks. In particular, recent studies have shown that today’s cyber attacks usually occur on the web via malware distribution and the stealing of personal information. A drive-by download is a kind of web-based attack for malware distribution. Researchers have proposed various methods for detecting a drive-by download attack effectively. However, existing methods have limitations against recent evasion techniques, including JavaScript obfuscation, hiding, and dynamic code evaluation. In this paper, we propose an emulation-based malicious webpage detection method. Based on our study on the limitations of the existing methods and the state-of-the-art evasion techniques, we will introduce four features that can detect malware distribution networks and we applied them to the proposed method. Our performance evaluation using a URL scan engine provided by VirusTotal shows that the proposed method detects malicious webpages more precisely than existing solutions.

저자 정보

이름 소속
김용민 문화콘텐츠학부