WebMon: ML- and YARA-based malicious webpage detection

被引:16
作者
Kim, Sungjin [1 ]
Kim, Jinkook [2 ]
Nam, Seokwoo [3 ]
Kim, Dohoon [4 ]
机构
[1] Korea Adv Inst Sci & Technol, Sch Comp, Grad Sch Informat Secur, Daejeon, South Korea
[2] NCSOFT JAPAN KK, Tokyo 1060032, Japan
[3] SGA Syst, Informat Sharing & Anal Ctr, Seoul, South Korea
[4] Kyonggi Univ, Dept Comp Sci, Kyonggido, South Korea
关键词
Docker; Machine learning; Malicious URL; WebKit2; YARA;
D O I
10.1016/j.comnet.2018.03.006
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Attackers use the openness of the Internet to facilitate the dissemination of malware. Their attempts to infect target systems via the Web have increased with time and are unlikely to abate. In response to this threat, we present an automated, low-interaction malicious webpage detector, WebMon, that identifies invasive roots in Web resources loaded from WebKit2-based browsers using machine learning and YARA signatures. WebMon effectively detects hidden exploit codes by tracing linked URLs to confirm whether the relevant websites are malicious. WebMon detects a variety of attacks by running 250 containers simultaneously. In this configuration, the proposed model yields a detection rate of 98%, and is 7.6 times faster (with a container) than previously proposed models. Most importantly, WebMon's focus on extracting malicious paths in a domain is a novel approach that has not been explored in previous studies. (C) 2018 Published by Elsevier B.V.
引用
收藏
页码:119 / 131
页数:13
相关论文
共 16 条
[1]  
[Anonymous], 2010, WEB C WWW
[2]  
[Anonymous], 2009, P 15 ACM SIGKDD INT
[3]  
[Anonymous], 2011, P 20 INT C WORLD WID
[4]  
[Anonymous], 2009, P 26 ANN INT C MACH, DOI DOI 10.1145/1553374.1553462
[5]  
Curtsinger C., 2011, USENIX SEC S
[6]  
Eshete B., 2014, P 4 ACM C DATA APPL
[7]  
Eshete B., 2015, NDSS
[8]   Malicious web content detection by machine learning [J].
Hou, Yung-Tsung ;
Chang, Yimeng ;
Chen, Tsuhan ;
Laih, Chi-Sung ;
Chen, Chia-Mei .
EXPERT SYSTEMS WITH APPLICATIONS, 2010, 37 (01) :55-60
[9]  
Kim S, 2017, ETRI J, V39, P406
[10]  
Li Zhou, 2012, ACM C COMP COMM SEC, P674