论文标题
检测和分析下载和恶意网站
Detection and Analysis of Drive-by Downloads and Malicious Websites
论文作者
论文摘要
下载驱动器是在没有用户行动或知识的情况下进行下载的。它通常会触发浏览器中漏洞的利用来下载未知文件。下载文件中的恶意程序将自身安装在受害者机器上。此外,可以将下载的文件作为安装程序伪装,以进一步安装恶意软件。通过下载驱动是一个很好的例子,说明了通过互联网上的恶意活动的指数增加以及它如何影响网络的日常使用。在本文中,我们试图从不同的角度下载来解决由驱动器引起的问题。我们深入了解通过下载来处理驱动器的困难并提出适当的解决方案。我们建议机器学习和功能选择解决方案,以纠正驱动器下载问题。实验结果报告了98.2%的精度,98.2%的F量和97.2%的ROC面积。
A drive by download is a download that occurs without users action or knowledge. It usually triggers an exploit of vulnerability in a browser to downloads an unknown file. The malicious program in the downloaded file installs itself on the victims machine. Moreover, the downloaded file can be camouflaged as an installer that would further install malicious software. Drive by downloads is a very good example of the exponential increase in malicious activity over the Internet and how it affects the daily use of the web. In this paper, we try to address the problem caused by drive by downloads from different standpoints. We provide in depth understanding of the difficulties in dealing with drive by downloads and suggest appropriate solutions. We propose machine learning and feature selection solutions to remedy the the drive-by download problem. Experimental results reported 98.2% precision, 98.2% F-Measure and 97.2% ROC area.