Title :
Browser JS Guard: Detects and defends against Malicious JavaScript injection based drive by download attacks
Author :
Kishore, K. Ravi ; Mallesh, M. ; Jyostna, G. ; Eswari, P.R.L. ; Sarma, Samavedam Satyanadha
Author_Institution :
Centre for Dev. of Adv. Comput., Hyderabad, India
Abstract :
In the recent times, most of the systems connected to Internet are getting infected with the malware and some of these systems are becoming zombies for the attacker. When user knowingly or unknowingly visits a malware website, his system gets infected. Attackers do this by exploiting the vulnerabilities in the web browser and acquire control over the underlying operating system. Once attacker compromises the users web browser, he can instruct the browser to visit the attackers website by using number of redirections. During the process, users web browser downloads the malware without the intervention of the user. Once the malware is downloaded, it would be placed in the file system and responds as per the instructions of the attacker. These types of attacks are known as Drive by Download attacks. Now-a-days, Drive by Download is the major channel for delivering the Malware. In this paper, Browser JS Guard an extension to the browser is presented for detecting and defending against Drive by Download attacks via HTML tags and JavaScript.
Keywords :
Java; Web sites; authoring languages; invasive software; online front-ends; operating systems (computers); security of data; HTML tags; Internet; browser JS guard; download attacks; drive by download attacks; file system; malicious JavaScript injection; malware Web site; operating system; user Web browser; Browsers; HTML; Malware; Monitoring; Web pages; Web servers; DOM Change Methods; Drive by Download Attacks; HTML tags; JavaScript Functions; Malware; Web Browser; Web Browser Extensions;
Conference_Titel :
Applications of Digital Information and Web Technologies (ICADIWT), 2014 Fifth International Conference on the
Conference_Location :
Bangalore
Print_ISBN :
978-1-4799-2258-1
DOI :
10.1109/ICADIWT.2014.6814705