• DocumentCode
    1975836
  • Title

    EINSPECT: Evolution-Guided Analysis and Detection of Malicious Web Pages

  • Author

    Eshete, Birhanu ; Villafiorita, Adolfo ; Weldemariam, Komminist ; Zulkernine, Mohammad

  • Author_Institution
    Fondazione Bruno Kessler, Trento, Italy
  • fYear
    2013
  • fDate
    22-26 July 2013
  • Firstpage
    375
  • Lastpage
    380
  • Abstract
    Most existing work to thwart malicious web pages capture maliciousness via discriminative artifacts, learn a model, and detect by leveraging static and/or dynamic analysis. Unfortunately, there is a two-sided evolution of the artifacts of web pages. On one hand, cybercriminals constantly revamp attack payloads in malicious web pages. On the other hand, benign web pages evolve to improve content rendering and interaction with users. Consequently, the onceprecise detection techniques suffer from limitations to cope with the evolution, resulting in malicious web pages that escape detection. In this paper, we present EINSPECT, an evolution-aware and learning-based approach to address evolution of web page artifacts to more precisely analyze and detect malicious web pages. EINSPECT continuously tunes its detection models to automatically decide the best interplay of features and learning algorithms to embrace the evolution of web page artifacts into the analysis and detection. We have implemented and evaluated our approach and the results show that EINSPECT is able to improve the effectiveness of analysis and detection ofmalicious web pages while aligning the detection models with the continuous evolution of web page artifacts.
  • Keywords
    Internet; learning (artificial intelligence); security of data; EINSPECT; content rendering; cybercriminals; evolution-aware approach; evolution-guided analysis; learning-based approach; malicious Web pages; precise detection techniques; Accuracy; Biological cells; Computational modeling; Feature extraction; HTML; Optimization; Web pages; attack evolution; lightweight emulation; machine learning; malicious web pages; static analysis;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Software and Applications Conference (COMPSAC), 2013 IEEE 37th Annual
  • Conference_Location
    Kyoto
  • Type

    conf

  • DOI
    10.1109/COMPSAC.2013.63
  • Filename
    6649850