• DocumentCode
    2116462
  • Title

    Drive-by downloads defense based on kernel level filtering

  • Author

    Li, Jingping ; Chen, Hao ; Sun, Jianhua

  • Author_Institution
    Coll. of Inf. Sci. & Eng., Hunan Univ., Changsha, China
  • fYear
    2012
  • fDate
    21-23 April 2012
  • Firstpage
    3212
  • Lastpage
    3215
  • Abstract
    Recently, How to secure your browser out of malware attacks became the hottest topics on system security. According to the characteristics of Windows systems and drive-by download, this paper designed to eliminate drive-by malware installations present a browser-independent system architecture based on windows kernel file system filter driver and user-level hook technology. By Intercepting the user´s download behavior, user-level module will get the file path information passed to the kernel-level file filter driver module, which can redirect all malicious program to a particular directory in which is to prevent the execution of any binary file. The capabilities of the design combining user-level modules and kernel-level modules can ensure the safety of the operation system. The experimental results present that our defense system has a good protection of the injection of malicious programs because of the fragile web browser and lower running overhead and little impacts to user.
  • Keywords
    Web sites; device drivers; file servers; invasive software; online front-ends; operating system kernels; user interfaces; binary file; browser independent system architecture; browser security; drive-by download defense; fragile Web browser; kernel level file filter driver module; malicious programs protection; malware attack; operation system safety; user download behavior; user level hook technology; user level module; windows kernel file system; Browsers; Delay; Internet; Kernel; Malware; API hook; download behavior; drive-by download; malware prevention; minifilter; system security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Consumer Electronics, Communications and Networks (CECNet), 2012 2nd International Conference on
  • Conference_Location
    Yichang
  • Print_ISBN
    978-1-4577-1414-6
  • Type

    conf

  • DOI
    10.1109/CECNet.2012.6201611
  • Filename
    6201611