DocumentCode
2116462
Title
Drive-by downloads defense based on kernel level filtering
Author
Li, Jingping ; Chen, Hao ; Sun, Jianhua
Author_Institution
Coll. of Inf. Sci. & Eng., Hunan Univ., Changsha, China
fYear
2012
fDate
21-23 April 2012
Firstpage
3212
Lastpage
3215
Abstract
Recently, How to secure your browser out of malware attacks became the hottest topics on system security. According to the characteristics of Windows systems and drive-by download, this paper designed to eliminate drive-by malware installations present a browser-independent system architecture based on windows kernel file system filter driver and user-level hook technology. By Intercepting the user´s download behavior, user-level module will get the file path information passed to the kernel-level file filter driver module, which can redirect all malicious program to a particular directory in which is to prevent the execution of any binary file. The capabilities of the design combining user-level modules and kernel-level modules can ensure the safety of the operation system. The experimental results present that our defense system has a good protection of the injection of malicious programs because of the fragile web browser and lower running overhead and little impacts to user.
Keywords
Web sites; device drivers; file servers; invasive software; online front-ends; operating system kernels; user interfaces; binary file; browser independent system architecture; browser security; drive-by download defense; fragile Web browser; kernel level file filter driver module; malicious programs protection; malware attack; operation system safety; user download behavior; user level hook technology; user level module; windows kernel file system; Browsers; Delay; Internet; Kernel; Malware; API hook; download behavior; drive-by download; malware prevention; minifilter; system security;
fLanguage
English
Publisher
ieee
Conference_Titel
Consumer Electronics, Communications and Networks (CECNet), 2012 2nd International Conference on
Conference_Location
Yichang
Print_ISBN
978-1-4577-1414-6
Type
conf
DOI
10.1109/CECNet.2012.6201611
Filename
6201611
Link To Document