Title :
Drive-by downloads defense based on kernel level filtering
Author :
Li, Jingping ; Chen, Hao ; Sun, Jianhua
Author_Institution :
Coll. of Inf. Sci. & Eng., Hunan Univ., Changsha, China
Abstract :
Recently, How to secure your browser out of malware attacks became the hottest topics on system security. According to the characteristics of Windows systems and drive-by download, this paper designed to eliminate drive-by malware installations present a browser-independent system architecture based on windows kernel file system filter driver and user-level hook technology. By Intercepting the user´s download behavior, user-level module will get the file path information passed to the kernel-level file filter driver module, which can redirect all malicious program to a particular directory in which is to prevent the execution of any binary file. The capabilities of the design combining user-level modules and kernel-level modules can ensure the safety of the operation system. The experimental results present that our defense system has a good protection of the injection of malicious programs because of the fragile web browser and lower running overhead and little impacts to user.
Keywords :
Web sites; device drivers; file servers; invasive software; online front-ends; operating system kernels; user interfaces; binary file; browser independent system architecture; browser security; drive-by download defense; fragile Web browser; kernel level file filter driver module; malicious programs protection; malware attack; operation system safety; user download behavior; user level hook technology; user level module; windows kernel file system; Browsers; Delay; Internet; Kernel; Malware; API hook; download behavior; drive-by download; malware prevention; minifilter; system security;
Conference_Titel :
Consumer Electronics, Communications and Networks (CECNet), 2012 2nd International Conference on
Conference_Location :
Yichang
Print_ISBN :
978-1-4577-1414-6
DOI :
10.1109/CECNet.2012.6201611