DocumentCode :
230789
Title :
Detection of plugin misuse drive-by download attacks using kernel machines
Author :
Cherukuri, Manoj ; Mukkamala, Srinivas ; Dongwan Shin
Author_Institution :
Inst. for Complex Additive & Syst. Anal., New Mexico Inst. of Min. & Technol., Socorro, NM, USA
fYear :
2014
fDate :
22-25 Oct. 2014
Firstpage :
546
Lastpage :
553
Abstract :
Malware distribution using drive-by download attacks has become the most prominent threat for organizations and individuals. Compromised web services and web applications hosted on the cloud act as the delivery medium for the exploits. The exploits included often target the vulnerabilities within the plugins of the web browsers. Implementing security controls to counter the exploits within the browsers for ensuring end point security has become a challenge. In this paper, a set of features is proposed and is extracted by monitoring the communications between the browser and the plugins during the rendering of webpages. The Support Vector Machines are trained using the defined features and the performance of the trained classifier is evaluated using a dataset with both malicious and benign use cases of the plugins. The dataset included 10,239 malicious use cases and 37,369 benign use cases. To compensate the imbalance in the distribution of the dataset, experiments were performed using weighted costs and oversampling. Our analysis shows that the Support Vector Machines trained by using the proposed set of features classified with an average accuracy of about 99.4%. On integrating the proposed approach as an inline defense, an average performance overhead of 5.14% was observed.
Keywords :
invasive software; online front-ends; support vector machines; Web browser; drive-by download attack; kernel machine; malware distribution; plugin detection; support vector machine; Analytical models; Browsers; Monitoring; Security; Web services; drive-by download; plugin exploits; web malware;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Collaborative Computing: Networking, Applications and Worksharing (CollaborateCom), 2014 International Conference on
Conference_Location :
Miami, FL
Type :
conf
Filename :
7014611
Link To Document :
بازگشت