• DocumentCode
    3159426
  • Title

    Anomaly Behavior Analysis for Web Page Inspection

  • Author

    Chen, Chia-Mei ; Tsai, Wan-Yi ; Lin, Hsiao-Chung

  • Author_Institution
    Nat. Sun Yat-Sen Univ., Kaohsiung, Taiwan
  • fYear
    2009
  • fDate
    27-29 Dec. 2009
  • Firstpage
    358
  • Lastpage
    363
  • Abstract
    As the Internet prevails, people access web services directly via web browsers over the network. However, most websites are not developed with sufficient security consideration. Hackers have taken the advantage of web application vulnerabilities to inject malicious codes into web pages. A victim who visits such a malicious web page will be compromised. Therefore, an efficient malicious web detection method is needed to prevent users from being compromised. Based on our observation, malicious web pages have uncommon behavior in order to evade from detection of Antivirus software. The anomaly behavior such as code encoding makes malicious web pages different from normal benign web pages. Current researches have noticed pattern-matching approach is not suitable to detect malicious web pages anymore, and then proposes a new detection method. The proposed method, a client-side malicious web page detection method, is based on anomaly behavior analysis. It focuses on distinguishing the behavior difference between malicious and benign web pages. The experimental results show that the proposed method can identify malicious web pages and alarm the website visitors efficiently.
  • Keywords
    Internet; security of data; Internet; Web browser; Web page inspection; Web service; anomaly behavior analysis; antivirus software; client side malicious Web page detection method; code encoding; malicious Web detection method; pattern matching approach; Application software; Banking; Computer hacking; Data security; Inspection; Java; Monitoring; Web and internet services; Web pages; Web services; Anomaly behavior; Drive-by download; Malicious webpage;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Networks and Communications, 2009. NETCOM '09. First International Conference on
  • Conference_Location
    Chennai
  • Print_ISBN
    978-1-4244-5364-1
  • Electronic_ISBN
    978-0-7695-3924-9
  • Type

    conf

  • DOI
    10.1109/NetCoM.2009.72
  • Filename
    5383961