• DocumentCode
    3255132
  • Title

    Identification of malicious web pages through analysis of underlying DNS and web server relationships

  • Author

    Seifert, Christian ; Welch, Ian ; Komisarczuk, Peter ; Aval, Chiraag Uday ; Endicott-Popovsky, Barbara

  • Author_Institution
    Victoria Univ. of Wellington, Wellington
  • fYear
    2008
  • fDate
    14-17 Oct. 2008
  • Firstpage
    935
  • Lastpage
    941
  • Abstract
    Malicious Web pages that launch drive-by-download attacks on Web browsers have increasingly become a problem in recent years. High-interaction client honeypots are security devices that can detect these malicious Web pages on a network. However, high-interaction client honeypots are both resource-intensive and unable to handle the increasing array of vulnerable clients. This paper presents a novel classification method for detecting malicious Web pages that involves inspecting the underlying server relationships. Because of the unique structure of malicious front-end Web pages and centralized exploit servers, merely counting the number of domain name extensions and Domain Name System (DNS) servers used to resolve the host names of all Web servers involved in rendering a page is sufficient to determine whether a Web page is malicious or benign, independent of the vulnerable Web browser targeted by these pages. Combining high-interaction client honeypots and this new classification method into a hybrid system leads to performance improvements.
  • Keywords
    Internet; file servers; online front-ends; pattern classification; security of data; telecommunication security; Web browser; Web server relationship; classification method; domain name system server; drive-by-download attack; high-interaction client honeypot; hybrid system; malicious Web page identification; security device; Communication system security; Domain Name System; IP networks; Information resources; Information security; Intrusion detection; Network servers; Web and internet services; Web pages; Web server; Client Honeypots; Drive-by-downloads; Intrusion Detection; Security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Local Computer Networks, 2008. LCN 2008. 33rd IEEE Conference on
  • Conference_Location
    Montreal, Que
  • Print_ISBN
    978-1-4244-2412-2
  • Electronic_ISBN
    978-1-4244-2413-9
  • Type

    conf

  • DOI
    10.1109/LCN.2008.4664306
  • Filename
    4664306