The Experts below are selected from a list of 114 Experts worldwide ranked by ideXlab platform
Peter Komisarczuk - One of the best experts on this subject based on the ideXlab platform.
-
anatomy of drive by Download Attack
Information Security Conference, 2013Co-Authors: Ian Welch, Xiaoying Gao, Peter KomisarczukAbstract:Drive-by Download Attacks where web browsers are subverted by malicious content delivered by web servers have become a common Attack vector in recent years. Several methods for the detection of malicious content on web pages using data mining techniques to classify web pages as malicious or benign have been proposed in the literature. However, each proposed method uses different content features in order to do the classification and there is a lack of a high-level frameworks for comparing these methods based upon their choice of detection features. The lack of a framework makes it problematic to develop experiments to compare the effectiveness of methods based upon different selections of features. This paper presents such a framework derived from an analysis of of drive-by Download Attacks that focus upon potential state changes seen when Internet browsers render HTML documents. This framework can be used to identify potential features that have not yet been exploited and to reason about the challenges for using those features in detection drive-by Download Attack.
-
AISC - Anatomy of drive-by Download Attack
2013Co-Authors: Van Lam Le, Ian Welch, Xiaoying Gao, Peter KomisarczukAbstract:Drive-by Download Attacks where web browsers are subverted by malicious content delivered by web servers have become a common Attack vector in recent years. Several methods for the detection of malicious content on web pages using data mining techniques to classify web pages as malicious or benign have been proposed in the literature. However, each proposed method uses different content features in order to do the classification and there is a lack of a high-level frameworks for comparing these methods based upon their choice of detection features. The lack of a framework makes it problematic to develop experiments to compare the effectiveness of methods based upon different selections of features. This paper presents such a framework derived from an analysis of of drive-by Download Attacks that focus upon potential state changes seen when Internet browsers render HTML documents. This framework can be used to identify potential features that have not yet been exploited and to reason about the challenges for using those features in detection drive-by Download Attack.
-
LCN - Detecting heap-spray Attacks in drive-by Downloads: Giving Attackers a hand
38th Annual IEEE Conference on Local Computer Networks, 2013Co-Authors: Van Lam Le, Ian Welch, Xiaoying Gao, Peter KomisarczukAbstract:In the anatomy of drive-by Download Attacks, one of the key steps is to place malicious code (shellcode) in the memory of the browser process in order to carry out a drive-by Download Attack. There are two common techniques to carry out this task: stack-based and heap-based injections. However, introduction of stack protection makes the stack-based injection harder to carry out successfully. The heap-based injections become common methods to deliver shellcode to the heap memory of the web browsers. This paper presents the role of heap-spray in drive-by Download Attacks. We propose a new detection mechanism which makes shellcode in heap-spray executed in order to detect drive-by Download Attack. The solution not only benefits detection of drive-by Download Attacks but also analysis of malware behavior.
Ayumu Kubota - One of the best experts on this subject based on the ideXlab platform.
-
TrustCom/BigDataSE/ICESS - Classification of Landing and Distribution Domains Using Whois’ Text Mining
2017 IEEE Trustcom BigDataSE ICESS, 2017Co-Authors: Tran Phuong Thao, Akira Yamada, Kosuke Murakami, Jumpei Urakawa, Yukiko Sawaya, Ayumu KubotaAbstract:Detection of drive-by-Download Attack has gained a focus in security research since the Attack has turned into the most popular and serious threat to web infrastructure. The Attack exploits vulnerabilities in web browsers and their extensions for unnoticeably Downloading malicious software. Often, the victim is sent through a long chain of redirection operations in order to take down the offending pages. Concretely, the Attack is triggered when a user visits a benign webpage that is compromised by the Attacker (called landing page) and is inserted some malicious code inside. The user is then automatically redirected to an actual page that installs malware on the user's computer (called distribution page) without his/her consent or knowledge. While there is a large body of works targeting on detection of drive-by Download Attack, there is little attention on the redirection which is a crucial characteristic of the Attack. In this paper, for the first time, we propose an approach to the classification of landing and distribution domains which are important components forming the head and tail of a redirection chain in the Attack. The methodology in our approach is to use machine learning for text mining on the registered information of the domains called whois. We intensively implemented our approach with six popular supervised learning algorithms, compared the results and concluded that Linear-based Support Vector Machine and CART algorithm-based Decision Tree are the best models for our dataset which respectively give 98.55% and 99.28% of accuracy, 97.78% and 98.95% of F1 score, 98.35% and 99.45% of average precision.
-
detecting and preventing drive by Download Attack via participative monitoring of the web
Information Security, 2013Co-Authors: Takashi Matsunaka, Junpei Urakawa, Ayumu KubotaAbstract:Drive-by Download Attack (DBD) is one of the major threats on the web infrastructure. DBD Attacks are triggered by user access to a malicious website and force users to Download malware by exploiting the vulnerabilities of web browsers or plugins. Malicious websites are ephemeral. Therefore, it is necessary to gather fresh information related to malicious activities to detect and prevent such Attacks. In this paper, we propose a framework that combats with DBD Attacks with users' voluntary monitoring of the web. This framework tackles the two issues: ways to obtain up-to-date information related malicious activities and ways to provide up-to-date information to the world. The framework aims to realize a security ecosystem: users actively offer information about their activities on the web (e.g. access URL, Download contents), and security analysts inspect the information to detect new threats and devise countermeasures for any new threats and then provide the countermeasures to users as feedback. The framework consists of sensors located on the user side and a centralized center located on the network side. Sensors are deployed in the web browser, in web proxies, and DNS servers. Sensors monitors the access URLs Download contents, the method of triggering the link events (e.g. mouse click, move, redirected by the server), then the sensors report the data to the center. The center analyzes the data, derives the statistical data and the web link structure, and detects new threats by facilitating the characteristics of malicious web pages. This paper also shows a real world example that demonstrates the potential of our framework. The example implies that our focus on the change of the web link structure can detect illegal falsification of web pages. Our framework can obtain long-term data on how many hosts users are forced to access by the access of a web page, so we believe that our framework can distinguish legitimate changes in web pages with compromised changes.
-
AsiaJCIS - Detecting and Preventing Drive-By Download Attack via Participative Monitoring of the Web
2013 Eighth Asia Joint Conference on Information Security, 2013Co-Authors: Takashi Matsunaka, Junpei Urakawa, Ayumu KubotaAbstract:Drive-by Download Attack (DBD) is one of the major threats on the web infrastructure. DBD Attacks are triggered by user access to a malicious website and force users to Download malware by exploiting the vulnerabilities of web browsers or plugins. Malicious websites are ephemeral. Therefore, it is necessary to gather fresh information related to malicious activities to detect and prevent such Attacks. In this paper, we propose a framework that combats with DBD Attacks with users' voluntary monitoring of the web. This framework tackles the two issues: ways to obtain up-to-date information related malicious activities and ways to provide up-to-date information to the world. The framework aims to realize a security ecosystem: users actively offer information about their activities on the web (e.g. access URL, Download contents), and security analysts inspect the information to detect new threats and devise countermeasures for any new threats and then provide the countermeasures to users as feedback. The framework consists of sensors located on the user side and a centralized center located on the network side. Sensors are deployed in the web browser, in web proxies, and DNS servers. Sensors monitors the access URLs Download contents, the method of triggering the link events (e.g. mouse click, move, redirected by the server), then the sensors report the data to the center. The center analyzes the data, derives the statistical data and the web link structure, and detects new threats by facilitating the characteristics of malicious web pages. This paper also shows a real world example that demonstrates the potential of our framework. The example implies that our focus on the change of the web link structure can detect illegal falsification of web pages. Our framework can obtain long-term data on how many hosts users are forced to access by the access of a web page, so we believe that our framework can distinguish legitimate changes in web pages with compromised changes.
Shigeki Goto - One of the best experts on this subject based on the ideXlab platform.
-
SecureComm - Website forensic investigation to identify evidence and impact of compromise
Lecture Notes of the Institute for Computer Sciences Social Informatics and Telecommunications Engineering, 2017Co-Authors: Yuta Takata, Mitsuaki Akiyama, Takeshi Yagi, Takeshi Yada, Shigeki GotoAbstract:Compromised websites that redirect users to malicious websites are often used by Attackers to distribute malware. These Attackers compromise popular websites and integrate them into a drive-by Download Attack scheme to lure unsuspecting users to malicious websites. An incident response organization such as a CSIRT contributes to preventing the spread of malware infection by analyzing compromised websites reported by users and sending abuse reports with detected URLs to webmasters. However, these abuse reports with only URLs are not sufficient to clean up the websites; therefore, webmasters cannot respond appropriately to such reports. In addition, it is difficult to analyze malicious websites across different client environments, i.e., a CSIRT and a webmaster, because these websites change behavior depending on the client environment. To expedite compromised website clean-up, it is important to provide fine-grained information such as the precise position of compromised web content, malicious URL relations, and the target range of client environments. In this paper, we propose a method of constructing a redirection graph with context, such as which web content redirects to which malicious websites. Our system with the proposed method analyzes a website in a multi-client environment to identify which client environment is exposed to threats. We evaluated our system using crawling datasets of approximately 2,000 compromised websites. As a result, our system successfully identified compromised web content and malicious URL relations, and the amount of web content and the number of URLs to be analyzed were sufficient for incident responders by 0.8% and 15.0%, respectively. Furthermore, it can also identify the target range of client environments in 30.4% of websites and a vulnerability that has been used in malicious websites by leveraging target information. This fine-grained information identified with our system would dramatically make the daily work of incident responders more efficient.
-
COMPSAC - MineSpider: Extracting URLs from Environment-Dependent Drive-by Download Attacks
2015 IEEE 39th Annual Computer Software and Applications Conference, 2015Co-Authors: Yuta Takata, Mitsuaki Akiyama, Takeshi Yagi, Takeo Hariu, Shigeki GotoAbstract:Drive-by Download Attacks force users to automatically Download and install malware by redirecting them to malicious URLs that exploit vulnerabilities of the user's web browser. Attackers profile the information on the user's environment such as the name and version of the browser and browser plugins and launch a drive-by Download Attack on only certain targets by changing the destination URL. When malicious content detection and collection techniques such as honey clients are used that do not match the specific environment of the Attack target, they cannot detect the Attack because they are not redirected. We propose here a method to exhaustively analyze Java Script code relevant to redirections and to extract the destination URLs in the code. Our method facilitates the detection of Attacks by extracting a large number of URLs while controlling the analysis overhead by excluding code not relevant to redirections. We implemented our method in a browser emulator called Mine Spider that automatically extracts potential URLs from websites. We validated it by using communication data with malicious websites captured during a three-year period. The experimental results demonstrated that Mine Spider extracted 30,000 new URLs from websites in a few seconds that existing techniques missed.
Dongwan Shin - One of the best experts on this subject based on the ideXlab platform.
-
similarity analysis of shellcodes in drive by Download Attack kits
Collaborative Computing, 2012Co-Authors: Manoj Cherukuri, Srinivas Mukkamala, Dongwan ShinAbstract:Drive-by Downloads have become the primary Attack vehicle for malware distribution in recent years. With the rise of targeted Attacks, the vulnerabilities within the cloud based services and web based collaboration frameworks might end up as the principal targets for hosting drive-by Download Attacks. In this paper, we studied the similarity of the shellcodes among different Attack kits. Shellcode is the malicious code used as the payload in drive-by Download Attacks. Specifically, we collected 15 different drive-by Download Attack kits and identified shellcodes used in each kit. As the shellcodes are transmitted to the browser as Javascript strings, we measured the similarity between regular strings and shellcodes defined in Javascript. We disassembled the shellcodes and computed the mean of Cosine Similarity, Extended Jaccard Similarity and Pearson Correlation measures based on the frequencies of the opcodes. Our analysis shows that the shellcodes, used as payloads, across different Attack kits were similar with other shellcodes and dissimilar with benign Javascript strings. We observe that some of the Attack kits released across different years had same shellcodes. The performance of similarity analysis was compared to an emulation based approach and observed reduction of 75% in the analysis time. Based on the results, the similarity measure of the shellcodes could be an effective static mechanism in detecting the shellcode based drive-by Download Attacks.
-
CollaborateCom - Similarity analysis of shellcodes in drive-by Download Attack kits
Proceedings of the 8th IEEE International Conference on Collaborative Computing: Networking Applications and Worksharing, 2012Co-Authors: Manoj Cherukuri, Srinivas Mukkamala, Dongwan ShinAbstract:Drive-by Downloads have become the primary Attack vehicle for malware distribution in recent years. With the rise of targeted Attacks, the vulnerabilities within the cloud based services and web based collaboration frameworks might end up as the principal targets for hosting drive-by Download Attacks. In this paper, we studied the similarity of the shellcodes among different Attack kits. Shellcode is the malicious code used as the payload in drive-by Download Attacks. Specifically, we collected 15 different drive-by Download Attack kits and identified shellcodes used in each kit. As the shellcodes are transmitted to the browser as Javascript strings, we measured the similarity between regular strings and shellcodes defined in Javascript. We disassembled the shellcodes and computed the mean of Cosine Similarity, Extended Jaccard Similarity and Pearson Correlation measures based on the frequencies of the opcodes. Our analysis shows that the shellcodes, used as payloads, across different Attack kits were similar with other shellcodes and dissimilar with benign Javascript strings. We observe that some of the Attack kits released across different years had same shellcodes. The performance of similarity analysis was compared to an emulation based approach and observed reduction of 75% in the analysis time. Based on the results, the similarity measure of the shellcodes could be an effective static mechanism in detecting the shellcode based drive-by Download Attacks.
Chengyu Song - One of the best experts on this subject based on the ideXlab platform.
-
preventing drive by Download via inter module communication monitoring
Computer and Communications Security, 2010Co-Authors: Chengyu Song, Jianwei Zhuge, Zhiyuan YeAbstract:Drive-by Download Attack is one of the most severe threats to Internet users. Typically, only visiting a malicious page will result in compromise of the client and infection of malware. By the end of 2008, drive-by Download had already become the number one infection vector of malware [5]. The Downloaded malware may steal the users' personal identification and password. They may also join botnet to send spams, host phishing site or launch distributed denial of service Attacks. Generally, these Attacks rely on successful exploits of the vulnerabilities in web browsers or their plug-ins. Therefore, we proposed an inter-module communication monitoring based technique to detect malicious exploitation of vulnerable components thus preventing the vulnerability being exploited. We have implemented a prototype system that was integrated into the most popular web browser Microsoft Internet Explorer. Experimental results demonstrate that, on our test set, by using vulnerability-based signature, our system could accurately detect all Attacks targeting at vulnerabilities in our definitions and produced no false positive. The evaluation also shows the performance penalty is kept low.
-
AsiaCCS - Preventing drive-by Download via inter-module communication monitoring
Proceedings of the 5th ACM Symposium on Information Computer and Communications Security - ASIACCS '10, 2010Co-Authors: Chengyu Song, Jianwei Zhuge, Xinhui HanAbstract:Drive-by Download Attack is one of the most severe threats to Internet users. Typically, only visiting a malicious page will result in compromise of the client and infection of malware. By the end of 2008, drive-by Download had already become the number one infection vector of malware [5]. The Downloaded malware may steal the users' personal identification and password. They may also join botnet to send spams, host phishing site or launch distributed denial of service Attacks. Generally, these Attacks rely on successful exploits of the vulnerabilities in web browsers or their plug-ins. Therefore, we proposed an inter-module communication monitoring based technique to detect malicious exploitation of vulnerable components thus preventing the vulnerability being exploited. We have implemented a prototype system that was integrated into the most popular web browser Microsoft Internet Explorer. Experimental results demonstrate that, on our test set, by using vulnerability-based signature, our system could accurately detect all Attacks targeting at vulnerabilities in our definitions and produced no false positive. The evaluation also shows the performance penalty is kept low.