首页> 外文会议>International Conference on Natural Computation;ICNC '09 >A Web Page Malicious Code Detect Approach Based on Script Execution
【24h】

A Web Page Malicious Code Detect Approach Based on Script Execution

机译:基于脚本执行的网页恶意代码检测方法

获取原文

摘要

Web page malicious code detection is a crucial aspect of Internet security. Current web page malicious codes detection work by checking for ȁC;signaturesȁD;, which attempt to capture (syntactic) characteristics of the known malicious codes. This reliance on a syntactic approach makes such detectors vulnerable to code obfuscations, increasingly used by malicious codewriters, which alter syntactic prosperities of the malicious code without affecting their execution behavior significantly. This paper takes the position that the key to webpage malicious code lies in their execution behavior. It proposes a script execution behavior feature based framework for analyzing propose of malicious codes and proving properties such as soundness and completeness of these malicious codes. Our approach analyses the script and confirms the script which contains malicious code by finding shell code, overflow behavior and hidden hyper link. As a concrete application of our approach,we show that the script execution behavior based webpage malicious code detector can detect many known malicious code but also the newest malicious code.
机译:网页恶意代码检测是Internet安全的重要方面。当前的网页恶意代码检测是通过检查ȁC; Signatures; D;来进行的,这些尝试试图捕获(语法上的)已知恶意代码的特征。这种对语法方法的依赖使此类检测器容易受到恶意代码编写者越来越多的代码混淆的影响,这些代码混淆会更改恶意代码的语法繁荣,而不会显着影响其执行行为。本文认为,网页恶意代码的关键在于其执行行为。它提出了一个基于脚本执行行为特征的框架,用于分析恶意代码的提议并证明这些恶意代码的健全性和完整性等特性。我们的方法通过分析外壳代码,溢出行为和隐藏的超链接来分析脚本并确认其中包含恶意代码的脚本。作为我们方法的具体应用,我们证明了基于脚本执行行为的网页恶意代码检测器可以检测到许多已知的恶意代码,但也可以检测到最新的恶意代码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号