Cujo: Efficient Detection and Prevention of Drive-by-Download Attacks

dc.contributor.authorRieck, Konrad
dc.contributor.authorKrueger, Tammo
dc.contributor.authorDewald, Andreas
dc.date.accessioned2020-06-15T06:32:01Z
dc.date.available2020-06-15T06:32:01Z
dc.date.issued2010
dc.description.abstractThe JavaScript language is a core component of active and dynamic web content in the Internet today. Besides its great success in enhancing web applications, however, JavaScript provides the basis for drive-by downloads—attacks exploiting vulnerabilities in web browsers and their extensions for unnoticeably downloading malicious so ware. Due to the diversity and frequent use of obfuscation in these JavaScript attacks, static code inspection proves ineffective in practice. While dynamic analysis and honeypots provide means to identify drive-by-download attacks, current approaches induce a significant overhead which renders immediate prevention of attacks intractable. In this paper, we present Cujo, a system for automatic detection and prevention of drive-by-download attacks. Embedded in a web proxy, Cujo transparently inspects web pages and blocks delivery of malicious JavaScript code. Static and dynamic code features are extracted on-the-fly and analysed for malicious patterns using efficient techniques of machine learning. We demonstrate the efficacy of Cujo in different experiments, where it detects 95% of the drive-by downloads with few false alarms and a median run-time of 500 ms per web page—a quality that, to the best of our knowledge, has not been attained in previous work on detection of drive-by-download attacks.en
dc.identifier.issn1436-9915
dc.identifier.urihttps://depositonce.tu-berlin.de/handle/11303/11359
dc.identifier.urihttp://dx.doi.org/10.14279/depositonce-10246
dc.language.isoen
dc.relation.hasversion10.1145/1920261.1920267
dc.rights.urihttp://rightsstatements.org/vocab/InC/1.0/
dc.subject.ddc004 Datenverarbeitung; Informatik
dc.subject.otherdrive-by download attacken
dc.subject.otherJavaScripten
dc.subject.otherCujoen
dc.subject.othermalicious softwareen
dc.titleCujo: Efficient Detection and Prevention of Drive-by-Download Attacksen
dc.typeResearch Paper
dc.type.versionsubmittedVersionen
tub.accessrights.dnbfree
tub.affiliationFak. 4 Elektrotechnik und Informatikde
tub.affiliation.facultyFak. 4 Elektrotechnik und Informatikde
tub.publisher.universityorinstitutionTechnische Universität Berlin
tub.series.issuenumber2010-10
tub.series.nameForschungsberichte der Fakultät IV - Elektrotechnik und Informatik / Technische Universität Berlin

Files

Original bundle
Now showing 1 - 1 of 1
Loading…
Thumbnail Image
Name:
tr_2010-10.pdf
Size:
1023.34 KB
Format:
Adobe Portable Document Format

Collections