Detection of Drive-by Downloads Based on Dynamic Page Views

ZHANG Huilin,ZHUGE Jianwei,SONG Chengyu,HAN Xinhui,ZOO Wei
DOI: https://doi.org/10.3321/j.issn:1000-0054.2009.z2.009
2009-01-01
Abstract:A dynamic page view based drive-by download detection method was developed to address the challenge hidden drive-by downloads which abuse inline linking dynamics creation and obfuscation.The method uses a script engine to execute page scripts with tools to reveal the script's actions and inline linking identification mechanisms and rebuilds the dynamic page view of the visited page by recursively analyzing the inline pages.The system then detects drive-by downloads based on the rebuilt dynamic page view.Tests on a prototype based on the open-sourced PHoneyC framework to detect 89 drive-by download samples showed that single page views in this paper had a detection rate of 29.2%, static page views had a detection rate of 43.8%, and the dynamic page views had a detection rate of 70.8%.Thus, the dynamic detection method has a much higher detection rate.
What problem does this paper attempt to address?