Web Page Malicious Code Detection Based on Embedded Fingerprints

HUANG Jianjun,LIANG Bin
DOI: https://doi.org/10.3321/j.issn:1000-0054.2009.z2.022
2009-01-01
Abstract:Web sites have become the main targets of many attackers.Signature-based detection needs to maintain a large signature database and Honeypot based methods are not efficient.Since attackers always make the malicious codes in Web pages difficult to detect by the browser users, their methods can be classified into various fingerprints.Various malicious codes were analyzed to identify 6 types of fingerprints.The system utilizes a spider integrated with script interpretation to fetch target Web pages and extract specific tags for detection by HTML parsing for matching with the fingerprints to detect malicious codes.This method needs fewer fingerprints than traditional detection methods and is more efficient.Results for 60 websites show that the system has a false negative rate of 2.63% and a false positive rate of 1.99%.
What problem does this paper attempt to address?