首页> 外文会议>International conference on security management >Digital Forensic Analysis of Web-Browser Based Attacks
【24h】

Digital Forensic Analysis of Web-Browser Based Attacks

机译:基于Web浏览器的攻击的数字取证分析

获取原文

摘要

In recent years, attacks that target browsers' vulnerabilities have increased significantly. An innocent user may lure to access untrusted website and malicious content passively downloaded and executed by his/her web browser; this attack vector known as, Drive-by-Download attack. Systems and security researchers addressed this attack from different perspectives. Several techniques and tools were introduced to detect and prevent Drive-by-Download attack; however, few research addresses the browser forensics perspectives to (1) identify traces (2) reconstruct the executed events of a downloaded malicious content, to assist the digital forensic investigation process. In this paper, digital forensic method is introduced to investigate a web browser subject to Drive-by-Download attack. A Proof-of-Concept implementation based on Firefox browser-extension was developed to inspect and analyze malicious URLs that host malicious executable. The developed system was tested using 55 malicious web pages and successfully identified the digital evidence of the attack. 77% of the identified evidence were artifacts that we believe it could assist forensic investigator to determine if web-browser or a system subject to examination is compromised or not, and the indications of compromises.
机译:近年来,针对浏览器漏洞的攻击已大大增加。无辜的用户可能引诱访问不受信任的网站以及由他/她的网络浏览器被动下载并执行的恶意内容;这种攻击媒介称为“下载驱动器攻击”。系统和安全研究人员从不同角度解决了这种攻击。引入了几种技术和工具来检测和阻止“下载驱动”攻击;但是,很少有研究针对浏览器取证的观点来(1)识别痕迹(2)重建下载的恶意内容的已执行事件,以辅助数字取证调查过程。在本文中,引入了数字取证方法来调查遭受“下载驱动”攻击的Web浏览器。开发了基于Firefox浏览器扩展的概念验证实现,以检查和分析托管恶意可执行文件的恶意URL。使用55个恶意网页对开发的系统进行了测试,并成功识别了攻击的数字证据。我们认为有77%的证据是人工制品,我们认为这可以帮助法医研究人员确定网络浏览器或要检查的系统是否受到威胁以及危害的迹象。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号