Using Machine Learning Techniques to Identify Drive-by-download
Xinhui Han · Xinxi wangluo anquan · 2011
The frequently used encryption and obfuscation becomes a hard problem of static analysis ,while dynamic analysis can not enumerate all possible executing paths. This paper proposes a machine learning based identifying method of drive-by-download, extracts a few features of url and drive-by-download context, and labels the urls, and then constructs classification models for training data and do a prediction experiment, achieving a good result.