Drive-by-Download Attack Deobfuscation based on AST

Xiang Jia-q · Information Security and Communications Privacy · 2015

Drive-by-download attack,as a popular way to distribute malicious code in recent years,has a huge amount of potential victims and now becomes the most widespread and the most detrimental client- side attack. The analysis of drive-by-download attack is the prerequisite and foundation for the research. This paper mainly focuses on the obfuscation techniques of drive-by-download attack's,which make it harder to detect the malicious codes. Firstly,the common deobfuscation techniques are discussed,then the deobfuscation techniques based on AST described,and based on this technology,a set of prototype system is implemented,and finally,the tests on the prototype system based on different types of web pages,indicate the effectiveness of this proposed technology.

Read the paper · More papers on PaperTik