Efficient Method to Detect Malicious Web Contents based on Time-bomb
Dong-Jin Kim, Seong-je Cho, Honggeun Kim · 2011
As the client-side attacks by malicious web contents have increased rapidly, much research has focused on high-interaction client honeypots which are effective to detect the attacks using dynamic analysis. As a result, high-interaction client honeypots become generally known. At the same time, a new malicious web page group including a time-bomb emerges to avoid the detection by high-interaction client honeypots. The web pages with a time bomb attack a target after a certain delay. In order to detect efficiently the malicious web pages with time bomb, the paper proposes a new detection model which introduces static analysis before dynamic analysis. The proposed model has first classified the suspicious web pages which are assumed to include a time bomb. We have enhanced the detection ratio of the malicious web pages by increasing the passage of time only for the classified pages and visiting them sequentially under the client honeypot. With a cost-based evaluation method, we have shown that our proposed model is better than the conventional one in terms of detection accuracy and cost.