Malnet Detection Techniques

Qing Li, Gregory Clark · 2015

This chapter describes the algorithms applied to rate the URLs and the web pages. It explores methods of exposing malware distribution servers. The chapter describes open-source tools, called honeyclients , which are often used for malware and malware distribution network (MDN) analysis. Malicious URLs that lead to the same malware change quickly to avoid detection. There are many classifiers that can be used to rate URLs. The chapter presents a straightforward example of how classifier training works using the Naïve Bayesian classifier. It explains how to prepare and present the data to the classifier for input classification. The chapter describes one analysis dimension that extracts keywords from a webpage and then uses these keywords to derive a category for that page. It provides an overview of browser honey-clients, and discusses the design trade-offs using popular honeyclient implementations as examples. Some of the challenges and alternative analysis techniques are also covered.

Read the paper · More papers on PaperTik