Back to Search Start Over

LoGos: Internet-Explorer-Based Malicious Webpage Detection.

Authors :
Sungjin Kim
Sungkyu Kim
Dohoon Kim
Source :
ETRI Journal; Jun2017, Vol. 39 Issue 3, p406-416, 11p
Publication Year :
2017

Abstract

Malware propagated via the World Wide Web is one of the most dangerous tools in the realm of cyber-attacks. Its methodologies are effective, relatively easy to use, and are developing constantly in an unexpected manner. As a result, rapidly detecting malware propagation websites from a myriad of webpages is a difficult task. In this paper, we present LoGos, an automated highinteraction dynamic analyzer optimized for a browserbased Windows virtual machine environment. LoGos utilizes Internet Explorer injection and API hooks, and scrutinizes malicious behaviors such as new network connections, unused open ports, registry modifications, and file creation. Based on the obtained results, LoGos can determine the maliciousness level. This model forms a very lightweight system. Thus, it is approximately 10 to 18 times faster than systems proposed in previous work. In addition, it provides high detection rates that are equal to those of state-of-the-art tools. LoGos is a closed tool that can detect an extensive array of malicious webpages. We prove the efficiency and effectiveness of the tool by analyzing almost 0.36 M domains and 3.2 M webpages on a daily basis. [ABSTRACT FROM AUTHOR]

Details

Language :
English
ISSN :
12256463
Volume :
39
Issue :
3
Database :
Complementary Index
Journal :
ETRI Journal
Publication Type :
Academic Journal
Accession number :
123425522
Full Text :
https://doi.org/10.4218/etrij.17.0116.0810