90 likes | 179 Views
Niels Provos , Dean McNamee, Panayiotis Mavrommatis , Ke Wang and Nagendra Modadugu – Google First Workshop on Hot Topics in Understanding Botnets ( HotBots ‘07), Usenix , 9 pp., 2007. Presentation by Yuk Hin (Edwin) Chan. The Ghost In The Browser Analysis of Web-based Malware.
E N D
NielsProvos, Dean McNamee, Panayiotis Mavrommatis, Ke Wang and NagendraModadugu – Google First Workshop on Hot Topics in Understanding Botnets (HotBots ‘07), Usenix, 9 pp., 2007. Presentation by Yuk Hin (Edwin) Chan The Ghost In The BrowserAnalysis of Web-based Malware
The Paper • By Google • Analyse large webpage repository for malware – “drive-by downloads” • A pull-based approach, which defeats network defences such as proxies and NAT • Outlines methods used by adversary • How exploits appear • What mechanisms they use • Discuss trends in malware
In Detail • Heuristics prune unlikely URLs • Much less URLs to analyse • Runs Internet Explorer in virtual machine • New processes created by visiting webpage • Classifies Malware • Voting by different anti-virus software • Relies on anti-virus companies • Difficult to be accurate • Analysis of malware distribution across hosts
Good • Google has access to huge dataset • Gives comprehensive results • Provided statistical data on • Malware types • Malware distribution • Malware lifetime
Limits 1 • Many methods used are not exact or detailed • “We detect malicious pages based on abnormalities such as heavy obfuscation” • Abnormalities are not well defined • “To detect pages … we examine the interpreted Javascript included on each web page.” • What about exploits that does not relate to Javascript?
Limits 2 • Limited browsers tested • Tests only Internet Explorer • Which version of IE is tested? • Not all malware target Internet Explorer • Other Browsers? • Firefox, Opera, Safari • It would be interesting to see the proportion of malware that targets browsers with smaller market share.
Thank You / Thoughts This study shows that malware is a common threat to users “About 10% of the URLs we analyzed were malicious”And the methods they use are varied and constantly evolving. How can we best combat this threat?
MapReduce Heuristics Exploit Link Page URL Exploit Link Map Exploit Link Reduce Exploit Link