Title
WebPatrol: automated collection and replay of web-based malware scenarios
Abstract
Traditional remote-server-exploiting malware is quickly evolving and adapting to the new web-centric computing paradigm. By leveraging the large population of (insecure) web sites and exploiting the vulnerabilities at client-side modern (complex) browsers (and their extensions), web-based malware becomes one of the most severe and common infection vectors nowadays. While traditional malware collection and analysis are mainly focusing on binaries, it is important to develop new techniques and tools for collecting and analyzing web-based malware, which should include a complete web-based malicious logic to reflect the dynamic, distributed, multi-step, and multi-path web infection trails, instead of just the binaries executed at end hosts. This paper is a first attempt in this direction to automatically collect web-based malware scenarios (including complete web infection trails) to enable fine-grained analysis. Based on the collections, we provide the capability for offline "live" replay, i.e., an end user (e.g., an analyst) can faithfully experience the original infection trail based on her current client environment, even when the original malicious web pages are not available or already cleaned. Our evaluation shows that WebPatrol can collect/cover much more complete infection trails than state-of-the-art honeypot systems such as PHoneyC [11] and Capture-HPC [1]. We also provide several case studies on the analysis of web-based malware scenarios we have collected from a large national education and research network, which contains around 35,000 web sites.
Year
DOI
Venue
2011
10.1145/1966913.1966938
ASIACCS
Keywords
Field
DocType
web-based malware scenario,complete web infection,common infection,complete infection,web site,multi-path web infection,automated collection,complete web-based malicious logic,web-based malware,traditional malware collection,traditional remote-server-exploiting malware,web pages
Web development,Web API,Internet privacy,World Wide Web,Web page,Web threat,Computer science,Computer security,Data Web,Web application security,Web navigation,Web service
Conference
Citations 
PageRank 
References 
13
0.78
11
Authors
5
Name
Order
Citations
PageRank
Kevin Zhijie Chen11506.32
Guofei Gu23361173.45
Jianwei Zhuge315513.86
Jose Nazario440226.51
Xinhui Han519511.44