Malfree web server response

Mahmood Ahmad, Rana Faisal Munir
{"title":"Malfree web server response","authors":"Mahmood Ahmad, Rana Faisal Munir","doi":"10.1109/ICET.2011.6048478","DOIUrl":null,"url":null,"abstract":"The trend of spreading malicious web contents through legitimate but compromised websites is not very rare to find. Websites bearing the trust of millions of clients are chosen to exploit the trust of its users by installing unwanted and malevolent contents on client machines through drive by download. This stealthier mechanism is aimed to convert a client machine into a botnet and to gain access on its resources like stored passwords, sensitive information and fingerprinting of running softwares. To deal with it, there are different solutions like honeypots and system state observers but all these antidotes are client resident. In this paper we have devised a heuristic based solution which resides on web servers and circumvents the movement of malicious contents toward client machines while keeping the server repute trusted and its availability 24/7 even after the compromise. Instead of blocking the complete website or any of its page, only malevolent contents are sanitized which adds novelty to the proposed system.","PeriodicalId":167049,"journal":{"name":"2011 7th International Conference on Emerging Technologies","volume":"56 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2011-10-20","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2011 7th International Conference on Emerging Technologies","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICET.2011.6048478","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

Abstract

The trend of spreading malicious web contents through legitimate but compromised websites is not very rare to find. Websites bearing the trust of millions of clients are chosen to exploit the trust of its users by installing unwanted and malevolent contents on client machines through drive by download. This stealthier mechanism is aimed to convert a client machine into a botnet and to gain access on its resources like stored passwords, sensitive information and fingerprinting of running softwares. To deal with it, there are different solutions like honeypots and system state observers but all these antidotes are client resident. In this paper we have devised a heuristic based solution which resides on web servers and circumvents the movement of malicious contents toward client machines while keeping the server repute trusted and its availability 24/7 even after the compromise. Instead of blocking the complete website or any of its page, only malevolent contents are sanitized which adds novelty to the proposed system.
错误的web服务器响应
通过合法但被入侵的网站传播恶意网络内容的趋势并不罕见。这些网站拥有数百万客户的信任,它们利用用户的信任,通过下载驱动的方式在客户端机器上安装不需要的恶意内容。这种更隐蔽的机制旨在将客户端机器转换为僵尸网络,并获得其资源的访问权限,如存储的密码、敏感信息和运行软件的指纹。为了解决这个问题,有不同的解决方案,如蜜罐和系统状态观察者,但所有这些解毒剂都是客户端驻留的。在本文中,我们设计了一种基于启发式的解决方案,该解决方案驻留在web服务器上,避免恶意内容向客户端机器移动,同时保持服务器信誉可信,即使在妥协后也能全天候可用。而不是封锁整个网站或其任何页面,只有恶意内容被清除,这增加了新颖性的提议系统。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信