Dissertation > Excellent graduate degree dissertation topics show
Content-based malicious code detection Research and Implementation
Author: WeiWei
Tutor: LiZhiTang
School: Huazhong University of Science and Technology
Course: Information Security
Keywords: Malicious code page Drive-by downloads Static Detection Motion detection Machine Learning
CLC: TP393.092
Type: Master's thesis
Year: 2011
Downloads: 95
Quote: 0
Read: Download Dissertation
Abstract
|
In recent years, worms, Trojans, botnets and other malicious code is always represented threats to Internet security, and as WEB2.0 and the growing popularity of cloud computing, more and more applications WEB-based services, there have been browsing is the trend of the operating system level, the use of browsers and browser plug-in replaces the use of loopholes in the operating system and application vulnerabilities, malicious code, malicious Web has become the main channel for dissemination or attack, becoming an important part of the underground economy. Malicious Web page that contains malicious content so viruses, Trojans, etc. can be carried out by means of its transmission or attack Web page that contains malicious content is also known as Trojan, in essence, is not a Trojan horse, but in the web as a medium to spread malicious or attack code, generally JavaScript, VBScript and other scripting language, contained in the web among the obfuscation through a variety of ways to evade detection, the content on the page to insert malicious behavior is also called \Malicious code through the use of a user's browser or plug the loopholes in the case without the knowledge of the user to download and run malicious software, such as adware, Trojans and viruses. Normal web page may also be malicious code, so even seemingly normal users to access some sites, there may be this kind of malicious code attacks. Since a large number of malicious code page used code obfuscation techniques, traditional anti-virus software false negative rate is very high, which also led to a growing number of attackers use malicious code to spread malicious software. Existing malicious web detection method can usually be divided into static detection (based on the page content or URL) and dynamic testing (based on the behavior triggered browsing the web), and a combination of both methods. Traditional static detection method is simple and fast, but can only detect known features, difficult to deal with page code obfuscation, so there will be a large number of false negatives and false positives, so many existing systems use dynamic testing method, in a virtual machine Open a Web browser to open, monitor system status to find malicious behavior. Dynamic monitoring method accuracy is high, but relatively large consumption of resources can not be used to detect the presence of a large-scale Internet pages. By analyzing the page content, feature extraction, we propose a lightweight malicious code detection methods for machine learning to automatically get the classification model. Meanwhile, in order to make up for the lack of static detection methods, the virtual machine via JavaScript code confusing part may be resolved to improve system accuracy. This method is mainly for testing source code of the page, without actually accessing the web and detection system behavior, so this system is to ensure the accurate detection of the case less resource consumption, faster, such as search engines, etc. can be applied to large-scale malicious web pages code detection. By systematically analyzing the characteristics of malicious code, malicious Web extracted features used, and completed a malicious code detection prototype system design and implementation, the experiment proved that the system can be more accurate and effective completion of malicious Web.
|
Related Dissertations
- Research and Design of a C++ Codes Defect Detection System,TP311.53
- C static code checking syntax tree Construction Methods,TP311.53
- Based on Data Distribution Characteristics of Text Classification,TP391.1
- A Video Monitoring System for Anshan Power Supply Room,TP391.41
- Application of Motion Detection Technology in Intelligent Surveillance System,TP277
- Research and Implement of Chinese Word Segment Techniques Based on the Conditional Random Field,TP391.1
- Research of Multimedia Enhancement Unit in the Embedded Processor,TP332
- Semi-supervised Learning and Active Learning of Sentiment Classification Coupled with Domain Knowledge,TP181
- A Static Behavior-Based Method to Detect Malware on Android,TP309
- Learning-based human motion synthesis inverse kinematics,TP391.41
- Social network algorithm and its application in recommendation,TP391.3
- Application of Data Mining in Email Anti-Spam System,TP393.098
- Based on self-learning social relation extraction research,TP391.1
- Graph model based on statistical and machine learning algorithm and its application of certain,TP181
- P2P Traffic Identification Method,TP393.06
- Based on rough sets and SVM national defense Comprehensive Quality Assessment Methods,E075
- SVM Based on SIFT and scene classification,TP391.41
- DM6437 -based video motion detection system design pedestrian,TP391.41
- Video Mean-Shift tracking algorithm applied research,TP391.41
- Machine learning based on sparse coding and image content recognition algorithm,TP391.41
- Multi-threaded fusion soccer video semantic analysis and event detection,TP391.41
CLC: > Industrial Technology > Automation technology,computer technology > Computing technology,computer technology > Computer applications > Computer network > General issues > The application of computer network > Web browser
© 2012 www.DissertationTopic.Net Mobile
|