引用本文:张慧琳,邹维,韩心慧.网页木马机理与防御技术.软件学报,2013,24(4):843-858
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览 9242次   下载 18671 本文二维码信息
码上扫一扫!
分享到: 微信 更多
网页木马机理与防御技术
张慧琳1,2, 邹维3, 韩心慧1,2
1.北京大学 计算机科学技术研究所, 北京 100080;2.北京大学 互联网安全技术北京市重点实验室, 北京 100080;3.中国科学院 信息工程研究所, 北京 100093
摘要:
网页木马是一种以JavaScript,VBScript,CSS 等页面元素作为攻击向量,利用浏览器及插件中的漏洞,在客户端隐蔽地下载并执行恶意程序的基于Web 的客户端攻击.网页木马的表现形式是一个或一组有内嵌链接关系的页面/脚本,有漏洞的客户端在访问该(组)页面时会“过路式下载”木马等恶意程序.网页木马通过这种被动攻击模式,能隐蔽、有效地将恶意程序植入客户端,这已经成为恶意程序传播的一种重要方式.近年来,围绕网页木马的攻防博弈在持续进行.首先阐述网页木马的机理和特点,然后从检测、特征分析、防范这3 个方面对网页木马防御方的研究进行总结和分析,最后对网页木马攻防双方的发展趋势进行讨论.
关键词:  网页木马  客户端攻击  被挂马网页  混淆  内嵌链接
DOI:10.3724/SP.J.1001.2013.04376
分类号:
基金项目:国家自然科学基金(61003217, 61003216); 发改委国家信息安全专项([2010]3044); 国家242 信息安全计划(2011A40)
Drive-by-Download Mechanisms and Defenses
ZHANG Hui-Lin1,2, ZOU Wei3, HAN Xin-Hui1,2
1.Institute of Computer Science and Technology, Peking University, Beijing 100080, China;2.Beijing Key Laboratory of Internet Security Technology, Peking University, Beijing 100080, China;3.Institute of Information Engineering, The Chinese Academy of Sciences, Beijing 100093, China
Abstract:
Drive-by-Download is a Web-based attack that targets at downloading and executing malwares on the client side without the user’s notice or consent. It usually takes HTML elements (e.g. JavaScript, VBScript, CSS) as attack vectors, and exploits vulnerabilities in browser and plugins to launch attacks. Drive-by-Download represents as an HTML page or a group of inline-linked HTML pages/scripts. After browsing these pages, vulnerable client sides will automatically download and execute malware. Through the pull-based attack mode, Drive-by-Download can effectively and secretly spread malware to clients and has become an important way to spread malware. In recent years, both the offense-side and defense-side make ongoing development. This paper first introduces the mechanisms and features of Drive-by-Download. Then the paper summarizes and discusses researches on detection, analysis and prevention of Drive-by-Download. Trends of Drive-by-Download and some possible research directions will be discussed at last.
Key words:  Drive-by-Download  client-side attack  landing page  obfuscation  inline linking

引用本文:
【打印本页】   【下载PDF全文】   查看/发表评论  【EndNote】   【RefMan】   【BibTex】
←前一篇|后一篇→ 过刊浏览    高级检索
本文已被:浏览次   下载  
分享到: 微信 更多
摘要:
关键词:  
DOI:
分类号:
基金项目:
Abstract:
Key words: