期刊文献+

基于AST的网页木马解混淆技术

Drive-by-Download Attack Deobfuscation based on AST
下载PDF
导出
摘要 网页木马是最近几年非常流行的一种恶意代码分发的形式,其目标群体庞大,已经发展为传播最广泛,危害最严重的一种客户端攻击类型,而对网页木马的分析是网页木马研究的重要基础和前提。本文主要关注网页木马为了隐藏自身并提高攻击成功率而引入的混淆技术,首先讨论了各种当前的解混淆技术,然后引入了利用抽象语法树的解混淆技术,并实现了一套基于该技术的原型系统,最后使用多种类型的网页测试了原型系统,证明了该技术的有效性。 Drive-by-download attack,as a popular way to distribute malicious code in recent years,has a huge amount of potential victims and now becomes the most widespread and the most detrimental client- side attack. The analysis of drive-by-download attack is the prerequisite and foundation for the research. This paper mainly focuses on the obfuscation techniques of drive-by-download attack's,which make it harder to detect the malicious codes. Firstly,the common deobfuscation techniques are discussed,then the deobfuscation techniques based on AST described,and based on this technology,a set of prototype system is implemented,and finally,the tests on the prototype system based on different types of web pages,indicate the effectiveness of this proposed technology.
出处 《信息安全与通信保密》 2015年第4期88-92,共5页 Information Security and Communications Privacy
基金 高级XXX技术研究(秘密级)(CNITSEC-KY-2013-009/2)
关键词 抽象语法树 解混淆 网页木马 客户端蜜罐 AST deobfuscation drive-by-download attack client-side honeypot
  • 相关文献

参考文献11

  • 1DAY O,PALMEN B,GREENSTADT R.Reinterpreting the Disclosure Debate for Web Infections. Managing Information Risk and the Economics of Security . 2009
  • 2CURTSINGER C,LIVSHITS B,ZORN B G,et al.ZOZZLE:Fast and Precise In-Browser Java Script Malware Detection. Proceedings of the 20th USENIX conference on Security SEC’’11 . 2011
  • 3PALANT W.Fire Fox add-on:Java Script deobfuscator. https://addons.mozilla.org/en-US/firefox/addon/javascript-deobfuscator/ . 2013
  • 4Cova M,Kruegel C,Vigna G.Detection and analysisof drive-bydownload attacks and malicious JavaScript code. International Conference on World Wide Web (WWW) . 2010
  • 5DELL’’AERA A.Thug. https://github.com/buffer/thug . 2014
  • 6LU G,DEBRAY S.Automatic Simplification of Obfuscated Java Script code:A semantics-based Approach. 2012 6 th International Conference on Software Security and Reliability . 2012
  • 7ECMA.ECMAScript Language Specification. Fifth edition. ECMA-262 . 2009
  • 8SUZUKI Y.Escodegen. https://github.com/Constellation/escodegen . 2014
  • 9NETWORK M D.Mozilla Parser AST. https://developer.mozilla.org/en-US/docs/Mozilla/Projects/Spider Monkey/Parser_API . 2014
  • 10HIDAYAT A.Esprima. http://esprima.org/ . 2014

二级参考文献3

共引文献29

相关作者

内容加载中请稍等...

相关机构

内容加载中请稍等...

相关主题

内容加载中请稍等...

浏览历史

内容加载中请稍等...
;
使用帮助 返回顶部